Back to blog
Deal Diligence 4 min read

The Cyber Liabilities You Inherit on Closing Day

YJ

Yasmine Johnston-Ison

Cyber Friday Insights

Some of the most expensive liabilities in an acquisition never appear in the P&L.

This week’s Cyber Friday examples included ransomware groups exploiting unpatched Fortinet firewalls, an actively exploited Windows networking-driver zero-day, and a campaign using unauthenticated guest access in Salesforce and ServiceNow to enumerate and exfiltrate records. Each issue can look like a technical detail during diligence. Each can become a business event after closing.

The buyer inherits the environment—and its exposure—the moment control changes hands.

Why “we’ll fix it after close” is risky

An overdue firewall patch can be an entry point. A Windows zero-day can turn a phishing foothold into broader system control. A guest account that was meant to make a portal convenient can expose customer records without an obvious sign in the financial statements.

These liabilities are easy to miss because they are distributed across infrastructure, endpoints, and SaaS settings. They may also be obscured by assumptions: the MSP handles it, the vendor is secure, the old admin account is inactive, or the seller would have told us about an incident.

Those assumptions are not controls.

What buyers should verify before signing

The cyber portion of diligence should answer five practical questions:

  1. What is exposed? Identify internet-facing firewalls, remote-access services, servers, websites, SaaS tenants, and privileged accounts.
  2. What is overdue? Review critical patches, unsupported systems, security exceptions, and the age of open findings.
  3. Who can reach it? Map employee, vendor, guest, service, and former-employee access—and test whether least privilege is real.
  4. What happens if it fails? Validate tested backups, recovery objectives, incident contacts, insurance requirements, and notification procedures.
  5. Who owns the fix? Assign every pre-close remediation or accepted risk to a named person with a deadline and evidence standard.

Do not accept a clean questionnaire as proof. Ask for configuration evidence, patch reports, access reviews, incident logs, and recent backup or recovery test results. The objective is not to create fear; it is to replace uncertainty with a priced and owned plan.

Legacy Forward takeaway

Cybersecurity diligence is deal insurance. It protects the value you are buying by identifying the liabilities that will otherwise arrive with the keys.

A target does not need to be flawless to be acquirable. It does need transparent exposure, credible controls, and a transition plan that starts before close. When a gap cannot be fixed in time, put it into the purchase agreement, the integration plan, or the economics of the deal.

Legacy Forward Consulting helps buyers translate hidden technology risk into clear decisions before signing and practical operating work after close.

CTA: Find the liability before closing day—not in the first incident review after it.

Need Structured Guidance for Your Acquisition?

Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.

Book an Appointment

45 minutes to confirm fit and define next steps.