When Verizon agreed to buy Yahoo's core business in 2016, the price was $4.83bn. Then, mid-deal, Yahoo disclosed two historic breaches — one affecting half a billion accounts, one over a billion. Verizon knocked $350m off the price and made the seller keep the regulatory and shareholder liabilities. That is the number every deal team knows. It is also, I think, the least interesting of the cautionary tales, because it is the one where the diligence worked: the breach surfaced before signing and the price moved to match.

The ones that should keep a board awake are the deals where it didn't.

The breach you don't find until after you've paid

Marriott bought Starwood in 2016 for around $13.3bn. What it did not know — what nobody knew until September 2018, two years after close — was that attackers had been living inside Starwood's reservation system since 2014. When the compromise finally surfaced it had exposed some 339 million guest records. The ICO fined Marriott £18.4m, and its finding is the sentence every acquirer should have framed on the wall: a buyer's due-diligence duty is "not a time-limited or a one-off requirement," and outsourcing the operation of the systems did not reduce Marriott's responsibility for them. Marriott did not cause the breach. It bought it, and then it owned it.

(An aside for accuracy, because this one gets misquoted in board papers: the ICO's original notice proposed £99m. The final fine was £18.4m. If a slide says £99m, it is citing the threat, not the outcome.)

Then there is the deal that should change how private equity thinks about this entirely. In 2024 Bain Capital acquired the education-software firm PowerSchool. A breach had occurred through stolen vendor credentials in August 2024 — before the deal closed — and surfaced months later, exposing data on tens of millions of students and teachers. In a March 2026 ruling, a US federal court allowed claims to proceed not just against the portfolio company but against Bain itself, finding that a sponsor's contractual disclaimers of control do not shield it where it exercises operational control over cybersecurity, and that pre-closing conduct can trigger post-acquisition liability. Read that slowly if you sit on an investment committee. The liability for the target's cyber failures reached up, through the ownership structure, to the sponsor. "We only owned it" stopped being a defence.

What you are actually buying

Cyber due diligence used to be a technical annexe that nobody on the board read. It is now three things at once, and all three are the board's: a valuation question, because a material finding moves the price; a liability question, because you inherit the target's regulatory exposure and its unremediated incidents; and — since PowerSchool — a personal question for the people who approved the deal.

So a serious cyber diligence is not a maturity questionnaire the target fills in about itself. It is independent verification, before signing, of the things management is least incentivised to volunteer. It should examine the real security posture — multi-factor authentication, privileged access, patching cadence, segmentation, whether the backups are genuinely isolated. It should look for undetected compromise directly, through external attack-surface scanning, dark-web credential exposure and, increasingly, an actual compromise assessment rather than a management assertion that all is well. It should map regulatory exposure under UK GDPR and any sector rules, the breach-notification history, and any open correspondence with a regulator. It should trace the third-party and supply-chain risk, because that is where the last several disasters actually began. And it should price the technical debt — the legacy systems and known-but-unfixed vulnerabilities that you, the buyer, will have to fund the remediation of.

The questions to ask before you sign — and the red flags

A board does not need to run the scan itself. It needs to ask the questions that reveal whether anyone has, and to recognise the answers that should stop a deal.

Ask whether all prior incidents were fully remediated, with evidence, rather than closed on a ticket. Ask about patch cadence on the systems that matter, whether there is continuous penetration testing rather than a dusty annual report, whether past-breach credentials are being watched on the dark web, whether MFA and privileged-access controls actually exist, and whether the backups are segregated from the systems they protect. Ask what governs the target's use of AI tools, because that is this year's unmanaged data-exfiltration route. None of these is technical enough to need a specialist to ask; all of them are revealing enough to need one to verify.

And watch for the red flags, because they are behavioural as often as technical. Leadership that cannot speak to its own cyber risk, or insists "everything is fine" without evidence or a mitigation plan. Reluctance to disclose known vulnerabilities. Signs of a regulator already circling. And the tells inside your own side of the table: a target CISO excluded from the deal room, or pressure to close fast and do the cyber work later. The data on that last one is bleak — in one 2025 survey, a third of CISOs said they were not heavily involved in transaction decisions, and one in four said leadership pushed to close over doing thorough cyber diligence. The pressure to skip this is coming from inside the house.

The most dangerous window is the one after you've signed

Here is the part that experience teaches and deal timetables ignore: the riskiest moment in the whole transaction is not diligence. It is the weeks immediately after close, when the instinct is to connect the two networks and start capturing the synergies the model promised.

Do not flat-connect the networks. An attacker who has been sitting undetected in the target — and dwell times routinely run to around three months, sometimes years — becomes your attacker, in your parent estate, the moment you join the two. This is not hypothetical. The Change Healthcare catastrophe of 2024, the largest healthcare breach in US history at around 190 million people, began at a remote-access portal that had no multi-factor authentication on a system inside a business that had been acquired two years earlier. The weakness was inherited. The integration surfaced it. The bill ran past two billion dollars.

So the hundred days after close are a security programme, not just an integration one. Early on: stand up monitoring and an incident-response retainer, run a compromise assessment on the target before you merge anything, inventory its assets and internet-facing services, enforce MFA and rotate privileged credentials, and confirm the backups are isolated and tested. Then remediate the critical vulnerabilities and consolidate identity and email security while keeping the estates segmented rather than merged. Only once the target is verified clean do you exercise the combined environment with a red-team test and hand it to business-as-usual governance. The model that assumes the acquisition is clean on day one is the model that funds the breach on day ninety.

Making the deal terms carry the risk

Where diligence surfaces something material, the board has levers, and it should insist they are used rather than papered over. Negotiate cyber-specific representations — compliance with data-protection law, no undisclosed breaches — and consider elevating the key ones to "fundamental" status, which extends the window to bring a claim, precisely because breaches surface late. Understand how warranty-and-indemnity insurance treats cyber: the insurers generally do not apply a blanket exclusion, but they underwrite what the diligence found and carve out what it didn't look at — so thin diligence quietly buys you broad exclusions. And know the gap the International Underwriting Association warned about only this month: the target's own cyber policy often terminates at completion with a short claims window, while the breach is discovered long after — leaving the W&I policy as the only recourse, if you thought to make it respond. Where a finding is concrete, that is what price reductions, ring-fenced indemnities and escrow holdbacks are for. Verizon reduced the price. You can too.

Why this is now a standing board discipline

If you invest through a fund, this has quietly become table stakes at the larger end and a visible gap at the smaller. In Kroll's late-2025 study of private-equity firms, 81% of the larger firms treated cyber diligence as a standard part of every transaction — against just 29% of the smaller ones, with the average incident during a hold period costing north of two million dollars. The bifurcation is the opportunity and the warning: the discipline is becoming standard, and the funds that skip it are the ones now most exposed — to the lost value, to the inherited regulator, and, after PowerSchool, to a claim that reaches the sponsor.

The through-line from Yahoo to Marriott to Change Healthcare to PowerSchool is a single, unglamorous fact: the damage was almost never caused by the buyer, and almost always paid for by the buyer. A deal transfers the revenue and the liabilities in the same signature. The board's job is to make sure it has actually looked at what it is buying — not the version of the company in the information memorandum, but the one with the attacker already inside — and to price, structure and integrate for the company that is really there.

This is general information for directors, not legal, financial or transactional advice; deal structures and liabilities are specific to each transaction and should be confirmed with your advisers.