In 2017, Verizon knocked $350 million off its acquisition price of Yahoo after discovering the company had suffered two massive data breaches affecting over three billion accounts. That's not a rounding error. That's what happens when cybersecurity due diligence gets treated as a last-minute checkbox instead of a core business function.

I've watched organizations spend months scrutinizing financial statements, legal liabilities, and revenue projections — only to skip a meaningful review of a target's security posture entirely. The result is inherited vulnerabilities, undisclosed breaches, and seven-figure remediation costs that nobody budgeted for.

This post breaks down what cybersecurity due diligence actually looks like when it's done right, where most companies fail, and how to build a repeatable process that protects your organization — whether you're acquiring a company, onboarding a vendor, or entering a strategic partnership.

What Is Cybersecurity Due Diligence?

Cybersecurity due diligence is the systematic evaluation of an organization's security posture before entering into a business relationship — merger, acquisition, investment, or vendor engagement. It goes beyond asking "do you have a firewall?" and digs into policies, architecture, incident history, regulatory compliance, and the human factors that cause most breaches.

The goal isn't perfection. It's identifying material risks so decision-makers can price them, mitigate them, or walk away.

The $4.88M Reason This Can't Wait

IBM's 2024 Cost of a Data Breach Report pegged the global average breach cost at $4.88 million. That number climbs significantly when a breach involves a third party or goes undisclosed during a transaction.

I've seen deals close where the acquiring company discovered — weeks later — that the target had no multi-factor authentication on its VPN, no endpoint detection, and a ransomware incident from six months ago that was quietly handled with a Bitcoin payment and zero disclosure. By then, the liability was fully transferred.

Cybersecurity due diligence exists to prevent exactly that scenario. It's not about being paranoid. It's about being informed.

Where Most Companies Fail at Cybersecurity Due Diligence

1. Relying on Questionnaires Alone

Security questionnaires are a starting point, not a finish line. I've reviewed hundreds of vendor assessments where companies checked "yes" to every control — then couldn't produce evidence for a single one.

Questionnaires tell you what an organization claims. Technical validation tells you what's actually true. You need both.

2. Ignoring the Human Layer

Most data breaches trace back to social engineering and credential theft, not sophisticated zero-day exploits. The 2024 Verizon Data Breach Investigations Report found that 68% of breaches involved a human element — phishing, stolen credentials, or simple errors.

If your due diligence process doesn't evaluate security awareness training programs, phishing simulation results, and employee access management, you're ignoring the biggest attack surface. Period.

3. Skipping Incident History

Every organization has had security incidents. The question is whether they detected them, responded effectively, and learned from them. Ask for incident response plans, post-incident reports, and evidence of tabletop exercises. A company that can't produce any of this hasn't been incident-ready — or hasn't been honest about past events.

4. Not Assessing Third-Party Risk Recursively

Your target's vendors are your vendors now. The SolarWinds supply chain attack in 2020 proved that threat actors don't need to compromise you directly — they just need to compromise someone you trust. Due diligence must evaluate how the target manages its own third-party risk.

A Practical Cybersecurity Due Diligence Checklist

Here's the framework I recommend. It's not exhaustive, but it covers the areas where I see the most material risk.

  • Governance & Policy: Written information security policy, acceptable use policies, data classification standards, board-level cyber risk reporting.
  • Technical Controls: Multi-factor authentication deployment, endpoint detection and response, network segmentation, encryption at rest and in transit, patch management cadence.
  • Identity & Access Management: Privileged access controls, least-privilege enforcement, regular access reviews, zero trust architecture progress.
  • Incident Response: Documented IR plan, evidence of testing (tabletop or live), breach notification procedures, cyber insurance coverage details.
  • Human Risk: Security awareness training frequency and completion rates, phishing simulation metrics, onboarding/offboarding procedures.
  • Regulatory Compliance: HIPAA, PCI-DSS, SOC 2, GDPR, CCPA — whatever applies to the target's industry and geography. Ask for audit reports and remediation timelines for findings.
  • Third-Party Risk: Vendor management program maturity, critical vendor inventory, evidence of vendor assessments.
  • Data Inventory: What sensitive data exists, where it resides, who has access, and how it flows between systems and partners.

The M&A Blind Spot: Inherited Breach Liability

When Marriott acquired Starwood in 2016, it unknowingly inherited a breach that had been active since 2014. The breach wasn't discovered until 2018, exposing approximately 500 million guest records. The UK's Information Commissioner's Office fined Marriott £18.4 million.

This is the nightmare scenario that cybersecurity due diligence is designed to prevent. During any acquisition, your team should be actively hunting for indicators of compromise — not just reviewing policies on paper. Penetration testing, dark web credential monitoring, and network traffic analysis should all be in scope.

Vendor Onboarding: Due Diligence Doesn't End at Signing

Cybersecurity due diligence isn't a one-time event. For ongoing vendor relationships, continuous monitoring is essential. CISA's guidance on supply chain risk management emphasizes that organizations must treat vendor access as a persistent attack surface.

I recommend building these into your vendor management lifecycle:

  • Annual reassessment of critical vendors using the same due diligence framework.
  • Contractual right-to-audit clauses that allow independent security assessments.
  • Real-time monitoring for vendor-related threat intelligence — compromised domains, leaked credentials, new vulnerabilities in vendor software.

How Security Awareness Fits Into Due Diligence

One of the most telling indicators of an organization's security maturity is how it trains its people. A company with a robust cybersecurity awareness training program signals that leadership takes human risk seriously.

During due diligence, I always ask for:

  • Training completion rates across the organization.
  • Phishing simulation click rates over the last 12 months.
  • Evidence that training is role-based — finance teams get different scenarios than engineering.
  • How quickly the organization can deploy targeted training after an incident.

If a target or vendor can't show meaningful investment in security awareness, that's a red flag. Tools like phishing awareness training for organizations give you a measurable way to benchmark human risk — and to improve it post-acquisition or during vendor remediation.

Building a Zero Trust Mindset Into Your Process

The NIST Zero Trust Architecture framework (NIST SP 800-207) isn't just a network design philosophy. It's a mindset that should permeate your due diligence process. Trust nothing by default. Verify everything.

That means:

  • Don't trust self-reported compliance. Request evidence.
  • Don't trust clean questionnaires. Validate with technical assessments.
  • Don't trust the absence of reported incidents. Hunt for compromise indicators independently.
  • Don't trust a single point-in-time assessment. Build continuous evaluation into the relationship.

What Happens When You Skip It

The consequences of inadequate cybersecurity due diligence are predictable and well-documented. You inherit breaches. You absorb regulatory fines. You discover that the crown jewels of the acquisition — customer data, intellectual property, proprietary systems — have already been exfiltrated by a threat actor who's been inside the network for months.

And then you get to explain to your board why nobody checked.

Start Before You Need It

The best time to formalize your cybersecurity due diligence process is before the next deal lands on your desk. Build your framework now. Train your team to execute it. Establish baseline requirements that every potential partner, vendor, or acquisition target must meet.

Your organization's security posture is only as strong as the weakest entity you connect to. Make sure you know what you're connecting to before you flip the switch.