top of page
Search

Buy‑Side Due Diligence: The Cyber Blind Spot That Keeps Costing Firms Billions

Aug 8
2 min read

In modern M&A, buyers still behave as if financial and accounting diligence are the center of gravity. That era is over. The world changed, and firms that haven’t noticed are the ones ingesting breaches, absorbing liabilities, and destroying enterprise value before the ink on the purchase agreement is dry. When a buyer acquires a company without performing real IT and cyber diligence, it isn’t buying an asset, it’s inheriting every compromise, misconfiguration, and long‑dwell intrusion the target never disclosed.


HP learned this with Autonomy, resulting in an $8.8 billion writedown. Twitter’s waived diligence contributed to a $25 billion value collapse as operational claims failed to match reality. And in 2026, the Bain–PowerSchool ruling made private‑equity buyers directly liable for post‑close cyber failures, turning cyber diligence into a legal obligation rather than a best practice.


The most dangerous scenario is the one buyers rarely consider: acquiring a firm that has already been breached. Industry data shows that 94 percent of audited codebases contain unpatched open‑source components or license conflicts, ideal hiding places for long‑dwell intrusions. CrowdStrike’s reporting placed average dwell time at 16 days, with some sectors exceeding 30. One in four reps‑and‑warranties insurance claims hit the full policy limit. These numbers describe a market where buyers are walking blind into inherited cyber liabilities because they never asked the right questions.


The structural failure is Post‑LOI Tunnel Vision. Once the board approves the deal, teams stop investigating and start executing. They stop asking whether the target has been breached and start asking how to close. That mindset has contributed to more than $400 billion in destroyed shareholder value across the largest M&A failures of the past decade. The data rooms are full, but the synthesis is missing.


The hard lesson is simple: IT is now the primary diligence track. Finance and accounting can be churned through AI, normalized, reconciled, and modeled with speed and accuracy that outperforms human teams. But IT diligence cannot be automated. It requires human adversarial thinking, architectural interpretation, and the ability to see the quiet places where breaches hide. Firms that continue treating IT as a secondary track are not buying companies, they are buying their compromises.


If your thinking about buying a company/division reach out we can discuss. 


 
 

Recent Posts

See All
Reconnaissance Is Not an Incident

Every statement out of the water sector this week says the same thing. Contained. Water is safe. Operators handled it. That is an after action report written by the wrong side. Twelve states now. More

 
 

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page