Do Non-Technology Companies Need IT Due Diligence in M&A?

By Stan Kreydin, Managing Director of Cyber Risk and Technology Advisory

IT due diligence is relevant even when an acquisition target in the deal is not necessarily a manufacturer, distributor, healthcare provider, or professional services company. Most middle-market businesses depend on cloud applications, ERP systems, Microsoft 365, third-party vendors, customer data, and digital infrastructure, which can create cybersecurity, cost, compliance, and integration risks for a buyer.

A common conversation in lower- and middle-market M&A is that the target is not a technology company, so technology diligence can be limited or skipped entirely. The target may manufacture products, distribute equipment, or provide professional services.

But that does not mean the company is not dependent on technology. A typical non-technology business may still rely on Microsoft 365, ERP or accounting systems, customer relationship management platforms, industry-specific applications, cloud storage, SaaS tools, managed service providers, and cybersecurity vendors. The risk is often not sophisticated proprietary technology. It is technology sprawl.

What Does Technology Sprawl Look Like?

A company may have a dozen SaaS applications that employees subscribed to individually, each with its own credentials and company data. Former employees may still have active accounts. Customer information may sit in cloud tools that were never formally vetted. An ERP may be aging, undocumented, heavily customized, or dependent on a single employee or an outside provider. Contracts may include renewal provisions or change-of-control terms that were not considered in the deal model. None of these scenarios requires the target to be a software company. They are normal technology risks within an operating business.

What Can Become a Day 1 Problem?

For a buyer, these issues can pose immediate integration challenges. Examples include vendor contracts that create unexpected costs, incompatible systems, excessive or unmanaged user access, unsupported software, weak cybersecurity controls, sensitive data stored in unapproved applications, and technology investments not reflected in the operating plan. A managed service provider may help maintain the target’s existing environment, but that does not necessarily mean the provider has been engaged or scoped to evaluate the environment from an M&A perspective. Those are different objectives.

Common Questions

  • Does a manufacturer need cybersecurity diligence? Potentially, yes. Manufacturers often rely on ERP systems, connected devices, cloud platforms, operational technology, customer information, and third-party vendors that can create cybersecurity exposure.
  • Can IT issues affect valuation? Yes. Material remediation costs, required system replacements, cybersecurity incidents, contractual obligations, or integration challenges can affect the economics of a transaction.
  • Should IT diligence be performed on every acquisition? The scope should reflect the target, the transaction, and the buyer’s investment thesis. The key question is not whether the company is a technology company, but how dependent the business is on technology and what risks the buyer will inherit at close.

If you have questions about cyber risk and technology advisory services or are ready to begin your engagement, please contact Stan Kreydin at [email protected].