Cybersecurity due diligence in M&A: a strategic lever or a costly misser?

post-title

Some of the biggest M&A deals turned into financial nightmares due to undiscovered cyber risks. Why do cybersecurity blind spots still slip through due diligence, jeopardizing billion-dollar deals? And more importantly, can cyber risk management become a strategic advantage instead of a costly oversight?

By Lucas Kuijper MSc & Prof. Dr. Yuri Bobbert

Introduction
What do mega deals like Starwood, Tiscali, Yahoo, SBTech, MyFitnessPal, Altran, and Amerigroup have in common? Each seemed like a strategic masterstroke at the time, yet all were soon overshadowed by cyber incidents - some occurring before, others during, or immediately after the acquisition.

A striking example is Marriott International’s 2016 acquisition of Starwood. What was meant to be a market share boost turned into a nightmare in 2018 when a large scale data breach came to light. Forensic investigations revealed that the attack originated from Starwood’s mission critical reservation system, which had been compromised as early as 2014 - a risk that went undetected during the acquisition process (Fruhlinger, 2020: CSO Online). As a result, Marriott faced years of lawsuits, reputational damage, and lost 6 percent of its market value due to the financial impact of the breach (Reuters, 2018: Yahoo Finance).

Ironically, these companies held respected security certifications such as ISO 27001 and were known for their strong corporate governance and mature IT processes. Yet if certified ‘compliance perfection’ fails to prevent digital disasters, what do these certifications truly say about an organization’s real cyber resilience? More importantly, why does cybersecurity remain an afterthought in M&A due diligence when a data breach can instantly devalue a deal? It is high time to challenge the traditional sacred cows of due diligence and rethink what is truly needed to incorporate cyber risk management into acquisition strategies.

Cybersecurity as blind spot in M&A
Previous research among 780 companies in private equity portfolios found that nearly one-fifth (19 percent) exposed serious cyber risks immediately after acquisition - a staggering percentage for deals that were already considered ‘closed’ and legally sealed. In some cases, these risks led to operational disruptions, reputational damage and unexpected financial setbacks.

These ‘zero tolerance findings’ showed that even after intensive due diligence, IT red flags were missed. This raises a fundamental question: if cyber risks can have such a big impact, why do they remain an under-researched aspect in the due diligence process?

With IT as the backbone of today's digital age and the constant threat of cyber-attacks on enterprises, cybersecurity is no longer just a defensive measure. Even in M&A deals, where company sensitive information is in flux, cybercriminals are making sophisticated calculations to determine maximum ransom amounts and force organizations to pay in crypto currencies.

Financial services, healthcare and technology companies remain attractive targets not only because of their valuable data, but also because of the urgency with which they must recover after an attack. As a result, cybersecurity is increasingly becoming a strategic tool that directly contributes to creating and protecting enterprise value. Whether platform acquisitions, add-ons or strategic exits, the degree to which an acquisition candidate manages its digital infrastructure can mean the difference between a valuable transaction and a costly miss.

Businesscase for cybersecurity in M&A

The hidden risks: how IT can drain deal value
In traditional mergers and acquisitions, the focus of due diligence is primarily on financial and legal risks. Cyber risks are often only formally hedged through warranties in the share purchase agreement, but in practice these vulnerabilities prove difficult to quantify and not fully controlled legally. This results in ‘zero tolerance findings’ – undiscovered IT system vulnerabilities that only come to light after closing and undermine the core value of the transaction.

First-hand case studies show that these risks are anything but hypothetical. The collapse of DigiNotar and the Yahoo-Verizon data breach show how IT incidents lead to costly litigation, stock price declines and even bankruptcies. Buyers who do not perform sufficient IT due diligence can inadvertently buy themselves a ‘a pig in a poke’ with hidden IT problems killing future growth and synergy benefits.

Technical debt – such as outdated systems, inadequate security measures or complex IT legacy architectures – can also affect an acquired company's operational efficiency and scalability. Without a proper analysis, the buyer can face unexpected costs and investments after closing that undermine the original deal assumptions.

