Cyber due diligence in M&A: what to check before you sign

Before you sign, cyber due diligence should answer three questions: has the target been breached, what data and access are you taking on, and what will it cost to bring the business up to your standard. The answers go to your counsel and your deal team, who turn them into price, conditions and contract protections.

Before signing or after closing?

Before signing, while findings can still change the price, the protections in the agreement or the decision itself. After closing, the same findings become your remediation budget. The mistake is treating cyber as an integration task, found out once the money has moved.

Before signingAfter closing
Breach history and open incidentsHands-on testing, with authorization
What personal and regulated data is held, and whereIdentity and network integration
Key security controls, as evidencedRemediation of the gaps found
Contracts, insurance and security commitments to customersAligning policies and monitoring

What should you check before signing?

  • Breach history. Ask for incidents in recent years, how each was handled and who was notified. Where the target is under PIPEDA, section 10.3(1) requires it to keep a record of every breach of security safeguards involving personal information, and the Breach of Security Safeguards Regulations (s. 6) require it to be kept for 24 months after the day the organization determines the breach occurred. The recent record should exist; an older one may lawfully be gone.
  • Data. What personal, health or payment data it holds, about whom, in which systems and jurisdictions.
  • Identity. How staff sign in, whether multi-factor authentication covers email and remote access, and who holds administrator rights.
  • Recovery. Whether backups exist that ransomware cannot reach, and when a restore was last tested.
  • Commitments. Security promises in customer contracts, independent assurance reports and what they actually cover, and the cyber insurance policy with its claims history.

Ask for evidence, not assurances: a policy is a claim, a configuration export or a restore log is evidence. Interviews with the people who run the systems usually tell you more than the data room.

Can personal information be shared during diligence?

Diligence often involves customer or employee data. Where PIPEDA applies, section 7.2(1) allows parties to a prospective business transaction to share personal information without consent only under an agreement that limits its use to the transaction, requires safeguards, and requires its return or destruction if the deal does not proceed, and only for information necessary to decide on and complete the deal. Share the minimum; samples and counts usually answer the question. Your counsel confirms which Act applies.

How do findings change the deal?

A finding is only useful if it changes something. Each one should say what is wrong, what it would cost to fix, and whether it points to past harm you cannot yet see. Counsel then decides what belongs in representations and warranties, an indemnity, a closing condition or the price. Do we draft those clauses? No. We tell your counsel what the findings mean and what the contract should protect against; drafting representations, warranties and indemnities is counsel’s work.

Expect gaps. The judgement call is which are ordinary remediation and which suggest an undiscovered compromise, because only the second should threaten the deal.

What goes wrong at integration?

The riskiest day is often the one the networks are joined. Do not trust the acquired environment until it has been checked: connect it through a controlled boundary, reset privileged credentials, and bring its accounts into your identity system on your terms. Our approach to vendor evidence is in vendor risk questionnaires that work, and the service in third-party risk and cyber due diligence.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

Testing and adversary simulation are carried out only with signed authorization, to a scope agreed in writing.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

When should cyber due diligence happen?

Before signing, while findings can still change the price, the protections in the agreement or the decision itself. After closing, the same findings become your remediation budget.

Can we scan or test the target’s systems?

Not as part of pre-signing diligence, which is documentary and interview-based. Hands-on testing of the target belongs after closing, and at any stage it needs the signed authorization of whoever owns the systems.

Do you draft the security clauses?

No. We tell your counsel what the findings mean and what the contract should protect against; drafting representations, warranties and indemnities is counsel’s work.

Is it worth doing on a small acquisition?

Yes, sized to the deal. A small acquisition still brings its accounts, its devices and its customer data into your environment, and that is where the risk lands.

Before the next deal

Send the deal timeline and what the data room holds. The reply is a diligence scope sized to the clock, written to sit alongside your counsel’s. More of our writing is at writing.

Discuss a scope