Buy‑Side Due Diligence: The Cyber Blind Spot That Keeps Costing Firms Billions
In modern M&A, buyers still behave as if financial and accounting diligence are the center of gravity. That era is over. The world changed, and firms that haven’t noticed are the ones ingesting breaches, absorbing liabilities, and destroying enterprise value before the ink on the purchase agreement is dry. When a buyer acquires a company without performing real IT and cyber diligence, it isn’t buying an asset, it’s inheriting every compromise, misconfiguration, and long‑dwell intrusion the target never disclosed.
HP learned this with Autonomy, resulting in an $8.8 billion writedown. Twitter’s waived diligence contributed to a $25 billion value collapse as operational claims failed to match reality. And in 2026, the Bain–PowerSchool ruling made private‑equity buyers directly liable for post‑close cyber failures, turning cyber diligence into a legal obligation rather than a best practice.
The most dangerous scenario is the one buyers rarely consider: acquiring a firm that has already been breached. Industry data shows that 94 percent of audited codebases contain unpatched open‑source components or license conflicts, ideal hiding places for long‑dwell intrusions. CrowdStrike’s reporting placed average dwell time at 16 days, with some sectors exceeding 30. One in four reps‑and‑warranties insurance claims hit the full policy limit. These numbers describe a market where buyers are walking blind into inherited cyber liabilities because they never asked the right questions.
The structural failure is Post‑LOI Tunnel Vision. Once the board approves the deal, teams stop investigating and start executing. They stop asking whether the target has been breached and start asking how to close. That mindset has contributed to more than $400 billion in destroyed shareholder value across the largest M&A failures of the past decade. The data rooms are full, but the synthesis is missing.
The hard lesson is simple: IT is now the primary diligence track. Finance and accounting can be churned through AI, normalized, reconciled, and modeled with speed and accuracy that outperforms human teams. But IT diligence cannot be automated. It requires human adversarial thinking, architectural interpretation, and the ability to see the quiet places where breaches hide. Firms that continue treating IT as a secondary track are not buying companies, they are buying their compromises.
If your thinking about buying a company/division reach out we can discuss.

