When You Buy the Business, You Buy the Breach
Cyber diligence is part of the price now, whether you are buying a competitor or selling the company you built.
Executive Summary
Buying a business means buying everything that happened to it before you signed, including the intrusion nobody noticed. Surveys of dealmakers consistently find that an undisclosed breach is an immediate deal breaker for most buyers, and that security problems routinely delay or reprice transactions. If you are buying, a few weeks of security review is cheap protection against inheriting somebody else’s incident. If you are selling, your security posture is something a buyer will examine and price. Here is what to look for, what to fix before you go to market, and why the riskiest day of the process is the one right after closing.
Two Deals That Taught the Market
Marriott acquired Starwood in 2016 and later discovered that attackers had been inside the Starwood reservation system before the deal closed. The breach affected hundreds of millions of guest records. Marriott owned it, disclosed it, and paid the regulatory bill.
Verizon and Yahoo is the other half of the lesson. When undisclosed breaches surfaced during that transaction, the purchase price came down by roughly 350 million dollars. Neither story is about exotic attackers. Both are about what diligence covered and what it did not.
This Is Not Only a Large Company Problem
Smaller deals happen constantly. An owner buys out a competitor. A private equity firm rolls up five regional firms. A founder sells to a strategic buyer after twenty years. In those deals the financial and legal review is thorough, and the technology review is often a conversation with the target’s IT person and a list of licenses.
The exposure is not smaller because the deal is. The acquired company’s email tenant, client records, and payroll data become yours at closing. So does its obligation for regulated data collected years ago, and any claim from a breach that happened before you owned it.
What to Examine Before You Sign
- Incident history, with evidence. Ask directly whether they have had a security incident, ransom demand, or notification event, then ask for the documentation. A confident no with nothing behind it tells you about their visibility, not their safety.
- Who holds the keys. How many administrator accounts exist, who has them, whether multifactor authentication is enforced everywhere, and how many former employees still have working logins. Identity is where the cost usually hides.
- What data they hold, and where. Client records, health or financial information, employee files, and the retention rules that apply. Data you did not know you bought is still data you must protect and disclose.
- The vendor and application list. Every platform and integration they use becomes part of your supply chain at closing, including the ones nobody formally approved.
- Backups that have been restored. Not whether backups run. Whether a restore has actually been performed, and how long it took.
- Insurance and claims history. The current policy, prior claims, and any exclusions. Coverage denied or withdrawn tells you something a seller may not volunteer.
- An outside look at the attack surface. A short external test shows what an attacker sees today: exposed services, forgotten websites, credentials for the target’s domain already circulating. It is quick, and it needs little from the seller beyond permission.
If You Are the One Selling
Most owners prepare for diligence as an accounting exercise. Increasingly it includes a security questionnaire, and vague answers slow deals down or turn into a holdback against the purchase price. A buyer cannot verify a claim you cannot evidence.
Being able to hand over a current asset inventory, proof that multifactor authentication is enforced, a recent penetration test, a tested restore, and a clean incident log removes friction from the stretch where you have the least leverage, which is right after a buyer finds something you did not mention.
The Riskiest Day Is the Day After Closing
Integration is where careful acquirers get breached. Two networks are connected quickly so people can work, and whatever was living quietly in the smaller environment now has a path into the larger one. Attackers read acquisition announcements too, because a merger is a stretch when unfamiliar names making unusual requests is normal.
Keep the environments separate until the acquired one has been examined. Reset privileged credentials and remove dormant accounts before you connect anything. Apply your own identity standard on day one rather than at the end of the integration project. And treat an existing compromise as possible until somebody has looked, because looking costs far less than an inherited incident.
The Terms Can Carry Some of the Weight
Deal documents can require the seller to represent that there are no undisclosed breaches, provide indemnification if that proves wrong, and hold part of the price in escrow against specific remediation milestones. Your counsel will draft the mechanics. What matters for a business leader is that these clauses only bite when diligence produced something specific to name. General language protects nobody.
The Takeaway
Every acquisition transfers risk along with revenue. Seeing that risk clearly takes weeks and costs a fraction of one inherited incident. Buyers who do it pay the right price. Sellers who do it reach the closing table faster. Nobody who skips it finds out cheaply.
How Simulint Helps With BlueSphere
Simulint supports both sides of a transaction. A targeted penetration test and external attack surface review give a buyer an evidence based picture of what they are about to own, and give a seller a clean answer before the questionnaire arrives.
After closing, BlueSphere Shield Elevate provides continuous vulnerability management and cloud posture monitoring across the combined environment. That matters most during integration, when the attack surface changes weekly and old assumptions no longer hold. Learn more: https://lnkd.in/eE9HTaw8