Cybersecurity Due Diligence as leverage for value creation
A well-executed cybersecurity due diligence process does more than mitigate risk – it can actually generate strategic value. By uncovering technical deficiencies early, buyers can avoid unexpected costs and compliance risks. For example, overdue IT investments and outdated systems are identified in a timely manner before they show up as a financial burden after closing.

It also provides a potential negotiating advantage. For example, when cyber risks or technical debt are identified, buyers can force a discount on the enterprise value or agree on financing constructions such as loan-to-equity bridges, which means that necessary IT investments do not have to be directly covered by the buyer.

IT due diligence is also a catalyst for post-merger success. A clear integration strategy enables buyer and seller alike to unlock immediate value and maximize operational efficiency. Well integrated and secure IT environments make companies more scalable, innovative and resilient to cyber threats – a factor that is increasingly weighed in the valuation multiple. So by leveraging IT as a strategic resource rather than a cost, an acquisition can pay off faster and more effectively.

Example
An example of how IT due diligence actually adds value is the case of publicly traded company Heidelberg Materials. By performing cybersecurity due diligence on its own organization, it became apparent that a strong IT security foundation was lacking to support further growth. Rather than build this infrastructure organically, Heidelberg chose to acquire a company that already had its IT architecture and particularly cybersecurity well in place. An acquisition like this not only saved them the time and expense of setting up an internal IT department, but also accelerated the organization's digital transformation and scalability. This minimized IT operational risk and increased shareholder confidence, contributing to a doubling of share value.

Moving from insight to action

Effective Cybersecurity Due Diligence goes beyond a standard IT scan. It's not just about what technologies and systems are in place, but more importantly how well the organization is able to manage cyber risk. A company can have wonderful compliance certifications and run a mature IT department on paper, but if fundamental controls are lacking, the risk of digital disaster remains on the horizon.

To make this transparent, basic cybersecurity due diligence begins with an inventory of all digital assets. This means not only software licenses, user accounts, network and hardware devices, but also the extent to which these assets are protected against cyber threats. A fragmented and poorly maintained IT landscape often indicates structural problems, such as inadequate patch management, outdated encryption standards and poor access and authorization controls. In short, if the digital infrastructure is a mess, as a buyer you need to pay attention on the true costs hidden in future IT investments.

But what exactly should you pay attention to?
Here are some fundamental areas of concern that directly impact deal value and post-merger risks:

• Security governance & awareness
How mature is the organization when it comes to cybersecurity? Is there a clear strategy, policy and accountability, or is it more of an adhoc approach? Security training and employee awareness programs are a key indicator. After all, a cybersecurity policy is meaningless if employees don't comply with it.

• Data governance & data breaches
Where is business and customer data stored? On a securely managed and monitored platform or in a jungle of scattered databases, legacy systems and cloud environments with no clear ownership? How is data secured and managed? And perhaps more importantly, what is the history of data breaches and how has it been responded to? A company that only finds out about an incident when it has been circulating on the (dark) web for months does not inspire confidence in the effectiveness of its security operations.

• Incident response, business continuity & vendor dependencies
How well prepared is the organization for a cyber-attack or data breach? Are there clear incident response plans and disaster recovery mechanisms, and are they regularly tested? A fundamental question is: Can the acquisition target recover independently in the event of a security breach, or is it completely dependent on external parties?

This is where the distinction between SaaS-based infrastructures and on-premises IT comes into play. An organization that outsources everything to third parties has less operational responsibility, but is also dependent on the security standards and responsiveness of its suppliers. What happens if that supplier is hacked? How quickly can the company be up-and-running again without complete external dependence? In many cases, the degree of control over the IT environment can be critical to the organization's cyber resilience.

