Where We Help Experience Insights Resources Leadership Book a Meeting →

Cybersecurity Due Diligence for Private Equity: From Findings to Deal Decisions

A buy-side framework for translating cybersecurity diligence findings into valuation adjustments, contractual protections, closing requirements, insurance actions, and funded post-close remediation.

← All insights
The short version

Cybersecurity diligence should convert each material exposure into a credible loss scenario, test it against operating evidence, and distinguish potential losses from remediation costs. The investment team can then assign an explicit response: reprice, protect contractually, require action before close, fund remediation after close, seek insurance protection, or decline the transaction.

Cybersecurity due diligence creates transaction value only when it changes a decision. A maturity score or list of missing controls is not enough. The investment committee needs to know what could happen, how it would affect the business, what evidence supports the assessment, what it will cost to reduce the risk, and who should bear the remaining exposure.

The practical output is a deal-response matrix. For each material cyber scenario, it should identify:

  1. The credible business impact.
  2. The evidence supporting or contradicting the scenario.
  3. The potential financial exposure.
  4. The one-time remediation spending and recurring operating costs.
  5. The required transaction response.
  6. The accountable owner and deadline.

The response may include a valuation adjustment, specific indemnity, escrow, representation, closing requirement, insurance action, funded post-close program, or decision not to invest. One finding may require several responses.

Start with loss scenarios, not control deficiencies

A finding such as “multifactor authentication is incomplete” describes a control gap. It does not explain the deal risk.

A useful diligence conclusion connects the gap to a plausible event and its business consequences. For example:

Privileged accounts used to administer the company’s production environment are not consistently protected by multifactor authentication. A compromised account could allow an attacker to disrupt the hosted product, access customer information, or alter production data. The exposure could include lost revenue, incident-response costs, customer claims, regulatory consequences, and delayed integration.

NIST IR 8286A recommends documenting risk scenarios based on the potential impact of threats and vulnerabilities on enterprise assets, assessing likelihood and impact, considering risk appetite and tolerance, and using the resulting information to support prioritization and response. [1] NIST’s business-impact guidance separately analyzes potential harm from losses of confidentiality, integrity, and availability. [2]

This distinction matters in underwriting. Two companies can have the same missing control but face very different exposure. The consequences depend on what the affected systems do, what data they contain, how quickly operations can be restored, and which contractual or regulatory obligations apply.

A deal team should organize findings around a limited number of material scenarios, such as:

  • Ransomware or destructive disruption of revenue-generating operations.
  • Exposure of regulated, customer, employee, or commercially sensitive data.
  • Compromise of a software product or its development and deployment process.
  • Fraud or unauthorized payments caused by account compromise.
  • Loss of a critical third party or cloud service.
  • An undisclosed historical incident with uncertain scope or continuing access.
  • Security weaknesses that prevent integration with the buyer, platform, or major customers.

The goal is not an exhaustive threat catalog. It is to identify scenarios that could affect cash flow, liquidity, customer retention, integration, or exit value.

Test whether controls work in practice

Policies and management presentations establish intent. They do not prove execution.

NIST’s guidance for organizational profiles states that a current-state assessment may include artifacts containing evidence that an intended cybersecurity outcome is being achieved. [3] In transaction diligence, the requested evidence should correspond to the scenario under review.

Evidence may include:

  • Identity-provider exports showing multifactor authentication coverage.
  • Lists of privileged, dormant, shared, and service accounts.
  • Endpoint-management and detection coverage reports.
  • Backup architecture, recent restore tests, and recovery timing.
  • Security alerts, incident tickets, forensic reports, and breach notifications.
  • Vulnerability data showing aging, ownership, and remediation history.
  • Cloud configuration and logging records.
  • Software-development access controls and deployment logs.
  • Data inventories, retention settings, and deletion evidence.
  • Third-party security reports and management’s responses to exceptions.
  • Cyber insurance applications, exclusions, claims history, and control attestations.

The evidence should also reconcile across sources. If management says all employees use multifactor authentication, the identity-provider report should support that claim. If recovery is said to take four hours, a recent restoration test should show a comparable result. If management reports no material incident, incident records, insurer disclosures, legal correspondence, and technical telemetry should not indicate otherwise.

Missing evidence is not proof of a breach or failed control. It is uncertainty. The investment committee should reduce, price, allocate, or reject that uncertainty rather than convert it into false confidence.

Separate loss exposure from remediation cost

A central distinction in cybersecurity diligence is the difference between exposure and remediation.

Loss exposure is the financial effect if the scenario occurs or has already occurred. It can include operational interruption, lost sales, customer concessions, legal defense, notification, forensic investigation, fraud, regulatory action, contractual claims, and reputational damage.

Remediation cost is what the business must spend to reduce the likelihood or impact of the scenario. It may include new technology, implementation services, internal staffing, external monitoring, system redesign, or replacement of unsupported infrastructure.

