Publication
Buying the Business…or a Breach? Cybersecurity’s Growing Role in Mergers & Acquisitions
What Cyber Risks Are We Inheriting?
When companies evaluate a potential acquisition, traditional due diligence tends to focus on financial performance, operations, and market position. But increasingly, one of the most important, and often overlooked, questions is: What cybersecurity risks are we inheriting?
Cybersecurity is no longer just an IT concern. It has become a core driver of deal value, transaction timing, regulatory exposure, and post-closing liability. As organizations become more digitally connected and increasingly technology-dependent, failing to adequately assess a target’s cyber posture can mean acquiring hidden and pervasive vulnerabilities that may not surface until months or even years after the deal closes.
When a Breach Changes the Price: Verizon and Yahoo
One of the most recognized examples is Verizon’s 2017 acquisition of Yahoo.1 After Yahoo disclosed two massive data breaches impacting more than one billion user accounts, Verizon reduced its purchase price by $350 million and negotiated a liability-sharing arrangement as part of the transaction.2
The lesson wasn’t simply that Yahoo had experienced a breach. The lesson was that cybersecurity directly changed the value of the deal.
While the Yahoo-Verizon transaction demonstrates how a known cyber incident can affect valuation before closing, other cases highlight the consequences of failing to detect those risks altogether.
When the Risk Stays Hidden: Marriott and Starwood
A striking example is Marriott’s 2016 acquisition of Starwood Hotels. Unbeknownst to Marriott at the time of acquisition, Starwood’s systems had been compromised nearly two years earlier. The breach remained undetected until after the transaction closed.3
Approximately 500 million guest records, including passport and payment card information, were ultimately exposed. Marriott later faced £18.4 million in UK regulatory fines, $52 million in U.S. state settlements, FTC-mandated security measures, improvements, and significant reputational damage. Immediately following disclosure of the breach, Marriott’s stock dropped approximately 5%, with estimates placing the overall financial impact at more than $1 billion.4
This case underscores an important lesson for executives: Cyber vulnerabilities often exist before the deal closes, but the liability becomes yours after the deal closes.
Why Cyber Risk Now Sits at the Center of Deal Value
This is far from an isolated case. Studies show that 62% of mergers and acquisitions experience delays due to cybersecurity concerns, while 73% of dealmakers say they would walk away entirely if significant undisclosed cyber issues were discovered.5 These statistics reflect a broader reality: cyber risk is now a business and valuation issue, not merely a technology issue.
Several factors make organizations particularly vulnerable during mergers and acquisitions:
- Integration gaps. Merging networks, applications, and legacy systems often introduces security holes.
- Distraction. Internal teams are understandably focused on closing the transaction and executing integration plans, creating opportunities that cybercriminals actively seek to exploit. At the same time, buyers assume responsibility for existing vulnerabilities.
- Inherited exposure. Buyers assume responsibility for undetected malware, compromised credentials, forgotten accounts with unknown access privileges, outdated systems, and third-party risks that may not have been fully identified during the transaction.
What Cybersecurity Due Diligence Should Cover
Given these realities, cybersecurity due diligence is no longer optional; it is essential.
At a minimum, cyber diligence should extend well beyond reviewing security policies. Buyers should:
- Evaluate technical vulnerabilities across systems and applications
- Understand how sensitive data is stored and protected
- Assess prior cybersecurity incidents and the organization’s ability to respond to them
- Review third-party vendor risks
- Determine whether the organization has mature incident responses, business continuity, and disaster recovery capabilities.
- Independently verify self-evaluations and attestations, and have a cyber professional review their risks rather than relying on the target’s own assurances
Perhaps most importantly, executives should ask whether leadership truly understands its cyber risks or whether cybersecurity has remained solely an IT conversation.
Resilience as an Investment Strategy
Ultimately, the question for buyers is no longer whether to evaluate cyber risk, but how thoroughly they evaluate it. When you acquire a business, you may also be acquiring years of unseen vulnerabilities.
