Perspective · M&A diligence

The cyber risks that reprice a deal

In an acquisition, the liabilities you can't see transfer to you anyway. Cyber and technology risk has become one of the most common (and most expensive) categories of “what we didn't find before we bought.” The good news is that it is also one of the most findable, if diligence looks in the right places.

Two deals every acquirer remembers

When Verizon acquired Yahoo, two previously undisclosed breaches surfaced during the process, ultimately affecting around three billion accounts. The purchase price was cut by $350 million, and Yahoo's successor later drew a $35 million SEC penalty for failing to disclose the incidents in time. The breaches had happened years earlier; no one raised them in the initial diligence.

Marriott's $13.3 billion acquisition of Starwood tells a quieter, more instructive story. Marriott inherited a network compromise that had been active in Starwood's reservation systems since 2014 and went undetected until 2018, exposing hundreds of millions of guest records and leading to years of litigation and a UK data-protection fine of roughly £18.4 million. Marriott later acknowledged it had been able to perform only limited diligence on Starwood's systems during the deal.

The through-line is simple and unforgiving: undisclosed and undetected liabilities transfer to the buyer at close. You inherit not just the assets and the customer base, but the target's entire security posture, including anyone already inside it.

Where the real risk hides

Financial and legal diligence are mature disciplines. Cyber and technology diligence often isn't, and the exposures that reprice deals cluster in a handful of predictable places:

  • Undisclosed or undetected compromise. The breach that has already happened and simply hasn't been found. It is the most damaging finding, and the one a checklist-style review is most likely to miss.
  • Where regulated data actually lives. Not the tidy inventory IT maintains, but the real sprawl across file shares, cloud, backups, and endpoints. Obligations under GDPR, CCPA, HIPAA, or GLBA follow the data, and the breach-notification clock starts at discovery, now on your watch.
  • Security and technical debt. End-of-life systems, unpatched estates, weak identity, and brittle architecture that will cost real money to bring up to standard over the first year or two.
  • Third-party and concentration risk. The vendors, platforms, and dependencies the target relies on but does not control, any of which can become the combined company's incident.
  • IP, licensing, and data provenance. Open-source and licensing exposure, and increasingly whether the target's data and models rest on rights it actually holds.

A sixth, easy to overlook: unresolved regulatory and contractual exposure: open findings, missed notifications, or commitments that don't survive contact with the acquirer's own obligations.

In a deal, undisclosed liabilities don't disappear. They change owners at close.

Diligence as a valuation instrument, not a formality

The firms that get this right treat technical diligence the way they treat quality of earnings, as an input to price and terms, not a box to tick. The findings do real work. Technical debt adjusts the purchase price. Security posture shapes representations and warranties, and the cost of cyber insurance. Concentration risk reshapes the integration budget. Unresolved compliance becomes an indemnity, an escrow, or a condition to close. What you can't see, you can't price; what you don't price, you absorb.

The questions that surface it

A sponsor or acquirer doesn't need to run the assessment personally, but should insist the diligence answers a short, pointed list. Has the target ever been breached, and how do we know, independent of their say-so? Where does regulated data actually reside, and what obligations come with it? What will it realistically cost to bring security to our standard in the first eighteen months? Which third parties could take the combined entity down? And what regulatory or contractual liabilities are we inheriting? Vague answers are themselves a finding.

NorthBridge runs cyber and technology diligence for acquirers and their sponsors, surfacing what reprices a deal before close, and turning it into a remediation and integration plan afterward. If you have a transaction in motion, let's make sure you know what you're buying.

Start a conversation

Related: What boards should ask the CISO, and our illustrative 90-day roadmap.