Skip to content

Cybersecurity Due Diligence: What a Pentest Proves Before Close

Cybersecurity due diligence for M&A and investors: what a penetration test proves before close, how to scope it on a deal clock, and a due diligence checklist.

Invadel Team12 min read

When you buy a company, you buy its breaches too. That includes the ones nobody has found yet.

In July 2014 an attacker installed a web shell on a Starwood server. Marriott bought Starwood in September 2016. The attacker was still inside in September 2018, when a database alert finally gave the attacker away. By Marriott’s own estimate, 339 million guest records were affected. The UK regulator fined Marriott £18.4 million. Its penalty notice records Marriott’s statement that it “was only able to carry out limited due diligence” on Starwood’s systems during the acquisition. (ICO penalty notice, October 2020)

This guide is about cybersecurity due diligence in M&A and private equity deals. It covers what a penetration test proves that a questionnaire cannot, how to run one on a deal clock, and what to do with the findings. It is not about vendor due diligence on your suppliers. If you are a startup facing investor diligence before a round, see our startups page. If you are a fund facing an allocator’s operational due diligence, see hedge funds and asset managers. If you run a private equity firm answering LP questionnaires or a portfolio testing program, see private equity cybersecurity.

What we do, up front: Invadel tests acquisition targets for buyers, with the target’s written authorization. We also test sellers before a sale process starts. Every penetration test has a fixed price, a fixed scope and a free retest.

What cybersecurity due diligence covers

Most diligence teams collect the same evidence. Each piece answers a different question, and each has a blind spot.

Evidence What it shows What it misses
Security questionnaire What the target says it does Whether any of it is true
SOC 2 or ISO 27001 report That controls were designed and, for SOC 2 Type II, operated over a period Whether the controls stop an attacker today
Policies and procedures Intent and maturity Execution
Incident and breach history Known incidents Unknown ones, like Starwood’s
Cyber insurance history Claims and coverage Why no claim was made
The target’s own pentest reports What a past tester found Whether it was fixed, and what changed since
An independent penetration test Whether the systems hold against an attacker now Anything outside the agreed scope

The first six are paper. The penetration test is the only item on the list that tries the doors. It is also the only one the buyer controls: you choose the tester and the scope.

Sell-side and buy-side

A due diligence test is either commissioned by the seller, to prepare, or by the buyer, to verify. The work is the same. Who controls it is not.

Sell-side Buy-side
Who hires the tester The company being sold The acquirer or PE sponsor
Who authorizes testing The company, for its own systems The target, in writing, before any testing
Who sees the full report The company, then buyers under NDA The buyer, plus whatever the parties agree to share with the target
When Two to three months before the data room opens After the LOI, during exclusivity
Goal Walk into diligence with findings already closed Find out what you are buying before you price it

Sell-side testing is the easier path. The company owns its systems, so it can authorize the test alone and fix the findings on its own schedule.

Authorization: the target signs, not the buyer

Until the deal closes, the buyer does not own the target’s systems. The buyer’s consent is not enough. Testing systems without the owner’s permission is unauthorized access, whatever the deal documents say.

For a buy-side test, four things are agreed in writing before any testing starts:

  1. The authorization letter. Signed by someone at the target with authority over the systems in scope. It names the systems, the dates and the testing firm.
  2. Rules of engagement. Testing windows, source IP addresses, systems that are off limits, and an emergency contact at the target who can stop the test.
  3. The NDA. It covers the buyer, the target and Invadel.
  4. Report distribution. Who receives the full technical report, who receives the executive summary, and what happens to the findings if the deal does not close.

Deals are often confidential inside the target, too. The circle can stay small: one technical contact at the target who knows the dates and can tell the rest of IT that the traffic is authorized.

The deal clock

A diligence test has a deadline set by lawyers, not engineers. Plan it in four stages.

