According to the target company, no significant cybersecurity incident has occurred in recent years. This would be reassuring if the company continuously monitored all its critical systems. However, its logs go back only a few months, and an external IT provider manages part of the system environment. There is therefore no complete picture of the earlier period.
If the acquired company continues to operate independently, such a gap may affect business continuity, its compliance position and expected IT expenditure. An incident or vulnerability discovered later could lead to data loss, service disruption, customer complaints or additional security investment. The new owner will have to address these consequences even if the target company’s IT systems continue to operate separately.
If the buyer also intends to integrate the two companies’ IT operations, further risks arise. Connecting the target company’s network, cloud services or user accounts could expose the buyer’s systems to previously unidentified vulnerabilities. The shortcomings identified may therefore affect the sequence, timing and cost of integration.
Cybersecurity due diligence examines how the target’s IT environment, past incidents, external dependencies and compliance position may affect the transaction’s business plan. The significance of technical findings must always be considered in light of the planned operations: which systems are essential to production, sales or customer service, and how does the buyer plan to connect them?
NIS2 applicability and compliance
In Hungary, cybersecurity legislation transposes the requirements of the NIS2 Directive into national law. A company’s activities, sector, size and certain specific circumstances all play a role in determining whether it falls within the scope of the rules.
In an M&A transaction, the target’s own statement is therefore only a starting point. The company may not have recognised that the rules apply to it, may have missed a required step, or may have a compliance programme that has not yet been put into practice.
It is also possible that the documentation is complete while the underlying security measures are only partly operational. The existence of a policy does not demonstrate that access rights are reviewed regularly, vulnerabilities are addressed promptly or employees know what to do in the event of an incident.
Addressing these gaps may require IT development, external expertise and internal resources. The associated costs and time requirements affect the post-transaction operating plan.
Past incidents and vulnerabilities
The value of a statement that “there have been no incidents” depends on whether the target company would have been able to detect one. With incomplete logging, limited monitoring or inadequate incident response processes, an attack may remain undetected for an extended period.
Past events involving data loss, ransomware, unauthorised access or business interruption may be particularly important. The cause and the action taken are also relevant to due diligence. Even after an incident has been closed, the technical or operational weakness that made it possible may remain.
Outdated systems may also indicate future costs. If a business-critical application is no longer supported by its vendor, the buyer may soon need to replace or update it, or introduce additional protective measures. This can easily overlap with other integration tasks, such as data migration or the consolidation of enterprise resource planning systems.
Access gained in the past does not automatically disappear when ownership changes. If an attacker retains access, connecting the two networks could also put the buyer’s systems at risk.
Critical systems and external providers
The technology required to run a business is often spread across several organisations. A cloud provider, IT operator, software partner or data processor may have access to systems and data that are important to the business.
Using an external provider does not automatically reduce the target company’s exposure. Unclear service scopes, access rights, incident response responsibilities and contractual liabilities may have the opposite effect.
In an M&A transaction, a further question is whether contracts and licences can continue on the same terms. Separating an IT service provided at group level, a non-transferable software licence or a strong dependence on a single provider may delay the transition.
Supplier risks are also prominent under NIS2. The buyer therefore needs to understand the role the target’s critical partners play in its operations and what access they have to its IT environment.
IT integration
If the transaction involves a merger, there may be a business need to connect the systems quickly after closing. Finance, HR, sales and reporting teams want to work with shared data as soon as possible. From a security perspective, however, connecting too quickly may increase risk.
An unknown device, an old administrator account or inadequately protected remote access could create a new entry point into the entire corporate group. The pace of integration must therefore reflect the target’s actual security position.
Business continuity must also be maintained during the initial period. While access rights are changed, security systems are aligned or providers are replaced, the same customers must be served and the same business processes must continue to operate. A poorly timed change can itself cause an outage.
The integration plan must therefore account for remediating identified vulnerabilities, reviewing access rights, extending monitoring and coordinating incident response responsibilities. The time and cost involved are part of executing the transaction.
Cybersecurity risk becomes an M&A issue when it could cause a system outage, data loss, a compliance gap or an unexpected need for investment. The buyer needs to know the condition of the IT environment it is acquiring and under what conditions it can connect that environment to its own systems.
If this becomes clear only after closing, the planned integration will have to be adapted to a system whose condition was previously unknown.
Related Services
M&A advisory service
Our M&A advisory service helps organisations to buy, sell and merge businesses, supporting them in achieving their strategic goals and creating value.
Transaction advisory service
We provide a full range of services related to M&A, including valuation, due diligence and transaction management.
Financial due diligence
Our Financial due diligence service helps organisations to thoroughly assess the financial risks and opportunities of a potential investment or acquisition.
Cost transparency and efficiency improvement
Our cost transparency and efficiency improvement consultancy service helps organisations to make their costs transparent and identify opportunities for improvement.