The two figures are not interchangeable. A $300,000 remediation program does not make the underlying exposure $300,000. Nor does a large theoretical loss justify spending the same amount on controls.

Underwriting should use four separate estimates:

EstimateDecision it supports
Probable exposureExpected cash-flow and liquidity implications under the most credible scenario
Tail exposureWhether the downside could exceed the deal’s risk tolerance or threaten the investment thesis
One-time remediationIncremental investment required to reach an acceptable control state
Recurring operating costEffects on run-rate EBITDA, staffing, insurance, and the ownership plan

These estimates should be ranges with explicit assumptions. Precision is rarely credible when incident scope, legal consequences, or customer behavior remains uncertain.

The SEC’s incident-disclosure framework offers a useful materiality lens even when the target is not public. Covered public companies must consider all relevant facts and circumstances, including quantitative and qualitative factors, and disclose a material incident’s impact or reasonably likely material impact on financial condition and results of operations. [6] Private equity underwriting should be equally concrete about how a cyber scenario reaches revenue, EBITDA, working capital, liquidity, and enterprise value.

Assign each material scenario to a deal response

The response should reflect the nature, timing, and allocability of the risk. Technical severity alone does not determine transaction treatment.

SituationDeal response to evaluate
A known historical incident creates identifiable liabilitiesSpecific indemnity, escrow or holdback, liability allocation, insurance review, and possible repricing
The exposure reduces sustainable earnings or adds recurring costValuation adjustment and revised operating model
Material one-time work is required to support the investment thesisFunded value-creation plan, purchase-price consideration, or seller-funded remediation
A vulnerability creates unacceptable signing-to-close or integration riskClosing condition, pre-connection requirement, or restricted integration sequence
Evidence is incomplete but can be resolved before closeAdditional diligence, forensic work, delayed signing or closing, or conditional protection
The risk is manageable without immediate containmentBudgeted post-close remediation with milestones and verification
The downside cannot be bounded or allocated within the fund’s risk toleranceDecline the transaction

Reprice when the finding changes the economics

A purchase-price adjustment is most defensible when the finding changes expected cash flow, required investment, sustainable EBITDA, or the probability of achieving the exit case.

Price is not a substitute for an operating plan. If the company must replace unsupported infrastructure, hire security leadership, redesign a product control, or satisfy customer requirements, the underwriting model should include the cost and timing even after a price adjustment.

The Yahoo-Verizon transaction illustrates how a disclosed cyber issue can affect more than price. After Yahoo disclosed its 2014 data breach, Verizon renegotiated the acquisition price downward by $350 million, a 7.25 percent reduction. [4][5] The amended agreements also allocated specified post-closing liabilities related to data security incidents and other data breaches between the parties. [5]

Use contractual protection for allocable liabilities

Specific indemnities, escrows, holdbacks, representations, covenants, and closing conditions solve different problems. Counsel should structure them according to the facts, governing law, and negotiated allocation of risk.

A specific indemnity may address a known historical exposure that remains with the buyer after closing. An escrow or holdback may improve the practical collectability of that protection. A covenant can require specified action before or after close. A closing condition can prevent the buyer from accepting an exposure that must be removed before ownership transfers or systems connect.

Representations and warranties insurance should not be treated as the primary answer to a known cybersecurity problem. RWI provides protection for certain unintentional and unknown breaches of seller representations and warranties. [10] A known issue may require direct allocation, remediation, separate insurance treatment, or a change in price.

Cyber insurance diligence should examine limits and uninsured exposure, claims history, retroactive dates, continuity through the transaction, recurring premiums, one-time coverage costs, and relevant purchase-agreement warranties. [9] The question is not simply whether a policy exists. It is whether coverage will respond to the scenario, entity, and period at issue after the transaction.

Require action before close when waiting is unsafe

Not every control gap belongs in a closing condition. That approach creates execution risk and distracts from the exposures that genuinely cannot wait.

Pre-close or pre-connection requirements deserve consideration when:

  • There are indicators of active compromise.
  • The scope of a historical incident remains unresolved.
  • A critical vulnerability is readily exploitable and affects essential systems.
  • Existing access could expose the buyer or platform after integration.
  • Reliable backups or recovery capabilities are absent from a business that depends on operational continuity.
  • The target cannot lawfully or contractually continue an important activity without corrective action.

The Marriott-Starwood matter shows why acquired environments require continued scrutiny. The UK Information Commissioner’s Office found that the Starwood systems were compromised in 2014, before Marriott acquired Starwood in 2016, and that Marriott did not detect the attack between the acquisition and September 2018. [7] The regulator imposed an £18.4 million penalty concerning Marriott’s failure to apply appropriate measures to personal data processed in the Starwood environment between May 25 and September 17, 2018, the period covered by its GDPR findings. [7]

The transaction implication is narrower than the facts are sometimes made to suggest: acquired systems should not be assumed safe because ownership has changed. Connection should follow containment and verification, not precede it.

