Twenty-three acquisitions. Zero cybersecurity due diligence.
That was the situation I walked into at a major telecom early in my career. The company had spent years acquiring smaller players. Financial due diligence on every deal. Legal due diligence on every deal. Operational due diligence on every deal. Cybersecurity due diligence on none of them.
No one had mapped the inherited attack surface. No one had assessed the security posture of the acquired entities. No one had asked the basic question of what we were actually buying when we bought a company. Twenty-three networks, twenty-three sets of unknown vulnerabilities, twenty-three unpatched estates, all quietly absorbed into the parent organization.
Then one of them got breached.
The breach was not catastrophic by the standards of what we see today. But it was loud enough. It forced a conversation that should have happened years earlier. Suddenly there was budget. Suddenly there was executive attention. Suddenly cybersecurity due diligence was a non-negotiable part of every deal. The very thing that had been treated as optional for twenty-three transactions became mandatory in a single quarter.
It took a breach to unlock what should have been obvious from day one.
The Blind Spot in Plain Sight
M&A due diligence is one of the most rigorous processes in corporate life. Teams pore over financial statements. Lawyers comb through contracts and litigation history. Operations specialists assess supply chains, vendor relationships, customer concentration. Every line item is interrogated. Every assumption is tested.
And then cybersecurity gets a paragraph in the data room.
Sometimes not even that. In many deals I have seen, the security review consists of a questionnaire the target fills out themselves, with no independent verification. The acquirer signs off based on a self-attestation from a company that may not have a security team, may not have a CISO, may not have ever conducted a penetration test, and may not even know what its own attack surface looks like.
This is not a small gap. This is the difference between knowing what you are buying and hoping for the best.
What You Actually Inherit
Here is the part most executives miss. When you acquire a company, you do not just acquire its revenue, its customers, and its IP. You acquire its vulnerabilities. Every misconfigured server. Every unpatched system. Every dormant admin account belonging to a former employee. Every shadow IT tool nobody documented. Every weak password policy. Every third-party integration with credentials hardcoded into a config file.
You inherit all of it. The moment the deal closes.
And it gets worse. In most acquisitions, network integration starts before the security team has even been briefed. VPN tunnels go up. Directory services get federated. Email domains get linked. Suddenly the acquired company's environment is not a separate problem. It is your problem. Their weakest endpoint is now a doorway into your crown jewels.
The attack surface expands the moment the deal closes. The acquirer rarely has visibility into what just got added.
Rolling Out Tools Is Not Due Diligence
Here is what tends to happen instead of a proper assessment. The bigger company starts enforcing its security standards on the acquired entity. Endpoint Detection and Response (EDR) tools get pushed to every laptop and server. Multi-Factor Authentication (MFA) gets rolled out across the user base. The acquired company's logs get piped into the parent's Security Information and Event Management (SIEM) platform. Boxes get ticked. Slides get green.
This feels like security. It is not.
You cannot protect what you have not mapped. Pushing EDR onto endpoints you have not inventoried means you are protecting some unknown percentage of the estate and missing the rest. Enforcing MFA on the user accounts you know about does nothing for the service accounts, the legacy systems, and the shadow IT no one has surfaced yet. Feeding the acquired environment into your SIEM without understanding what normal looks like in that environment generates noise, not insight.
Tools are the answer to a question. Due diligence is what tells you what the question is. Skipping the assessment and going straight to rollout is how acquirers convince themselves they have handled the cyber risk while leaving the actual exposure untouched.
The dormant admin account does not care that you deployed EDR. The misconfigured cloud bucket does not care that you mandated MFA. The unpatched server running an end-of-life operating system in a back office is not going to show up in your SIEM dashboards because no one told the SIEM it exists.
Controls without context are theatre.
The Asymmetry Nobody Talks About
There is a reason smaller acquired companies are disproportionately the weakest link. They have not had the resources to build mature security programmes. They often have no dedicated security staff. Their controls live in someone's head, not in documentation. Their patching cadence is whatever the IT generalist gets to between other tickets.
This is not a criticism of smaller companies. It is a statement of fact. A twenty-person fintech does not have the same security maturity as the bank acquiring it. A founder-led tech company does not have the same governance posture as the conglomerate writing the cheque. The asymmetry is structural.
But the asymmetry does not stay contained after the deal closes. The weakest link becomes everyone's weakest link. One compromised endpoint in a recently acquired subsidiary can cascade through the parent organization's network in hours. Attackers know this. They watch deal announcements. They target the smaller entity precisely because it is the soft underbelly of a much larger prize.
What Cyber Due Diligence Should Actually Look Like
The fix is not complicated. It just has to happen.
A proper cyber M&A due diligence process covers, at minimum:
- A documented inventory of the target's assets. Servers, endpoints, cloud accounts, SaaS subscriptions, code repositories, data stores. If they cannot tell you what they have, that is the finding.
- An independent assessment of the target's security posture. Not a self-attestation. A real review of controls, architecture, identity management, patching cadence, logging and monitoring, incident response capability.
- A breach history check. Has the target been breached? Are they currently compromised? Threat intelligence and dark web monitoring can answer this before you sign.
- A regulatory exposure review. What data does the target hold? What jurisdictions do they operate in? What compliance obligations transfer to you on day one? NDPA, GDPR, PCI DSS, sector-specific frameworks. You need to know.
- A third-party and supply chain assessment. The target's vendors become your vendors. Their integrations become your integrations. Map them.
- A people and culture review. Who has admin access? What happens to those accounts post-deal? Is there a security culture or is security something one person does on Fridays?
- An integration risk assessment. How will the two environments connect? What is the sequencing? Where are the exposure points during the integration window?
This is not exotic work. It is the same discipline you already apply to financial and legal due diligence. It just has to be applied to cyber. And critically, it has to come before the tool rollout, not instead of it.
Back to the Twenty-Three
After that breach, the telecom did the work it should have done before any of those acquisitions closed. We built a cyber M&A due diligence programme. Every future deal got a security assessment before signing. Every legacy acquisition got a retrospective review. We mapped the inherited attack surface across all twenty-three entities. We found things that should have been found years earlier.
The breach paid for the programme. That is the part that still bothers me.
It did not have to happen that way. The cost of due diligence is a rounding error against the cost of a breach. The expertise exists. The frameworks exist. The only thing that has been missing in most deals is the decision to treat cyber as a first-class diligence workstream rather than a footnote.
If you are a CFO, a COO, a General Counsel, or an M&A advisor reading this and thinking cyber is the security team's job, I would gently push back. Cyber due diligence is a deal decision. It belongs in the same conversation as financial and legal. The cost of getting it wrong does not land on the security team. It lands on the balance sheet, on the share price, and on the boardroom.
Do the work before the deal closes. Not after the breach.
At GRCK, we work with acquirers, investors, and corporates on cyber due diligence for transactions across African and global markets. If you have a deal on the horizon, we should talk before signing, not after.
