Owner’s notes

Cybersecurity and IT Diligence: How to Prepare for a Sale

· 8 min read · Bankerly Team

By the time a buyer signs a letter of intent, the technology and security review has usually already begun in the background. For lower-middle-market companies, cybersecurity and IT diligence has moved from a footnote to a workstream that can affect deal value, indemnification terms, and in some cases whether a transaction closes at all. Buyers want to understand what they are inheriting, from data assets and access controls to breach history and regulatory exposure. This overview describes the areas buyers commonly examine and the kinds of records owners often assemble in advance. It is educational information about a general process, not security, legal, or professional advice, and every business faces different risks and obligations.

Why buyers scrutinize IT and security

Advisory firms describe cybersecurity diligence as an effort to understand the risks a data breach would pose to critical business assets, from intellectual property and operations to customer information and payment card data. According to EY-Parthenon, overlooking these concerns can expose an acquirer to diminished revenue, profit, market value, and brand reputation after a deal closes. A buyer that discovers weak controls or an undisclosed incident late in the process may reprice, expand escrow and indemnity provisions, or walk away. Smaller companies are not exempt. Acquirers of lower-middle-market targets often find that security programs were built informally over time, held together by a handful of people and a set of habits rather than written policy. That is not unusual, and it does not automatically signal a weak business. What tends to matter to a reviewer is whether the informal practice can be described, evidenced, and handed over. Diligence teams increasingly include technical specialists or outside firms who run their own scans and interviews, so the review is rarely limited to the documents a seller volunteers. Understanding the questions in advance tends to help owners avoid surprises and present an accurate picture of how the company actually operates.

Asset and data inventory

A common starting point is a clear picture of what the company owns and where sensitive data lives. Buyers frequently ask for an inventory of hardware, software, cloud services, and the systems that store or process regulated data. Areas of interest often include:

  • Data mapping that shows what personal, financial, or health data is collected, where it is stored, and who can reach it.
  • Software and system inventory, including custom applications and the third-party libraries they depend on.
  • Intellectual property such as source code, proprietary datasets, and the controls protecting them.
  • Shadow IT, meaning tools or accounts adopted by teams outside central oversight.

An accurate inventory tends to signal a mature operation, while gaps can prompt deeper questioning.

Access controls and multi-factor authentication

Identity and access management is a recurring focus. Reviewers commonly look at how accounts are provisioned, how privileges are limited, and how the company enforces strong authentication. The principle of least privilege, under which users receive only the access their role requires, is a frequent benchmark. Multi-factor authentication has become a widely referenced control. In the payments context, PCI DSS version 4.0.1 makes MFA mandatory for access into cardholder data environments, part of a set of future-dated requirements that became fully enforceable on 31 March 2025, according to the PCI Security Standards Council. Buyers may also review offboarding practices, since dormant accounts belonging to former employees are a familiar weak point. Administrative and privileged accounts draw particular attention, because they can change configurations, reach large volumes of data, or disable other controls. Reviewers sometimes ask how administrative access is granted, whether it is logged, and how shared credentials, if any, are managed. Single sign-on, centralized identity directories, and consistent password standards are frequently treated as signs that access is governed rather than improvised. Where those are absent, a buyer may still get comfortable, but the review tends to take longer and generate more follow-up questions.

Backups, recovery, and resilience

Business continuity is examined alongside prevention. A buyer generally wants confidence that the company can recover from ransomware, hardware failure, or accidental deletion without catastrophic loss. Records that owners often keep on hand include:

  • Backup scope and frequency, covering which systems are backed up and how often.
  • Recovery testing, meaning evidence that restorations have actually been performed, not just scheduled.
  • Recovery objectives that describe tolerable downtime and data loss.
  • Disaster recovery and continuity plans that document who does what during an outage.

Backups that are isolated from production systems are frequently viewed as more resilient against ransomware that seeks to encrypt connected copies.

Incident history and patching

Buyers routinely ask about past security incidents, including breaches, ransomware events, and significant near misses. Full disclosure matters, because an undisclosed incident discovered after closing can become a representation-and-warranty dispute. Reviewers tend to look at how incidents were detected, contained, and remediated, and whether root causes were addressed. Patch and vulnerability management is a related theme. Reviewers may request evidence of regular patching, vulnerability scans, and, in some cases, independent penetration tests. A documented process for tracking and closing findings is often viewed more favorably than a single clean scan, because it demonstrates an ongoing practice rather than a one-time effort. Reviewers may distinguish between systems the company controls directly and those managed by cloud providers, where patching responsibilities are shared. Unsupported or end-of-life software tends to attract scrutiny, since it can no longer receive security fixes and may require replacement after a deal closes. Owners sometimes prepare a short summary of the environment that notes operating systems, major applications, and any components known to be aging, which lets a buyer weigh the cost of modernization against the value of the business.

