Checklist · Worldwide
M&A Cyber Due Diligence Checklist
Undisclosed breaches, unlicensed data, and unmanaged privileged access have all reduced deal value after signing. This checklist covers what to request during diligence, the findings that should change price or indemnity terms, and how to integrate security in the first 100 days after close.
Documents to request during diligence
- Full incident history for at least five years, including near misses and regulator correspondence.
- Penetration test and vulnerability scan reports, with remediation status for every high finding.
- Current audit reports or certifications, including SOC 2, ISO 27001, and any customer audit findings.
- Asset and identity inventory, covering cloud accounts, domains, and administrative access.
- Data inventory and record of processing activities, with the lawful basis for marketing databases.
- Cyber insurance policy, claims history, and any coverage conditions currently unmet.
- Supplier list with critical dependencies, contract security terms, and open assessment findings.
- Customer contracts containing security commitments, audit rights, or breach notification clauses.
- Open source and software licensing inventory, plus intellectual property provenance for AI models.
- Security team structure, key person dependencies, and open roles.
Red flags that should affect terms
- An undisclosed incident discovered during diligence rather than declared by the seller.
- No multi-factor authentication on administrative or production access.
- Shared or personal credentials used for production systems, with no audit trail.
- Marketing or customer data collected without a documented lawful basis or consent record.
- Backups that are not isolated from production credentials or have never been restore-tested.
- Unsupported or end-of-life systems processing regulated data.
- A single individual holding undocumented knowledge of critical infrastructure.
- Regulatory action, complaint, or ongoing supervisory authority inquiry that was not disclosed.
Technical validation to perform, not just ask about
- External attack surface review of the target's domains, exposed services, and cloud footprint.
- Credential exposure search across breach corpora for target domains.
- Identity configuration review of the primary directory and cloud tenants.
- Verification that claimed certifications are current and cover the systems in scope.
- Confirmation of who controls domain registrations, DNS, and code signing keys.
First 100 days after close
- 01Days 1 to 10: take control of privileged credentials, domains, DNS, and cloud root accounts.
- 02Days 1 to 10: extend monitoring and endpoint detection coverage across the acquired estate.
- 03Days 10 to 30: complete a risk assessment and agree the integration security baseline.
- 04Days 10 to 30: close identity gaps, remove standing admin access, and enforce phishing-resistant authentication.
- 05Days 30 to 60: align policies, incident response escalation, and vendor risk processes.
- 06Days 30 to 60: reconcile data protection obligations, including transfer mechanisms and retention.
- 07Days 60 to 100: remediate the high findings from diligence and report progress against the deal thesis.
- 08Days 60 to 100: decide the target-state architecture: absorb, isolate, or retire the acquired systems.
Evaluating or integrating an acquisition?
Dephiant runs cyber diligence for buyers and sellers, quantifies findings in deal terms, and leads the post-close security integration.