  1. Before the LOI. No testing. A buyer can review public information: breach disclosures, regulator actions, lawsuits, and what the target exposes to the internet in public records. That is a desk review, not a test. It shapes the questions and the test scope.
  2. After the LOI, in exclusivity. The authorized test. Onboarding starts within 24 hours of a signed proposal, and testing usually starts within a week. A single application or perimeter test typically completes in one to two weeks. We report critical findings the day we confirm them, so the deal team does not wait for the final report.
  3. Before signing. Findings become deal terms (see below). If the target fixes issues before signing, the free retest proves it.
  4. After close. The tests that were too invasive to run on someone else’s network. See the 100-day plan below.

What to test before close, and what to leave until after

Before close, test what an outside attacker can reach. It is the highest exposure, it runs remotely, and it does not disrupt the target’s staff.

After close, or before you connect the networks, test the inside:

These wait because they need internal access, they involve the target’s staff, and they carry more operational risk than a buyer should take on a network it does not yet run.

Scope menus at published prices

Every price below is a published starting price for the smallest tier. Your exact figure comes back as one fixed quote in writing from your scope.

Target type Before close After close
SaaS company Web application ($5,200), API ($4,000), cloud ($6,800) Microsoft 365 review ($4,200), phishing campaign ($3,600)
Services firm or industrial company External network ($4,200), flagship application if there is one ($5,200) Internal network ($6,000), Microsoft 365 review ($4,200)
Small bolt-on acquisition External network ($4,200) Microsoft 365 review ($4,200), internal network ($6,000)

Larger applications, more cloud accounts or several sites move into the medium and large tiers, all listed on the pricing page. Each penetration test includes a report, an attestation letter and a free retest of the fixes.

How to read the target’s existing pentest report

Most targets will hand over a recent penetration test report. Read it before you decide what to test yourself. Six warning signs:

  • No retest. Findings are listed but nothing shows they were fixed.
  • Scanner findings only. Missing headers, TLS settings and outdated software versions, with nothing about access control or business logic. That is a vulnerability scan with a cover page.
  • Stale or narrow scope. The report is over a year old, covers a product the target no longer sells, or leaves out the application you are buying.
  • No authenticated testing. The tester never logged in, so nothing behind the login was tested.
  • A tester who is not independent. The report came from the managed service provider that runs the target’s network. They were testing their own configuration.
  • Summary only. An attestation letter or executive summary with no technical report behind it, even under NDA.

Our penetration testing report template shows what a complete report contains, and the sample report shows ours.

Turning findings into deal terms

This section is general information, not legal advice. Your deal counsel decides the terms.

Findings give a deal team something concrete to negotiate with. Common uses:

  • A pre-close fix list. Named findings fixed before closing, with the retest as evidence.
  • Remediation covenants. The seller commits to fix named findings by a date.
  • Specific indemnities, escrows or holdbacks tied to the risk the test exposed.
  • Price. It happens. In February 2017, after Yahoo disclosed its data breaches, Verizon and Yahoo cut the purchase price for Yahoo’s operating business by $350 million and agreed to share certain breach-related liabilities. (Yahoo Form 8-K, February 21, 2017) Altaba, formerly Yahoo, later agreed to pay a $35 million SEC penalty for failing to disclose the 2014 breach. (SEC press release 2018-71)

For a public acquirer, the stakes continue after close. The SEC’s 2023 rules require a Form 8-K under Item 1.05 generally within four business days after a company determines that a cybersecurity incident is material. (SEC press release 2023-139) Once the target is yours, its incidents are yours to disclose.

Sell-side: test before the process starts

If you are preparing a company for sale or a large raise, test before the data room opens. The sequence:

  1. Test the product, the perimeter and the cloud two to three months before launch.
  2. Fix the findings.
  3. Take the free retest, so the report shows them closed.
  4. Put the attestation letter and executive summary in the data room, with the full report available under NDA.