Vendor and SaaS risk

Modern companies depend on a web of third-party software and service providers, and that dependency is part of the review. Vendor and supply-chain vulnerabilities are a recognized source of breaches, so buyers examine how a target manages the parties it relies on. Common points of interest include the roster of critical vendors and cloud platforms, the contracts and data-processing terms governing them, and any available third-party assurance reports such as SOC 2 examinations or ISO 27001 certifications. Reviewers may also consider whether vendor access is scoped appropriately and monitored. For a smaller company, a simple register of key vendors and the data each one can access often answers many questions at once. Concentration risk can also surface here, since heavy reliance on a single provider or an unusual custom integration may affect how a buyer plans to integrate or separate systems after closing. Reviewers sometimes ask whether contracts allow assignment to a new owner, because a change of control can trigger renegotiation or termination clauses that carry cost.

Data-privacy posture and payment card data

Privacy exposure has grown as more states enact consumer data privacy statutes. Legal guides from firms such as White & Case describe a patchwork of comprehensive state laws now on the books, with roughly twenty states having enacted such statutes and additional laws taking effect in 2026, per reporting from the International Association of Privacy Professionals. These laws commonly grant residents rights to access, delete, and opt out of certain data uses, and they generally require reasonable security measures and clear privacy notices. Applicability usually turns on thresholds tied to the number of residents whose data a business handles or the share of revenue derived from selling data, so obligations vary by company. Businesses that accept payment cards face a separate framework in PCI DSS, which applies to organizations that store, process, or transmit cardholder data. Buyers often review privacy notices, consumer-request handling, and, where relevant, PCI compliance status as part of assessing regulatory risk. Sector-specific rules can add further layers, such as HIPAA for certain health information or financial-services requirements, depending on the industry. Because obligations shift as new statutes take effect and existing ones are amended, a current view of which laws apply is generally more useful than an assessment from a year or two earlier.

Where preparation meets the sale process

Much of this material overlaps with the broader diligence file a seller assembles, and organizing it early tends to reduce friction later. A well-ordered virtual data room that includes security policies, an incident log, backup evidence, a vendor register, and privacy documentation lets a buyer's technical reviewers move efficiently. Platforms such as Bankerly organize sell-side deliverables and data-room materials so that IT and security records sit alongside financial and legal exhibits. However a company chooses to prepare, the general pattern holds: clear documentation of the current state, honest disclosure of known issues, and evidence that controls operate in practice are the elements buyers most consistently look for.

Sources

Frequently asked questions

What is cybersecurity due diligence in an M&A deal?
It is the buyer's review of a target company's IT systems and security controls to understand the risks being acquired. Reviewers commonly examine data inventories, access controls, backups, incident history, patching practices, vendor relationships, and regulatory exposure such as privacy law and payment card obligations. The goal is to identify hidden risks that could affect value or create liability after closing.
Why does multi-factor authentication come up so often in diligence?
MFA reduces the risk that a stolen password alone can compromise a system, so buyers treat it as a baseline indicator of access-control maturity. In the payments context, PCI DSS version 4.0.1 makes MFA mandatory for access to cardholder data environments, with those requirements fully enforceable as of 31 March 2025. Reviewers often look for MFA on email, cloud platforms, and administrative accounts.
How do state data privacy laws factor into a technology review?
Roughly twenty states have enacted comprehensive consumer privacy laws, and more take effect in 2026. These statutes generally grant residents rights to access, delete, and opt out of certain data uses, and they require reasonable security and clear privacy notices. Applicability usually depends on how many residents' data a business handles, so a buyer assesses which laws apply and whether the target meets them.
What backup and recovery records do buyers typically want to see?
Buyers often look for the scope and frequency of backups, evidence that restorations have actually been tested, defined recovery objectives for downtime and data loss, and disaster-recovery or continuity plans. Backups that are isolated from production systems are generally viewed as more resilient against ransomware. Documentation that shows recovery works in practice tends to carry more weight than a plan alone.
Does a past security incident automatically derail a sale?
Not necessarily. Many companies have experienced incidents, and buyers generally focus on how the event was detected, contained, and remediated, and whether root causes were addressed. The larger concern tends to be non-disclosure, because an incident discovered after closing can become a representation-and-warranty dispute. This is general information, not legal advice, and specific situations warrant qualified counsel.

Considering a sale in the next few years? See what a prepared process looks like.