Cybersecurity due diligence is the structured assessment of an organisation's security posture and cyber risk, performed when something important depends on it: an acquisition, an investment, a major partnership, or onboarding a critical vendor. Get it wrong and you inherit someone else's data breach, liability, or remediation bill. This guide covers cybersecurity due diligence best practices, what it covers, when you need it, and how to approach it.
What cybersecurity due diligence is
It is a deliberate evaluation of a target company's information security: how they protect data and systems, the maturity of their controls, their compliance posture, their history of incidents, and the cybersecurity risk that would transfer to you if you acquired, invested in, or relied on them. Unlike an internal audit, cyber due diligence is performed by or for the acquirer taking on the cyber risk, to inform a decision and, often, to price it.
Cybersecurity due diligence is also a form of third-party risk management when applied to suppliers. Good security posture in a target does not guarantee zero risk assessment issues, but a thorough review identifies potential risks and surfaces the ones that matter. The due diligence process examines cybersecurity practices, policies and procedures, security controls, and regulatory compliance obligations in parallel.
When you need it
Cybersecurity due diligence matters most in a few situations:
- Mergers and acquisitions. When you acquire a company through a merger, you acquire its cybersecurity risk, its data liabilities, and any undisclosed breaches. Security has become a standard and material part of M&A diligence.
- Investment. Investors increasingly assess the cyber risk of what they fund, because a data breach can destroy value, especially in financial services.
- Critical vendor onboarding. Before you trust a vendor with your data or systems, you assess whether they can protect it, often a deeper version of a vendor security questionnaire.
- Major partnerships. Any relationship where another party's weak security becomes your exposure.
Facing a deal or onboarding a critical vendor?
Run the free security self-assessment to get a baseline picture of your own posture before due diligence starts.
What it covers
Thorough cybersecurity due diligence examines several dimensions:
- Governance and posture: who owns security, the cybersecurity policies and practices in place, and overall maturity.
- Technical controls: access management, encryption, monitoring, vulnerability management, network security, and the state of the infrastructure.
- Compliance: the credentials and obligations they hold or claim, and whether the evidence backs them. Note the differences: SOC 2 produces a CPA attestation report (not a certificate); ISO 27001 a certificate issued by an accredited certification body; PCI DSS is evidenced by an AOC or SAQ; HIPAA and GDPR are laws, not credentials you hold, so look for compliance programmes and documented controls rather than certificates. Confirm which regulatory regimes actually apply: GDPR applies where EU or UK personal data is processed, HIPAA applies to US healthcare data, and other requirements may follow by contract or sector.
- Data handling and privacy: what sensitive data they hold, where it lives, how it is protected, and their approach to data protection and data privacy.
- Incident history: past breaches, how they were handled, outstanding exposure, and the quality of their incident response plans.
- Third-party risk: the security of their own vendors and supply chain, whether detection systems can catch threats from those relationships, and the overall cyber security and supply chain readiness of the target organisation.
The output is a clear picture of risk and, ideally, a view of what it would cost to fix. Penetration testing findings or existing security assessment reports provide valuable insights where assertions alone are not enough. Cybersecurity due diligence services performed by specialists can also run risk assessment processes more efficiently than an internal team working under deal pressure.
What good and weak due diligence look like side by side
Before selecting a methodology, it helps to know what you are aiming for. The table below contrasts the hallmarks of thorough versus superficial cybersecurity due diligence:
| Dimension | Thorough due diligence | Superficial due diligence |
|---|---|---|
| Evidence standard | Verifies claims with technical evidence and audit reports | Accepts self-reported answers without verification |
| Incident history | Reviews past breaches, root causes, and remediation | Relies on "no incidents to report" declarations |
| Compliance | Reviews actual SOC 2 attestation report and ISO 27001 certificate, including scope | Accepts a claim of compliance at face value, no review of the underlying report or certificate |
| Third-party risk | Reviews the target's own vendor controls and sub-processors | Ignores supply-chain exposure entirely |
| Output | Business-readable risk picture with remediation costs | A document that satisfies process but informs no decision |
| Timing | Pre-close findings inform negotiation and price | Findings arrive post-close with no leverage |
How to approach it
Scope the diligence to the size of the decision: a critical acquisition warrants deeper assessment than a routine vendor. Use a structured risk management framework and align with industry standards so the assessment is consistent and defensible. Look for evidence, not assertions, the same way a good penetration testing engagement proves rather than lists. And translate the findings into business terms: what the cyber threats are, what they could cost, and what would have to change to address cyber resilience gaps.