• Critical IT systems & revenue impact
Not all IT systems are equally critical, but systems that directly contribute to revenue such as e-commerce platforms, ERP systems and core applications require extra attention. A ransomware attack on a billing system or supply chain IT can cause immediate financial damage and jeopardize business continuity.
Yet the importance of other systems should not be underestimated. A hack on an HR or CRM system can lead to a report to the governing authorities, reputational damage and regulatory fines, especially if sensitive personal or customer data ends up on the street.

Conclusion: not a luxury, but a necessity

M&A is all about managing risk and maximizing value. Yet cybersecurity often remains an insufficiently important aspect within due diligence, while the impact on deal value, compliance and operational continuity can be significant.

Those who discover cybersecurity only after closing run the risk of unexpected costs, regulatory fines and a deteriorated financial position that may lead to forced cost reductions or investment write downs. Cyber risks cannot simply be swept away in the purchase guarantee. A data breach or failing IT infrastructure after closing quickly becomes a pig in a poke when it turns out that the company is technically or operationally unable to combat cyber threats.

What legally appears as a covered risk can look very different in practice: operational disruptions, compliance problems and lengthy recovery costs. Fast, targeted Cybersecurity Due Diligence not only protects against hidden risks, but also gives buyers an early grip on the acquisition candidate's IT structure. It prevents unwanted surprises and helps ensure a smooth integration.

Furthermore, not every sector has the same requirements. A fintech with customer data in the cloud requires different security checks than a manufacturing company with industrial IT. Customization is essential: assess data governance, vendor dependencies and the risk of lost revenue when critical systems fail.

Takeaway:
Incorporate cybersecurity into the core of the due diligence process. Ask the right questions to the seller side before closing and leverage the insights in negotiation and integration planning. Cybersecurity is not a solitary compliance check, but a strategic factor in the success of the deal.

About the authors

LUCAS KUIJPER MSc

Is the Group Head of IT focusing on IT Governance, Risk, and Compliance at Normec, a rapidly growing provider of testing, inspection, certification, and compliance (TICC) services, backed by private equity firm Astorg. He drives IT integration and leads IT due diligence as part of Normec’s active buy-and-build strategy, which has resulted in over 70+ acquisitions and contributed to the company’s valuation exceeding 2 billion euros. Previously, he held roles as IT Director and Cybersecurity Consultant in corporate organizations. As the founder of Egenix, he applies his expertise in digital transformation to help businesses navigate IT challenges and sustain value creation. He holds a Master’s degree in IT Risk & Cybersecurity Management from Antwerp Management School.

PROF. DR. YURI BOBBERT

Is a professor at Antwerp Management School (Antwerp, Belgium), Global Chief Securitystrategy Officer at ON2IT, and co-founder of Anove International. He is the former global head of IT security, risk, and compliance at NN Group NV, where he led the digital due diligence and integration process for the acquisition of DeltaLloyd. This 2.5 billion euros deal created the largest life insurance company in the Netherlands.

Related articles

Margot Desseyn: M&A is a people’s business

KooKoo co-founder Margot Desseyn fell in love with dealmaking because of the people; now she brings them together to discuss the strategies behind making these deals a success, and will join the M&A Community Belgium on 24 September 2026 in Antwerp to do it again.

Carve-outs give management a real opportunity to lead

During a recent M&A Community Belgium event, Syntagma Capital advisory board member and VIU founder Rudi Nerinckx revealed the top priorities on a carve-out HR agenda; from competency audits and TSAs to value creation plans.

Quanteus Group: Investing with impact – a conversation with Joachim Vansanten

Joachim Vansanten, Partner at Quanteus Group, believes that it’s possible to generate profit and create impact without compromising on either. With a hands-on approach, a strong focus on impact, and a long-term vision, the investment firm distinguishes itself in a market often dominated by short-term thinking.

Kinepolis acquires 13 US Showcase cinemas for 30 million dollars

Kinepolis Group (Euronext: KIN), the Belgian cinema chain, has signed a definitive agreement to acquire 13 Showcase Cinemas from Harbor Lights Entertainment (formerly National Amusements Inc.), marking a significant expansion of its US footprint.

Top