Build the post-close plan before approving the investment

“Remediate after close” is not a plan. A credible Day 1 and first-100-day program should specify scope, budget, accountable executives, external support, dependencies, milestones, and verification.

At minimum, the plan should answer:

  • What must be contained on Day 1?
  • Which accounts, connections, data flows, and systems require immediate restriction?
  • What forensic or legal work remains open?
  • Which actions are prerequisites for integration?
  • What can be completed in 30, 60, and 100 days?
  • What requires a longer modernization program?
  • Which costs are one-time, and which affect run-rate EBITDA?
  • Who has authority to make decisions and accept residual risk?
  • What evidence will demonstrate completion?
  • How will the board and sponsor receive progress reports?

The plan should also account for applicable external deadlines. Under the Department of Justice’s current Justice Manual, an acquirer may qualify for a presumption in favor of declination for misconduct uncovered through acquisition-related diligence if specified conditions are met. Timely disclosure generally means within 180 days after closing, and timely remediation generally means within one year, although prosecutors retain discretion to extend those periods based on the circumstances. [8] The policy’s relevance depends on the facts and requires legal advice, but it reinforces a broader point: post-close discovery does not provide an unlimited remediation window.

For add-on acquisitions, the cyber plan should align with the broader decision about what to standardize and what to keep local. Identity, privileged access, endpoint visibility, incident response, backups, and security monitoring often require decisions before broader consolidation begins.

Give the investment committee a decision document

The final diligence output should preserve the technical evidence, but its core decision document can be concise. For each material scenario, present:

  • Scenario: What could happen, or may already have happened?
  • Affected assets: Which operations, systems, products, data, and entities are exposed?
  • Evidence: What was tested, and what remains unverified?
  • Business impact: How would the event affect customers, revenue, EBITDA, liquidity, integration, or exit?
  • Exposure range: What are the probable downside, tail downside, and level of confidence?
  • Remediation: What one-time and recurring spending is required?
  • Transaction treatment: Reprice, indemnify, escrow, insure, require action before close, fund work after close, or decline?
  • Owner and deadline: Who is accountable, and when will completion be verified?

This approach fits within a broader private capital technology decision process. It also creates continuity between diligence and ownership. A finding that affects underwriting should become a funded workstream with evidence-based closure, not disappear into a report after closing.

Know when remediation is not enough

Many cybersecurity control deficiencies can be fixed technically. That does not make every affected company investable.

Declining the transaction may be appropriate when the team cannot bound a potentially material historical incident, management has concealed or misrepresented evidence, the product’s security architecture undermines its commercial viability, essential operations cannot be protected within the available time and capital, or the residual downside exceeds the fund’s tolerance after contractual protection.

The decision is not whether engineers could eventually improve the environment. It is whether the buyer can understand, allocate, finance, and execute the risk within the transaction and ownership plan.

Useful cybersecurity diligence therefore requires technical and transaction judgment. The work must test operating evidence, translate findings into financial consequences, shape deal terms, and continue through remediation. That continuity is part of what a technology operating partner for private capital should provide.

Sources

  1. 1
    Identifying and Estimating Cybersecurity Risk for Enterprise Risk Management, NIST IR 8286A Rev. 1National Institute of Standards and Technology · 2025-12-18 · accessed 2026-09-28
  2. 2
    Using Business Impact Analysis to Inform Risk Prioritization and Response, NIST IR 8286DNational Institute of Standards and Technology · 2022-11-17 · accessed 2026-09-28
  3. 3
    NIST Cybersecurity Framework 2.0: Quick-Start Guide for Creating and Using Organizational ProfilesNational Institute of Standards and Technology · 2024-02-26 · accessed 2026-09-28
  4. 4
    In the Matter of Altaba Inc., formerly Yahoo! Inc.: Order Instituting Cease-and-Desist ProceedingsU.S. Securities and Exchange Commission · 2018-04-24 · accessed 2026-09-28
  5. 5
    Yahoo! Inc. Current Report on Form 8-K: Amendment to Verizon Transaction AgreementsU.S. Securities and Exchange Commission · 2017-02-21 · accessed 2026-09-28
  6. 6
    Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure: A Small Entity Compliance GuideU.S. Securities and Exchange Commission · 2023-08-30 · accessed 2026-09-28
  7. 7
    Marriott International Inc, Penalty NoticeInformation Commissioner's Office · 2020-10-30 · accessed 2026-09-28
  8. 8
  9. 9
    Cyber Due Diligence in M&AMarsh · accessed 2026-09-28
  10. 10
    Representations and Warranties InsuranceChubb · accessed 2026-09-28
EE Solutions

Need a senior technology team around the decision?

EES works with private capital firms and portfolio companies from technical assessment through execution.

Book a Meeting →