Cybersecurity due diligence involves reviewing security policies and procedures against recognised standards, cross-referencing cyber due diligence assessments with technical evidence, and identifying where the target company's cybersecurity policies fall short of regulatory requirements. Security incidents that occurred without full remediation are a particular concern. Due diligence assessments should identify areas where immediate action is needed, separating what must be addressed pre-close from what can follow post-close. Cybersecurity due diligence provides the acquirer with a baseline that informs negotiations and post-deal security standards. The goal is to inform a decision, not to produce a document nobody reads.
The bottom line
Cybersecurity due diligence is how you understand the security risk you are about to take on, whether through an acquisition, an investment, a partnership, or a critical vendor. It covers governance, technical controls, compliance, data handling, incident history, and third-party risk, and it should produce a clear, business-readable view of cyber risk and the cost to address it. Scope it to the decision and insist on evidence over assertions.
How Onyx helps
Onyx conducts cybersecurity due diligence for acquirers, investors, and organisations onboarding critical vendors. We assess governance, technical controls, compliance, data handling, incident history, and supply-chain risk, and we deliver findings in business terms: what risk transfers, what it would cost to remediate, and what must be addressed before versus after close.
Our risk assessment service covers the same dimensions and can be scoped to the size of the transaction. Where technical verification is needed, our penetration testing and vulnerability assessment services provide the evidence layer that assertions alone cannot.
See also: responding to a vendor security questionnaire if you are on the supplier side preparing for customer due diligence, and understanding your company's cyber risks for the leadership framing behind what due diligence surfaces.
Need cybersecurity due diligence scoped for a deal or vendor onboarding?
Tell us what is at stake and we will outline the right assessment on a short call.
FAQ
What is cybersecurity due diligence?
It is a structured assessment of an organisation's security posture and cyber risk, performed when something important depends on it, such as an acquisition, investment, partnership, or critical vendor onboarding. It evaluates how they protect data, the maturity of their controls, their compliance, and their incident history to inform and price a decision.
When do I need cybersecurity due diligence?
Most importantly during mergers and acquisitions, when making an investment, when onboarding a critical vendor, or before entering a major partnership where another party's weak security becomes your exposure. The greater the dependency and the value at risk, the deeper the diligence.
What does cybersecurity due diligence cover?
Governance and security posture, technical controls, compliance credentials and obligations (SOC 2 attestation report, ISO 27001 certificate, HIPAA obligations, PCI DSS AOC or SAQ, and applicable regulations such as GDPR), data handling, incident history, and third-party and supply-chain risk. The output should be a clear picture of cybersecurity risk and, ideally, the cost to remediate it.
Why is cybersecurity due diligence important in M&A?
Because when you acquire a company you acquire its security risks, data liabilities, and any undisclosed breaches. Security has become a standard, material part of M&A diligence, since a hidden incident or weak posture can significantly affect value and create post-deal liability.
What is the difference between due care and due diligence in cybersecurity?
Due care is the ongoing effort an organisation puts into maintaining effective cybersecurity through a cybersecurity program, security measures, and cybersecurity policies and procedures. Due diligence in cybersecurity is a specific assessment activity, performed at a point in time, to understand the security posture of another organisation before taking on risk exposure.
How is due diligence different from an internal audit?
An internal audit assesses your own organisation against a standard. Cybersecurity due diligence is performed by or for the party taking on risk, about another organisation, to inform a decision such as an acquisition, investment, or vendor relationship, and often to price that cyber risk. The acquirer needs to understand cybersecurity across all dimensions, including data security, data protection and information security practices, and sensitive data and systems handling, to make an informed decision.
