Back to blog
Deal Diligence 3 min read

Patch Fast, Trust Less: What Patch Management Reveals in Due Diligence

YJ

Yasmine Johnston-Ison

Cyber Friday Insights

A patch gap is easy to describe as a technical problem. In an acquisition, it is more useful to treat it as operating evidence.

This week’s Cyber Friday examples made the point. CISA warned that attackers were actively exploiting on-premises SharePoint Server vulnerabilities to achieve remote code execution. Microsoft’s July Patch Tuesday shipped fixes for hundreds of vulnerabilities, including zero-days already being exploited. CISA also added actively exploited WordPress Core vulnerabilities to its Known Exploited Vulnerabilities catalog.

The lesson is not that every target must patch instantly. The lesson is that a buyer should be able to see how the target decides what gets patched, how quickly, by whom, and with what proof.

Why patch management matters in diligence

“We’ll patch it after close” is not a remediation plan. It is an unfunded post-close obligation.

SharePoint, Windows Server, VPN appliances, and WordPress often sit underneath the systems that keep a small business operating. If those systems are exposed, unsupported, or inconsistently maintained, the risk is not limited to a possible incident. The gap can signal weak ownership, undocumented dependencies, informal change control, and a business that relies on luck instead of repeatable operating practices.

That matters to the deal because the buyer inherits the environment on day one. A vulnerability that looks manageable before closing can become an interruption, notification obligation, customer issue, or integration delay after closing.

What buyers should ask for

Make patch history part of the diligence request list:

  • A 12-month patch and vulnerability-management report, including exceptions.
  • The current inventory of servers, endpoints, firewalls, websites, and other internet-facing systems.
  • The owner and service provider responsible for each critical platform.
  • Evidence that critical patches were applied, not merely approved.
  • A list of unsupported software, overdue updates, and compensating controls.
  • Recent penetration tests, incident records, backup tests, and remediation plans.
  • A clear answer to who has administrator access and how that access is reviewed.

The quality of the answers matters as much as the number of open findings. A target with a documented exception process may be safer than one that claims to be “fully patched” but cannot produce a report.

Legacy Forward takeaway

Cyber hygiene is operational hygiene. Patch discipline tells you whether the company runs on systems—or on individual heroics and good timing.

Price the gap, assign an owner, and put the remediation plan into the transition workstream before signing. Buyers do not need perfect systems. They do need an honest view of what they are inheriting.

If you are evaluating a target and want a practical framework for cyber-aware diligence, Legacy Forward Consulting can help you turn technical exposure into clear deal decisions.

CTA: Bring the patch history into the diligence room before it becomes a post-close surprise.

Need Structured Guidance for Your Acquisition?

Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.

Book an Appointment

45 minutes to confirm fit and define next steps.