01
Questionnaires describe intent; evidence describes reality
A completed security questionnaire tells the acquirer what the target believes to be true. Diligence should test a small number of high-consequence claims against evidence: pull the actual privileged-account listing, the last quarter of vulnerability scan output, the incident register and the recovery test results. Where evidence cannot be produced, that absence is itself a finding.
This is not an exhaustive audit. It is a targeted sampling exercise designed to establish whether the control environment described in documents is the one operating in practice.
02
Identity and access: the most reliable predictor of exposure
- Number and provenance of privileged accounts, including service and vendor accounts
- Multi-factor authentication coverage for remote access, administration and email
- Joiner-mover-leaver evidence, especially timeliness of revocation
- Shared credentials and standing access to production data
- Recertification records for high-privilege entitlements
03
Technical debt is a financial line item
Unsupported operating systems, unmaintained applications, deferred patching and end-of-life network equipment are common and generally quantifiable. The correct output of diligence is not a red flag but a costed remediation plan with a timeline, because that plan will become the acquirer's obligation on day one.
Where the target operates in a regulated environment, remediation timing also carries supervisory implications; a plan measured in years may not survive contact with the acquirer's own regulator.
04
The target's own third parties become yours
Acquirers routinely assess the target and overlook the supply chain behind it. A target with modest internal systems may depend entirely on two providers with no exit plan, weak contractual protections and unclear data residency. Reviewing the target's critical third-party inventory, contracts and concentration is as material as reviewing its internal controls.
05
Incident history tells you how the organization behaves
- Complete incident register, including near-misses and events not externally reported
- Post-incident reviews and evidence that actions were completed
- Regulatory or privacy-commissioner notifications and correspondence
- Litigation, extortion payments or fraud losses connected to security events
- Cyber insurance claims history, exclusions and current coverage adequacy
06
Plan day one before you sign
Integration is where residual risk crystallizes. Connecting two networks, merging identity directories or migrating data can introduce exposure that neither organization had independently. Deciding in advance what stays isolated, what integrates and in what order should be an output of diligence, not an afterthought of the integration team.
What good looks like
- Cyber, privacy and third-party diligence scoped together, starting before exclusivity
- A short list of claims tested against primary evidence rather than attestation
- A costed, time-bound remediation plan reflected in the financial model
- Findings mapped to specific deal protections: price, escrow, conditions, reps
- An agreed day-one and first-100-days security plan, including isolation decisions
- Clear ownership of the retained risk after close, with board-level visibility
This article is general commentary on transaction diligence practice and does not constitute legal, tax or investment advice. Engage qualified counsel and technical specialists for any specific transaction.
Frequently asked questions
When should cyber diligence begin in a transaction?
+
As early as the target permits meaningful access. Cyber findings frequently affect price, escrow, reps and warranties, and day-one integration planning, so surfacing them after exclusivity leaves little room to respond commercially.
What evidence should an acquirer request?
+
Current network and data-flow documentation, asset and identity inventories, recent penetration test and vulnerability scan results with remediation status, independent assurance reports, incident history and post-incident reviews, third-party inventory with critical dependencies, privacy program records, and cyber insurance policies with claims history.
How do Canadian privacy laws affect diligence?
+
Personal information practices are assessed under PIPEDA and, in Quebec, Law 25, which carries its own governance, transparency and breach-notification obligations. Cross-border data transfers, retention practices and consent records deserve particular attention where the target serves Canadian consumers.
What is the most common post-close surprise?
+
Unbudgeted remediation. Deferred patching, unsupported systems, excessive privileged access and weak identity controls rarely appear in the financial model, yet they must be addressed on a defined timeline once the acquirer owns the risk.
Can contractual protections substitute for diligence?
+
Only partially. Representations, warranties and indemnities allocate loss after the fact; they do not restore service, protect clients or answer a regulator. For regulated acquirers, demonstrable diligence is itself an expectation.