Organizations that treat cybersecurity as a strategic component of due diligence are far better positioned to understand the true value of an acquisition, negotiate from a position of strength, and avoid inheriting risks that can quickly transform a promising investment into a long-term liability.
Every acquisition represents an opportunity to create value, accelerate growth, and strengthen an organization for the future. But resilience should be part of that investment strategy from day one. By understanding cyber risk before the deal closes and planning for secure integration afterward, organizations can protect the very assets they set out to acquire. The strongest deals are not simply measured by the purchase price or projected returns, but by an organization's ability to sustain trust, operations, and resilience long after the closing documents are signed.
Connect with Our Team
Considering a transaction — or preparing your company to be acquired? Talk to Ice Miller's Tech, Privacy & Cyber Risk team about buy-side and sell-side cybersecurity due diligence that protects deal value.
[1] Anjali Athavaley & David Shepardson, Verizon, Yahoo Agree to Lowered $4.48 Billion Deal Following Cyber Attacks, REUTERS, Feb. 21, 2017, https://www.reuters.com/article/business/verizon-yahoo-agree-to-lowered-448-billion-deal-following-cyber-attacks-idUSKBN1601EK/.
[2] Id. As part of the agreement, Yahoo and Verizon split cash liabilities related to some government investigations and third-party litigation related to the breaches. Yahoo also continued to be responsible for liabilities from shareholder lawsuits and SEC investigations.; see also U.S. Securities and Exchange Commission, Altaba, Formerly Known as Yahoo!, Charged With Failing to Disclose Massive Cybersecurity Breach; Agrees to Pay $35 Million, SEC, Apr. 24, 2018, https://www.sec.gov/newsroom/press-releases/2018-71.
[3] Marriott Corp., Marriott Announces Starwood Guest Reservation Database Security, Marriott, June 15, 2026, Marriott Announces Starwood Guest Reservation Database Security Incident | Marriott International.
[4] Alex Veiga, Marriott Agrees to Pay $52 Million, Beef Up Data Security to Resolve Probes Over Data Breaches, AP NEWS, Oct. 9, 2024, https://apnews.com/article/marriott-data-breach-settlement-97534838b650bfc7a9e73a5336b2988e.; Joe Tidy, Marriott Hotels Fined £ 18.4m for Data Breach That Hit Millions, BBC, Oct. 30, 2020, https://www.bbc.com/news/technology-54748843; Attorney General Platkin, Multistate Coalition Announces $52 Million Settlement for Marriott, Starwood Data Breaches, STATE OF NJ, DEP’T. OF L. & PUBLIC SAFETY, Oct. 9, 2024, https://www.njoag.gov/attorney-general-platkin-multistate-coalition-announce-52-million-settlement-for-marriott-starwood-data-breaches/; Federal Trade Commission, FTC Takes Action Against Marriott Starwood Over Multiple Data Breaches, FTC, Oct. 9, 2024, FTC Takes Action Against Marriott and Starwood Over Multiple Data Breaches | Federal Trade Commission.; William White, MAR Stock Drops on News of Marriott Data Breach, YAHOO FINANCE, Nov. 30, 2018, https://finance.yahoo.com/news/mar-stock-drops-news-marriott-161130825.html?guccounter=1&guce_referrer=aHR0cHM6Ly93d3cuYmluZy5jb20v&guce_referrer_sig=AQAAAItdUCxGrJhvlWz9FChPyPN5B-SoFVce84llgfyW0VyiDAzlICLqShnsAt0yApAytU-NwAm43XcLXhBzMbjamdlXar104Nhy4f_ZrwQW63Jj9vArpt63RJgpv5JPQQnB2L1IKBXP5eEN1nycsbkoxqFutEvQLjn301PwNArMYjo2.
[5] Karyn DiMassa & Rich Sowalsky, Cybersecurity: The Hidden Pillar of M&A Due Diligence, CENTRI BUSINESS CONSULTING, Dec. 10, 2025, https://centriconsulting.com/news/insights/cybersecurity-the-hidden-pillar-of-ma-due-diligence/.
This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.
