The practical answer
- Short answer
- A late cyber finding doesn't just cost the fix — it reprices the whole deal. How to surface material security exposure during exclusivity, before you sign.
- Best fit
- Industry: Private Equity / M&A. Function: Due Diligence
- Operating path
- Compliance & Security → Turnaround & Restructuring → Turnaround & Restructuring Services
- Key metric
- 53% Buyers who discover critical cyber issues after closing
Day 26 of exclusivity, and someone finally asked for the vendor list
Here is how it usually goes. The financials are clean. The EBITDA bridge holds up, customer concentration is tolerable, the growth story sings. The bankers want to sign. And then, late in the window, somebody on the buy side asks a question nobody had asked yet: who, outside the company, can currently reach production? The answer comes back as a spreadsheet last touched two years ago, listing a managed-services vendor that no longer exists and three API keys nobody can map to a human. That is not a typo in the data room. That is a repricing event you found 96 hours before you were supposed to wire the money.
Security debt is the exposure that never makes the balance sheet but follows the entity through the close anyway: a legacy ERP two major versions behind on patches, an object store left world-readable, domain-admin rights that were granted for one migration sprint in 2023 and never revoked. None of it dings revenue today. All of it becomes your remediation budget, your breach disclosure, and your management distraction the day after you own the cap table.
The headline case is still Verizon and Yahoo, where disclosed breaches were tied to a $350 million cut to the purchase price. People treat that as a mega-deal anomaly. It is not. It is the mid-market story scaled up: the same controls were absent, the same diligence was thin, and the same lever — reprice or walk — got pulled. Below the public-company tier, the lever pulls just as hard; it simply does so in escrow language and indemnity caps instead of press releases.
And the timing is the trap. A Forescout-cited M&A security study found that 53% of buyers discover critical cybersecurity issues only after the deal closes. After close means after you paid the multiple, after you structured the debt, after the seller's reps expired into a survival period you now have to litigate. The finding didn't disappear during diligence. Nobody went looking for it.
When the breach surfaces after close, you didn't buy a problem — you paid full multiple for one and volunteered to fix it on your own dime.
Why the standard IT diligence misses it — and what a finding actually costs
Most IT diligence is a hygiene scan dressed up as risk work. A vendor runs a vulnerability sweep, confirms a firewall exists, and asks whether staff complete phishing training. That tells you the state of the patches on the day of the scan. It tells you nothing about whether this company can notice, prioritize, and close a security gap on its own — which is the only thing that predicts what you'll inherit. A target with a clean scan and a culture of ignored alerts is more dangerous than one with open findings and a disciplined remediation cadence, because the second one is curable and the first one keeps generating new holes after you own it. When we run a portfolio cybersecurity risk assessment, the patch list is the smallest part of the file; the management pattern behind it is the asset.
The reason a single finding moves a deal is that it isn't priced as a repair — it's priced as a band of liability. You're underwriting three numbers at once:
- Remediation capex you can size: rip-and-replace or harden the insecure infrastructure. This one is knowable and goes straight into the 100-day budget.
- Regulatory and contractual exposure you can only bound: GDPR, CCPA, HIPAA, or customer-contract security clauses that travel with the legal entity, not the asset sale you thought you negotiated.
- Trust impact you can't model: the churn and renewal risk if a breach has to be disclosed to customers or partners after you're the owner of record.
The middle and last numbers are why a finding is a deal term, not a line item. IBM's 2024 report puts the global average data breach at $4.88 million — a number that can swallow a mid-market target's annual profit, spook the lender, and consume the management team for two quarters at exactly the moment your value-creation plan needs them.
Change Healthcare in 2024 is the pattern worth memorizing, not just the headline. A single compromised access path cascaded into operational paralysis that reached far past the breached system. The mid-market version is quieter and constant: a platform bolts on an add-on without vetting its identity, backup, endpoint, and vendor-access controls, and inherits the remediation it should have caught in diligence. Where there's high technical debt, security debt is almost always riding along — the same shortcut that defers a refactor defers the patch, the access review, the backup test, and the tabletop.
The 10-day triage: three asks that separate manageable from material
You can't run a forensic audit inside a 30-day exclusivity window, and you don't need to. You need to find the findings that change valuation, escrow, the insurance binder, or the 100-day plan — and you can do that with three requests that are cheap to make and brutally diagnostic in how they're answered.
1. The vendor-access list — and how fast it arrives. Ask for every third party with live VPN, API, or remote access to the core environment. The document matters less than the latency. "We'll need to pull that together" means no one owns it. A two-year-old spreadsheet means it exists but isn't governed. Unmonitored vendor access is the single most common entry point for ransomware and credential abuse in portfolio companies — and the easiest thing to fake a clean answer on, which is exactly why the speed of the response tells you more than the contents.
2. The privileged-user ratio. Count the accounts with root or production-admin rights against headcount. Healthy looks like narrow, reviewed, tied to a specific job. If every engineer can write to production databases, you're buying standing risk, and that becomes a day-one integration and remediation roadmap item — sometimes a holdback, sometimes a specific indemnity carved out of the reps.
3. The last real incident drill. Don't accept the incident-response document. Ask for the artifacts of the last time it was used: the calendar invite, the tabletop notes, the lessons-learned, the actions that actually closed afterward. A plan that has never been exercised is a Word file, not a capability — and you'll find that out the hard way during your hold instead of during diligence.
Whatever those three asks surface, the response is the same discipline: price it, structure it, or walk. A material finding belongs in enterprise value, in escrow, in the indemnity language, in the cyber-insurance review, and in the 100-day budget — not in a hopeful assumption that reps-and-warranties coverage will cover it. R&W is not a diligence substitute; known vulnerabilities and pre-existing conditions are exactly the kind of buyer-owned problem it carves out. On Monday, on your next live deal, send those three asks before you send the LOI. The answers will tell you whether you're buying a company that manages security debt or one that's about to hand you the bill.

