All insights
Cyber Risk & Strategy June 4, 2026 7 min read

Cyber Due Diligence in Mergers and Acquisitions

When a deal goes wrong because of cyber risk, it rarely fails loudly. More often the acquirer discovers, months after completion, that the target had been breached and never disclosed it, that its flagship product runs on unpatched infrastructure, or that a quiet privacy investigation is about to surface. By then the price is paid and the liabilities are yours. Cyber due diligence exists to find these problems while you can still do something about them.

For Australian buyers, investors and boards, cyber risk has moved from a technical footnote to a material factor in valuation. This guide sets out what a substantive cyber due diligence review covers and how to act on what it finds.

Why cyber due diligence belongs in every deal

The value of most modern businesses sits in intangible assets: customer data, intellectual property, software, and the trust that lets them keep operating. A weak security posture quietly erodes all of these. When you acquire a company, you acquire its security debt in full, including the breaches it has not noticed yet and the regulatory exposure it has not disclosed.

The most-cited cautionary tale remains Verizon’s 2017 acquisition of Yahoo, where the discovery of massive historical data breaches during the deal reduced the purchase price by around US$350 million. The lesson is not that breaches are fatal to deals; it is that the time to discover them is before, not after, you sign. Cyber due diligence gives you that opportunity, and the leverage that comes with it.

The five areas a substantive review covers

A credible cyber due diligence engagement is broader than a vulnerability scan. It examines five distinct dimensions of the target’s risk, each of which can affect price, terms or your decision to proceed.

1. Security posture and control maturity

This is the assessment of how well the target actually protects itself. You are looking at the maturity of its controls against a recognised baseline rather than a vendor’s marketing claims. For Australian targets, the Essential Eight is the natural yardstick: patching of applications and operating systems, multi-factor authentication, application control, restriction of administrative privileges, and backups. Where the target operates internationally or sells to enterprise, alignment to ISO 27001 is a stronger signal of a managed security program.

Key questions: Is patching timely and evidenced? Is MFA enforced everywhere, including for administrators and remote access? Who holds privileged access, and is it reviewed? Are backups tested and held offline? Maturity gaps here translate directly into remediation cost and elevated breach likelihood.

2. Breach and incident history

You want a complete picture of past incidents, how they were handled and what residual exposure remains. A historical breach that was detected, contained, disclosed and remediated tells you the target has a working response capability. A breach that was concealed, or one whose root cause was never fixed, is a serious red flag.

Probe for evidence: incident logs, post-incident reviews, notifications made to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, and any forensic reports. Silence is not reassurance. The absence of any recorded incidents in a sizeable organisation often signals a lack of detection capability rather than a clean record.

3. Data and intellectual property assets

Much of what you are buying is data and IP, so understanding what the target holds, where it lives and how it is protected is central. Map the categories of personal information it collects, the volume, and whether it holds sensitive data such as health or financial records that carry heightened obligations. Identify where source code, designs and trade secrets reside, and confirm the target actually owns them, particularly where contractors or open-source components are involved.

Data held offshore, in poorly secured cloud buckets, or without a clear retention and deletion regime represents both a breach risk and a compliance liability you will inherit.

4. Compliance and regulatory exposure

The target’s regulatory obligations become yours at completion. Under the Privacy Act 1988, the Australian Privacy Principles govern how personal information is handled, and recent reforms have sharply increased the penalties for serious or repeated breaches. If the target operates in financial services, APRA CPS 234 imposes specific information security obligations, and CPS 230 adds operational resilience requirements. Targets serving government may carry obligations under the Security of Critical Infrastructure Act or contractual security clauses.

Look for current or threatened regulatory action, gaps against applicable obligations, and contractual security commitments to the target’s own customers that you will need to honour.

5. Integration risk

Finally, assess what it will cost and take to safely combine the two organisations. Connecting a target with weaker controls to your network can import its risk directly into yours. Incompatible identity systems, end-of-life technology, undocumented infrastructure and reliance on a handful of key people all increase integration cost and timeline. This is frequently the largest hidden cost in a deal and the one most often missed.

Running the assessment in practice

A workable cyber due diligence process follows a clear sequence. Request documentation early, because access to evidence is almost always the constraint on timing.

  • Scope and request. Define what matters for this deal and issue a documentation request: policies, audit reports, penetration test results, incident records, asset inventories, cloud configurations and compliance evidence.
  • Review and interview. Examine the evidence and interview the target’s IT and security people. Conversations reveal culture and gaps that documents conceal.
  • Validate. Where access permits, corroborate claims with external attack-surface analysis, configuration review or a targeted technical assessment rather than taking assertions at face value.
  • Report commercially. Translate findings into deal language: material risks, estimated remediation cost, and recommended actions on price, warranties or conditions.

