Cyber Due Diligence: A UK CISO's M&A Checklist for 2026 | INFORMD Executive Briefing

Cyber Due Diligence: A UK CISO’s M&A Checklist for 2026

UK CISOs should run structured cyber due diligence — testing incident history, identity sprawl and third-party exposure — before signing, not after integration begins. The National Cyber Security Centre (NCSC) and, for regulated acquirers, the Digital Operational Resilience Act (DORA) both treat security ownership through a deal as a continuity requirement, not a one-off checkbox.

Why Do Cyber Risks Surface After the Deal Closes, Not Before?

Most acquirers still treat cybersecurity as a late-stage confirmatory item rather than a core diligence workstream, and the gap shows up in the numbers. According to Forescout Technologies’ survey of 2,700 IT decision-makers, 53% of respondents found critical cybersecurity issues during the M&A assessment phase serious enough to put the deal itself at risk. Separately, industry research cited across the deal advisory sector puts the figure at 52% of acquirers who only discover major cybersecurity risk during post-closing integration, after the price has been agreed and the warranties signed. The UK’s clearest cautionary case remains Marriott, fined £18.4 million by the Information Commissioner’s Office under UK GDPR for a breach that originated inside the Starwood reservation systems it had acquired years earlier. The vulnerability existed before the deal closed; the liability transferred with it.

The pattern behind both statistics is consistent: legacy systems slated for decommissioning but never switched off, credentials that were never rotated after a prior breach, and shadow IT that no one on the target’s side thought worth disclosing because it predates the current security team. None of this shows up in a standard financial or legal diligence pack, which is why it has to be scoped as its own workstream with its own sign-off, reporting into the deal steering committee rather than buried inside a generic IT appendix.

Executive Action:

  • Treat cyber diligence as a named workstream with its own budget and timeline, not a subset of IT diligence.
  • Require sight of the target’s last three years of incident and near-miss logs before the exclusivity period begins.
  • Flag single-person security functions as a structural red flag, not a staffing footnote.

What Should CISOs Demand Before Signing a Letter of Intent?

The diligence request list should go further than the standard vendor security questionnaire. CISOs need direct sight of penetration test results from the last twelve months, a current asset and identity inventory, evidence of MFA coverage across privileged accounts, and a full register of third-party and SaaS dependencies — the same exposure surface INFORMD has previously mapped in its supply chain cyber risk briefing. Where the target holds Cyber Essentials Plus, ISO 27001, or an equivalent certification, request the underlying audit report, not the certificate. INFORMD’s project review checklist gives deal teams a structured way to capture this intake before external advisors are formally engaged.

Warranty and indemnity insurers are increasingly asking the same questions, and a weak cyber diligence file now shows up as a pricing problem, not just a risk problem: gaps in the evidence base translate directly into narrower cover or higher premiums on the W&I policy. CISOs who can hand the insurer a clean, evidenced diligence file — rather than a vendor questionnaire completed by the target’s own team — are doing the CFO a direct commercial favour.

Executive Action:

  • Request raw pentest and audit reports, not summary certificates or attestation letters.
  • Map every SaaS and third-party integration the target relies on before signing.
  • Score identity and access hygiene separately from network security, because they fail independently.

How Should DORA and UK GDPR Reshape the Diligence Scope for Regulated Deals?

For acquirers in financial services, DORA adds a specific obligation: the target’s ICT third-party register must be reconciled into the acquirer’s own register from day one, not phased in over a transition period, and the FCA and PRA both expect evidence of that reconciliation as part of ongoing operational resilience reporting. Under UK GDPR, data controller and processor obligations transfer with the entity, which is precisely what turned Starwood’s legacy exposure into Marriott’s liability. Boards should require a documented cyber sign-off before releasing acquisition funds, and INFORMD’s capital approval assessment template can be adapted to make that sign-off a formal gate rather than an informal conversation.

Executive Action:

  • Reconcile the target’s ICT third-party register against DORA requirements before completion, where applicable.
  • Confirm who inherits data controller obligations for legacy breaches discovered post-signing.
  • Make cyber sign-off a named condition in the capital release process, not a verbal assurance.

What Belongs in the First 100 Days of Post-Merger Cyber Integration?

Diligence findings only have value if they drive the integration plan, which is why INFORMD’s post-merger integration checklist sets out the wider 100-day execution sequence. On the security side, priorities are identity consolidation, killing orphaned accounts before they’re forgotten, network segregation until trust is verified, merging incident response plans into one chain of command, and re-certifying against Cyber Essentials Plus under the combined entity rather than assuming the acquired certificate still applies. A tabletop exercise that simulates an incident spanning both organisations’ systems, run inside the first 60 days, surfaces command-chain gaps far faster than a policy review ever will, and it should include the target’s outgoing CISO if they are still under an earn-out retention period.

INFORMD’s briefing library tracks the wider governance obligations that apply once integration begins, and a forthcoming video briefing will walk deal teams through live red-flag examples.

Executive Action:

  • Segregate networks by default until identity and access controls are verified, not integrated on trust.
  • Merge incident response plans and reporting lines within the first 30 days, not the first year.
  • Re-certify Cyber Essentials Plus and equivalent frameworks under the combined entity’s name.

INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).

For tailored advisory introductions on deal-stage cyber diligence, contact INFORMD.

Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk.

Frequently Asked Questions

What is cyber due diligence in M&A?

Cyber due diligence is a structured review of a target company’s security posture — incident history, identity controls, third-party dependencies and certifications — run before a deal signs. It sits alongside financial and legal diligence rather than inside a generic IT appendix, because security failures transfer with the entity at completion.

When should cyber due diligence start in a deal?

Before the exclusivity period begins, ideally at initial target screening. Forescout research found 53% of acquirers uncovered critical cybersecurity issues during the assessment phase alone — starting diligence late means those findings surface after commercial terms are already agreed.

Does DORA apply to UK M&A deals?

DORA applies where the acquirer or target is a UK financial services firm with EU operations or ICT dependencies in scope. It requires the target’s ICT third-party register to be reconciled into the acquirer’s own register, with the FCA and PRA expecting evidence of that reconciliation in resilience reporting.

Who is liable for a data breach discovered after acquisition?

Under UK GDPR, data controller and processor obligations transfer with the acquired entity. The Information Commissioner’s Office fined Marriott £18.4 million for a breach that predated its acquisition of Starwood, confirming that legacy exposure becomes the acquirer’s liability at completion.

Similar Posts