Why you must pay close attention to IT Security in an M&A deal

When companies acquire other companies, it’s not just the financial metrics that come under scrutiny. The state of IT security is also playing an increasingly important role in M&A deals. In this guide, we’ll highlight what to pay particular attention to and the potential consequences of any shortcomings.

How do M&A and IT security go together?

Mergers and acquisitions (M&A) are strategic processes in which two companies merge or one company acquires another. These transactions are often aimed at increasing market share, acquiring new technologies, or expanding geographically.

In an increasingly digital world, IT security plays an ever-more-important role – even in M&A deals! Companies need resilient IT infrastructures to protect business data, customer data, and confidential information. Successful cyberattacks jeopardize a company’s success and, consequently, mergers and acquisitions.

_______

“A company that has very good figures today from a business perspective and is therefore an interesting object to buy may be worth nothing tomorrow due to a cyber attack. In addition, further risks may arise for the buyer. That’s why a well-founded assessment of the technical and organizational IT security measures is part of every M&A deal”.
– Florian Bröder, Managing Director FB Pro –

_______

Why IT Security can be the deciding factor in the success of a deal

Before a company acquisition, due diligence – an assessment of the target company – is always conducted. This process typically focuses on aspects such as revenue, earnings, contracts, customers, employees, and market position.

As a rule, there is also a technical due diligence and a specialized cybersecurity due diligence. This is because one factor that is often overlooked can significantly influence the value of a transaction: the actual state of IT security.

When buyers acquire a company, they are not just purchasing its products, expertise, and customer relationships. They often also assume the company’s legacy technical issues and cybersecurity risks. These can include unpatched systems, insecure configurations, compromised user accounts, poorly protected data, risky service providers, or even a previously undetected hacker attack.

That is why, in an M&A deal, the question should not only be, “What are we buying?” but also, “What cyber risks might we be buying along with it?”

IT Security issues in an M&A process: What are the potential consequences?

If an IT audit uncovers inadequate security measures, data breaches, or compliance violations, the consequences may include the following:

🛑 Before the M&A Deal
If IT security issues arise during the due diligence phase, this may lead to renegotiations, price reductions, or even the cancellation of the deal. The buyer(s) may therefore lower the purchase price or demand additional guarantees and commitments to minimize the risks.

🛑 During the M&A deal
IT systems with security gaps and vulnerabilities make integration into other system landscapes more difficult. This results in delays and high costs. In addition, security incidents—which can be very costly—may occur.

🛑 After the M&A deal
Undetected security issues can cause long-term damage. This includes financial losses due to security incidents, legal consequences resulting from compliance violations, and reputational damage that undermines the trust of customers, partners, and investors.

Example: How a negative cybersecurity due diligence affects the purchase price

The post “Buying the Business…or a Breach?” provides a concrete example of how a questionable state of IT security can have financial implications for an M&A deal. Among other things, it examines the deal between Verizon and Yahoo.

After serious data breaches at Yahoo came to light, Verizon reduced the purchase price by $350 million. In addition, certain shareholder lawsuits and proceedings by the U.S. Securities and Exchange Commission remained entirely with Yahoo.

“Ultimately, the question for buyers is no longer whether to evaluate cyber risk, but how thoroughly they evaluate it. When you acquire a business, you may also be acquiring years of unseen vulnerabilities.”
– Chetrice Romero, Senior Cyber Security Advisor bei Ice Miller –

_____

How can IT security issues be resolved?

As is often the case, taking proactive action is better than reacting too late. That’s why, throughout all phases of an M&A process – which can stretch over many months or even years – you should protect your “data assets” as effectively as possible and in accordance with current regulations.

For example, follow the guidelines set forth by NIS2 and ISO 27001. You must also comply with industry standards such as DORA or TISAX – if these apply to your company!

Furthermore, a phased approach is recommended. This includes, among other things, the following measures:

Before the M&A deal

✅ Intrusion detection systems (IDS) are not generally required, but they are highly recommended. In addition, a regular IT security audit helps identify and address vulnerabilities in the IT infrastructure.

✅ Work with IT security experts to identify potential risks and implement effective security measures.

✅ Secure your systems proactively, for example, through System Hardening. Also, ensure you have professional intrusion detection in place.

_____

A simple practical tip

Audit TAP screenshot (Image: FB Pro GmbH)

Would you like to know how well an IT system is “hardened”? Create transparent reports quickly and automatically to measure the status of the applied system configuration – this is possible with our free AuditTAP.

Therefore: Request an audit TAP report from various reference systems as part of an M&A deal and evaluate it. Anything below 40% compliance with standardised frameworks should be checked more closely!

_____

During the M&A Deal

✅ Implement systems for continuously monitoring the IT security situation no later than now, in order to detect threats early and respond to them.

✅ Continuously optimize your measures to improve information security. For example, install updates as soon as possible and implement the requirements of new regulations.

✅ Allocate a sufficient IT budget for the period following the M&A deal. Even after the acquisition or merger, information security, data protection, and compliance requirements must continue to be met.

After the M&A Deal

✅ Conduct regular security audits to ensure that IT systems comply with current threats (such as AI attacks) and regulatory requirements.

✅ Regularly raise awareness and train all existing and new employees so they are informed about current security threats and cybersecurity practices.

✅ Continue to prioritize “IT security” at all levels!

For more tips, read the article “Cybersecurity: The Hidden Pillar of M&A Due Diligence.

Conclusion

IT security is of great importance in M&A deals and can have a decisive impact on the success of a transaction. If you, as a CEO, are looking to sell your company, you should ensure that your infrastructure is robust and secure.

A thorough security audit, support from experts, and the implementation of modern security protocols are particularly important for mitigating potential risks. After all, early and regular reviews of IT security not only protect sensitive data but also strengthen buyer confidence and ensure a smooth transition.

Do you need assistance with System Hardening?

Do you want to protect your systems in the long term? Feel free to contact us – we’d be happy to help you implement automated System Hardening in accordance with established standards.

💬 Make an appointment!

______

Note: The information provided in this blog post is for general informational purposes only and does not constitute legal or tax advice. If you need legal or tax advice, please contact a tax firm or law firm.

Image: Freepik

Leave a Reply