A buyer who sees findings already closed has less to negotiate with. A buyer who finds them first has more. Our third-party penetration testing page describes the attestation letter that goes into the data room.

The first 100 days after close

The ICO’s Marriott notice makes the point plainly: an acquisition is a trigger for due diligence “either immediately prior to acquisition or shortly thereafter,” and the duty is not a “one-off requirement.” A 100-day testing plan covers what diligence could not.

Window Test Why Starting price
Days 1 to 30 Microsoft 365 or Google Workspace review Email is where wire fraud and account takeover start $4,200
Days 1 to 30 External network test, if not done pre-close Close the perimeter you now own $4,200
Days 31 to 60 Internal network test or Active Directory assessment Before the networks connect, find the path to domain admin $6,000
Days 61 to 100 Phishing campaign Measure the new staff before training them $3,600
Ongoing Validated scans under a vulnerability management program, then an annual test Keep the acquired estate on your normal cadence From $1,500

Do the internal work before you join the networks. The ICO notes that the Starwood systems the attacker reached stayed segregated from the Marriott network, so the attack never reached the wider Marriott network. Test before you connect.

Cybersecurity due diligence checklist

Use this list to plan the workstream. Work through each line, or record why it does not apply.

Documents to request

  • The last two years of penetration test reports, with retest results
  • SOC 2 Type II or ISO 27001 certificate and report, with exceptions
  • Incident and breach history, including incidents that were not notified
  • Cyber insurance policy, applications and claims history
  • Network and data flow diagrams, and an asset inventory
  • The list of regulations the target reports under (PCI DSS, HIPAA, NYDFS, GDPR)

Questions to ask

  • Who has administrator access to email, cloud and Active Directory, and is it protected by MFA?
  • Which vendors and MSPs hold remote access?
  • Where is customer data stored, and who can reach it?
  • What was the last significant finding, and when was it fixed?

Testing

  • Written authorization from the target, signed before any testing
  • Rules of engagement, NDA and report distribution agreed
  • External perimeter tested
  • Flagship application and API tested, behind the login
  • Cloud account tested
  • Critical and high findings retested

Deal terms

  • Findings reviewed by deal counsel
  • Pre-close fixes, covenants, indemnities or price adjustments decided

After close

  • Microsoft 365 or Google Workspace review in the first 30 days
  • Internal network or Active Directory test before network integration
  • Phishing baseline within 100 days
  • Target added to your annual testing program

Frequently asked questions

Can a buyer commission a penetration test of a company it has not bought yet? Yes, with the target’s written authorization. The buyer hires us and the target signs the authorization for its own systems. No testing starts until that letter, the rules of engagement and the NDA are in place.

How long does M&A penetration testing take? Onboarding starts within 24 hours of a signed proposal and testing usually starts within a week. A single application or perimeter test typically completes in one to two weeks. Critical findings are reported the day we confirm them.

Who sees the report? Whoever the parties agree in writing before testing. Usually the buyer receives the full report and the target receives the findings it needs to fix.

Is a SOC 2 report enough for cybersecurity due diligence? It shows that controls exist and operated over a period. It does not show whether they stop an attacker. A current penetration test of the systems you are buying answers that.

What does cybersecurity due diligence testing cost? It is built from our published prices: external network from $4,200, API from $4,000, web application from $5,200, internal network from $6,000 and cloud from $6,800, each with a free retest. See pricing.

Is this the same as vendor due diligence? No. Vendor due diligence checks a supplier before you share data with it, usually through its SOC 2 report and pentest summary. Our list of SOC 2 penetration testing providers covers that side.

The short version

Paper tells you what the target says. A penetration test tells you what an attacker would find. Get the target’s written authorization, test the perimeter, the product and the cloud before close, and test the inside before you connect the networks.

Fixed price, fixed scope, free retest. Scope your diligence test and get the price in writing, or read how our third-party penetration testing is documented for the people who rely on it.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation