Cybersecurity Due Diligence: Process, Checklist, and Best Practices

Cybersecurity due diligence assesses a company's security posture before a deal or partnership. Learn the process, checklist, M&A examples, and best practices.
تم كتابته بواسطة
تم النشر في
Monday, August 17, 2026
تم التحديث بتاريخ
August 16, 2026

Cybersecurity due diligence is the process of assessing an organization's security posture, incident history, and cyber risk before a merger, acquisition, investment, partnership, or vendor engagement. 

The risk is concrete: a Forescout survey found that 53% of organizations encountered a critical cybersecurity issue during an M&A deal that put the deal in jeopardy.

Cybersecurity due diligence gives acquirers, investors, and security teams an evidence-based view of what they are taking on before they commit. This guide explains what cybersecurity due diligence is, why it matters, when it applies, what it assesses, the process and checklist behind it, real-world cases, and the practices that make it effective.

What is Cybersecurity Due Diligence?

Cybersecurity due diligence is the structured assessment of a company's security controls, posture, and incident history before a transaction or business relationship. It examines how an organization protects its data and systems, whether it has suffered breaches, and how much cyber risk a buyer or partner would inherit. The assessment applies across mergers and acquisitions, private equity investment, and third-party onboarding. Cybersecurity due diligence moves the evaluation beyond a target's self-disclosure, because a company cannot report a breach it has not detected.

Why is Cybersecurity Due Diligence Important?

Cybersecurity due diligence matters because cyber risk transfers to the acquirer the moment a deal closes. Five reasons make it essential:

  • Inherited liability: regulators hold the acquirer accountable for the target's past breaches under GDPR, HIPAA, and SEC disclosure rules.
  • Deal valuation: a discovered breach lowers the price and reshapes the terms, as the cases below show.
  • Hidden incidents: the assessment surfaces undisclosed or undetected breaches before they become the buyer's problem.
  • Integration risk: connecting an insecure target to the acquirer's network extends the attack surface.
  • Reputation: a breach inherited through an acquisition damages customer trust in the combined company.

Forescout found that 73% of organizations treat an undisclosed breach as an immediate deal breaker, and 65% reported regret after closing a deal because of inherited cybersecurity problems.

When is Cybersecurity Due Diligence Required?

Cybersecurity due diligence applies whenever one organization takes on risk from another. Four situations call for it:

Mergers and Acquisitions

M&A is the primary context. An acquirer assesses a target's security posture and breach history before closing to price the deal correctly and plan integration. Most cybersecurity due diligence happens here.

Investment and Private Equity

Investors evaluate the cyber risk of a company before funding it. A portfolio company with weak security or an undisclosed breach threatens the value of the investment.

Vendor and Third-Party Onboarding

Before granting a supplier access to data or systems, an organization assesses its security. Vendor due diligence repeats on a schedule rather than running once, because vendor risk changes over time.

Partnerships and Integrations

Any partner that connects to an organization's data, APIs, or infrastructure introduces risk. Due diligence confirms the partner's security before the integration goes live.

What Cybersecurity Due Diligence Covers?

A thorough cybersecurity due diligence assessment typically examines eight domains:

cybersecurity due diligence domains

1. External Attack Surface and Exposure

This domain maps the target's internet-facing assets, including domains, subdomains, open ports, and cloud services, and checks them for misconfigurations and exploitable weaknesses. It reflects what an attacker sees from outside.

2. Breach and Incident History

Reviewers examine past breaches, dark-web exposure, and leaked credentials tied to the target. This domain surfaces the undisclosed and undetected incidents that self-disclosure misses.

3. Security Controls and Architecture

This covers the target's defensive controls, network segmentation, patching, and technical debt. Weak architecture signals higher integration cost and risk.

4. Identity and Access Management

Reviewers assess privileged access, multi-factor authentication, and offboarding practices. Excessive privileges and shared accounts are common findings.

5. Data Protection and Privacy

This domain examines how the target stores, encrypts, and handles sensitive and personal data. It establishes whether data practices meet the standards the buyer is held to.

6. Compliance and Regulatory Posture

Reviewers verify standing against GDPR, HIPAA, PCI DSS, ISO 27001, and SOC 2. Compliance gaps carry fines that transfer to the acquirer.

7. Incident Response and Recovery

This covers incident response plans, business continuity, and disaster recovery. It measures how fast the target detects, responds to, and recovers from an attack.

8. Third-Party and Supply Chain Risk

The target's own vendors extend the risk. This domain maps the supply chain dependencies that the buyer would inherit.

Cybersecurity Due Diligence Checklist

This checklist condenses the assessment into concrete items to verify:

  • Scan the external attack surface for exposed assets and misconfigurations.
  • Check the dark web for leaked credentials and signs of a prior breach.
  • Review breach history and breach-notification records.
  • Request security certifications, including SOC 2 and ISO 27001.
  • Assess identity and access management, including MFA and privileged accounts.
  • Verify encryption and data-protection practices.
  • Confirm compliance with applicable regulations.
  • Evaluate incident response, business continuity, and disaster recovery plans.
  • Map third-party and fourth-party dependencies.
  • Quantify remediation cost for use in negotiation.

The Cybersecurity Due Diligence Process

Cybersecurity due diligence runs in three phases tied to the stages of a deal:

Phase 1: Pre-Deal External Assessment

Before a letter of intent (LOI) is signed, the target rarely grants internal access, so the assessment is external. Reviewers map the public-facing attack surface, check the dark web for breach exposure and leaked credentials, review disclosed incidents, and build a threat profile from open sources. This phase produces a go or no-go view without the target's cooperation.

Phase 2: In-Depth Assessment

With the letter of intent signed and access granted, the assessment deepens. Reviewers examine security controls, identity and access management, data protection, compliance, and incident response through documentation, scans, and interviews with the target's security team.

Phase 3: Post-Close Integration

After the deal closes, the work shifts to remediation and integration. The acquirer fixes the gaps found earlier, integrates the target securely, and places the acquired environment under continuous monitoring.

Real-World Cybersecurity Due Diligence Examples

Two cases show what cybersecurity due diligence is built to prevent:

Yahoo and Verizon

During Verizon's 2016 agreement to acquire Yahoo, Yahoo disclosed breaches affecting billions of accounts. Verizon cut the purchase price by $350 million, and the two companies agreed to share breach liability. The case became a reference point for how an undisclosed breach reshapes a deal.

Marriott and Starwood

Marriott acquired Starwood in 2016 without detecting that attackers had been inside Starwood's reservation system since 2014. The breach surfaced in 2018 and exposed roughly 339 million guest records. The UK regulator fined Marriott £18.4 million and cited insufficient due diligence during the acquisition.

Vendor and Third-Party Cybersecurity Due Diligence

Vendor due diligence applies the same assessment to suppliers, partners, and service providers before they gain access to data or systems. It differs from M&A due diligence in cadence: a vendor is assessed at onboarding and reassessed on a schedule, because its risk changes over time. This work sits inside a broader third-party risk management program, and the single-vendor evaluation is a third-party risk assessment. Continuous monitoring keeps the assessment current between cycles.

Challenges of Cybersecurity Due Diligence

Cybersecurity due diligence faces practical constraints:

  • Time pressure: competitive deals compress the assessment into days.
  • Limited access: the target grants little visibility before the letter of intent.
  • Self-disclosure reliance: a target cannot report a breach it has not found.
  • Skills gap: internal teams sometimes lack assessment expertise.
  • Scope breadth: covering every system and dependency is difficult under a deadline.

Best Practices for Cybersecurity Due Diligence

These practices keep cybersecurity due diligence effective:

  1. Start external assessment early, before the letter of intent.
  2. Treat self-disclosure as a starting point, not as evidence.
  3. Check the dark web for breaches the target has not detected.
  4. Quantify findings in financial terms to inform negotiation.
  5. Cover all assessment domains, not security controls alone.
  6. Carry due diligence into post-close integration and ongoing monitoring.

Frequently Asked Questions (FAQ)

What is the difference between cybersecurity due diligence and a security audit?

A security audit measures an organization's own controls against a standard. Cybersecurity due diligence assesses another party's security and inherited risk before a deal or relationship, often with limited access and under deal deadlines.

How long does cybersecurity due diligence take?

Cybersecurity due diligence ranges from a few days for a pre-deal external review to several weeks for a full assessment. Competitive deals compress the timeline, sometimes to 48 to 72 hours for an initial review.

Who performs cybersecurity due diligence?

Specialist cybersecurity firms, the acquirer's internal security team, or advisory partners perform cybersecurity due diligence. Legal, compliance, and deal teams act on the findings during negotiation.

What is cybersecurity due diligence in M&A?

Cybersecurity due diligence in M&A is the assessment of a target's security posture, breach history, and inherited cyber risk before an acquisition closes, so the buyer can price the deal and plan integration accurately.

Can cybersecurity due diligence be done without the target's cooperation?

Yes. Much of the pre-deal assessment is external, covering the public attack surface, dark-web exposure, and disclosed incidents. Internal control review and interviews require the target's cooperation after a letter of intent.

What happens if cybersecurity due diligence uncovers a breach?

A discovered breach reshapes the deal. The buyer renegotiates the price, adjusts terms and liability, requires remediation before closing, or walks away when the risk runs too high.

المشاركات ذات الصلة
AI Supply Chain Security: How to Defend the AI Stack
AI supply chains break where code review can't reach: models, datasets, and gateways. Learn the 7 attack types and 8 controls that defend the AI stack.
CI/CD Credential Exposure: What Attackers Steal From Pipelines and What to Rotate
CI/CD pipelines hold cloud keys, tokens, and signing material attackers steal through builds. Learn the 6 leak paths and the 5-wave rotation order that works.
How to Check If AI API Keys Have Been Leaked
After the 2026 LiteLLM supply chain breach, here's how to check if your AI API keys leaked, and what to do if they did.

ابدأ العرض التوضيحي الخاص بك الآن!

جدولة عرض تجريبي
إصدار تجريبي مجاني لمدة 7 أيام
لا توجد التزامات
قيمة مضمونة بنسبة 100%

مقالات قاعدة المعارف ذات الصلة

لم يتم العثور على أية عناصر.