By Stan Kreydin, Managing Director of Cyber Risk and Technology Advisory
IT and cybersecurity due diligence should begin early enough in an M&A transaction to influence valuation, deal structure, negotiation, insurance considerations, and integration planning. Every deal team has a budget line for legal, another for financial diligence, and another for the advisor managing the process. IT and cybersecurity diligence does not always receive the same treatment. It may be folded into a questionnaire or introduced late in the process after something in the data room raises a concern. That sequencing matters.
What Can Late Technology Diligence Miss?
The risk that appears after signing is not always something that could never have been discovered. Sometimes it is simply something no one was asked to investigate early enough. Examples include a cybersecurity incident that predates the transaction, former vendors with active system access, administrative credentials that were never rotated, unsupported infrastructure, insurance exclusions, technology investments required immediately after close, and key-person dependencies. If those issues surface late, the buyer may have fewer options. The structure may already be in place. Negotiating leverage may be reduced. The integration timeline may already be underway.
Why Should IT and Cyber Diligence Have a Dedicated Scope?
Technology and cybersecurity affect multiple aspects of a transaction. A material finding could influence protections in the purchase agreement, valuation, escrow or indemnification considerations, cyber insurance, Day 1 readiness, integration priorities, post-close capital expenditures, employee retention, or vendor transition plans.
A dedicated workstream allows the buyer to determine which technology risks are material to the transaction, rather than relying on a generic questionnaire to identify them.
When Is the Right Time to Begin?
There is no single point that applies to every transaction, but the work should begin while findings can still influence decisions. That generally means treating IT and cyber diligence like other core diligence workstreams: establishing an appropriate scope early, identifying the required information, reviewing supporting evidence, and leaving enough time to investigate emerging issues. The purpose is not simply to document risk. It is to understand risk while there is still time to act.
If you have questions about cyber risk and technology advisory services or are ready to begin your engagement, please contact Stan Kreydin at [email protected].