What a documentation request should ask for

The quality of a cyber due diligence review depends heavily on the evidence you obtain, and vendors will not always volunteer it. A focused request, issued early, prevents the engagement from stalling. A reasonable list for most targets includes the following.

  • Governance. Security policies, the organisation chart for IT and security, board reporting on cyber risk, and any risk register.
  • Controls evidence. Recent penetration test and vulnerability scan reports, patch management records, MFA coverage, and privileged access reviews.
  • Incident history. Incident logs, post-incident reviews, breach notifications to regulators, and any forensic reports from the past three to five years.
  • Assets and data. Asset and software inventories, a data map showing what personal information is held and where, and cloud configuration details.
  • Compliance. Audit and certification reports, third-party security attestations, and records of any regulatory correspondence or investigations.
  • Third parties. A list of critical suppliers with access to systems or data, and the security terms in those contracts.

Be alert to what is missing. A target that cannot produce an asset inventory or has no record of penetration testing is telling you something about its maturity, whether or not it intends to.

The third-party and supply-chain dimension

A target’s risk does not stop at its own boundary. Modern businesses depend on a web of cloud platforms, software vendors and managed service providers, any of which can be the route to a breach. The 2020 SolarWinds incident showed how a single compromised supplier can cascade across thousands of organisations downstream. When you acquire a company, you also acquire its supply-chain exposure.

Review which third parties hold the target’s data or have access to its systems, how that access is controlled, and what the contracts say about security and breach notification. Concentration risk matters too: heavy reliance on a single provider, or a critical service with no contracted security obligations, is exposure you will inherit and have to manage from day one.

Turning findings into deal outcomes

Diligence only adds value if it changes the deal. Findings typically flow into one of a few levers. Quantified remediation costs can support a price adjustment. Specific risks can be addressed through warranties and indemnities, so the seller carries the cost if a concealed problem surfaces later. Significant exposure can become a condition precedent, requiring the seller to fix it before completion. And the most serious findings, such as an active, unresolved breach or systemic non-compliance, may justify walking away.

Whatever the outcome, capture the remediation priorities for the first 100 days after completion, so security work begins immediately rather than drifting while integration consumes attention.

How CISO Advisory can help

Cyber due diligence sits awkwardly between deal teams who understand value and technical teams who understand systems, and it benefits from someone fluent in both. CISO Advisory provides independent cyber due diligence for Australian buyers and investors, reporting to you with findings expressed in commercial terms. Founder Ken Armitt brings 27 years of hands-on experience across government, financial services and enterprise, and our Virtual CISO service can carry the remediation work through into post-deal integration. If a transaction is in motion, call 07 2112 8502 or visit our contact page to discuss scope and timing.

Frequently asked questions

What is cyber due diligence in an M&A transaction?

Cyber due diligence is the structured assessment of a target company's security posture before a deal completes. It examines the target's controls, breach history, data and IP assets, regulatory exposure and the cost of integrating its systems, so the buyer can price risk accurately and avoid inheriting undisclosed liabilities.

When should cyber due diligence start in a deal?

Ideally during the diligence phase, alongside financial and legal review, well before signing. Starting early gives the buyer time to investigate red flags, renegotiate price or terms, and build remediation costs into the model. Leaving it until after completion means the buyer absorbs every problem without recourse.

Can a past data breach kill a deal?

Not usually on its own, but it changes the calculus. A historical breach matters less than how the target responded, whether it was disclosed, whether the root cause was fixed and whether regulatory or legal exposure remains open. An undisclosed or unremediated breach is a far bigger problem than a managed one.

Who should conduct cyber due diligence?

An independent specialist who reports to the buyer, not the target. Internal IT teams are often stretched and may lack the assessment experience or objectivity. A Virtual CISO or external advisor can run the review, interpret findings commercially and translate technical risk into deal terms the board understands.

How long does cyber due diligence take?

A focused review typically runs two to four weeks depending on the target's size, complexity and how readily it provides documentation. Larger or regulated targets with multiple subsidiaries take longer. The bottleneck is usually access to evidence, so requesting documentation early keeps the timeline on track.

Talk to a Virtual CISO

Need this handled for your organisation?

Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.

Confidential. We typically respond same business day — or call us 24/7.

Frameworks & standards we assess and advise against

Independent, vendor-neutral expertise across the Australian and international frameworks government, regulators and boards rely on.

E8
Essential Eight
ISO
ISO/IEC 27001
NIST
NIST CSF 2.0
CPS
APRA CPS 234 / 230
ISM
ACSC ISM
PSPF
PSPF
IRAP
IRAP readiness
SOC2
SOC 2
PCI
PCI DSS
NDB
Privacy Act / NDB
SOCI
SOCI Act