InfoGuard AG (Headquarter)
Lindenstrasse 10
6340 Baar
Switzerland
InfoGuard AG
Stauffacherstrasse 141
3014 Bern
Switzerland
InfoGuard Deutschland GmbH
Frankfurter Straße 233
63263 Neu-Isenburg
Germany
InfoGuard Deutschland GmbH
Landsberger Straße 302
80687 Munich
Germany
InfoGuard Deutschland GmbH
Am Gierath 20A
40885 Ratingen
Germany
InfoGuard GmbH
Kohlmarkt 8-10
1010 Vienna
Austria
Today, cyber risks are among the key factors in mergers and acquisitions (M&A). Undetected vulnerabilities, ongoing cyberattacks, or regulatory shortcomings in the wake of a merger can directly impact a company’s value and jeopardize the success of a transaction. Particularly critical are vulnerabilities that only become apparent after closing and then fall entirely under the buyer’s responsibility.
As part of a cybersecurity due diligence process, security-related risks of the target company are systematically analyzed. The results provide transparency regarding the actual level of security maturity, support purchase decisions, and help avoid risks after the transaction is completed.
A structured cybersecurity due diligence provides transparency regarding the target company’s actual security maturity level. It delivers reliable decision-making criteria for management and decision-makers, reduces liability risks, and protects corporate value.
In the context of M&A transactions, cyber risks typically arise in five particularly critical areas:
Hidden cyberattacks: APTs (Advanced Persistent Threats) or undetected data breaches may be acquired along with the target company.
These risks directly impact the purchase price, contract terms, and integration costs.
A cybersecurity due diligence follows a structured approach so that investors, management, and other decision-making bodies can quickly obtain a robust, transparent picture of a target company’s security maturity level. This involves assessing technical risks, organizational processes, and regulatory requirements.
Step 1: Initialization & Scoping
Kick-off Workshop
Document Request
Risk and Compliance Focus
At the outset, the audit’s objectives, scope, and relevant stakeholders are defined. These include, among others, IT managers, compliance teams, and security managers. In addition, relevant documents such as security policies, audit reports, or existing security concepts are analyzed. Special focus is placed on critical assets such as customer data, intellectual property, and business-critical systems.
Step 2: Conducting the Assessments
Modular Assessment of the IT Landscape
Technical Analyses
Interviews & Workshops
Based on the defined scope, a technical and organizational assessment of the IT landscape is conducted. Depending on the requirements, various testing methods are used—for example, automated security analyses, penetration tests, log evaluations, or interviews with IT managers. Among other things, security incidents, authorization structures, and existing management processes are examined.
Step 3: Analysis & Risk Assessment
Risk Register
Evaluation
Prioritization of Risks and Mitigation Measures
All findings are compiled into a structured risk register and assessed in terms of likelihood of occurrence and impact. The identified risks and potential measures are then prioritized—for example, to improve patch management, security processes, or governance structures.
Step 4: Reporting & Handover
Management Summary
Technical Report
Presentation
Theresults are tailored to the intended audience: A management summary highlights the most critical risks and recommendations for decision-makers, while a technical report documents detailed findings and evidence. The final presentation of the results to the steering committee facilitates joint evaluation and decision-making.
Whether it’s M&A, transformation, or risk assessment: Cyber risks can only be evaluated if they are systematically analyzed. Our assessments and strategy services create transparency and help you identify cyber risks early on and make informed decisions.

Not every transaction requires the same scope of review. The scope and depth of a cybersecurity due diligence depend, among other factors, on company size, industry, regulatory environment, and planned integration model.
Typical audit modules include:
ISO 27001:2022 Assessment
Assessment of the information security management system (ISMS), particularly in regulated industries or for companies operating internationally. The focus includes security controls, risk management, and the implementation of relevant requirements.
Key areas: ISMS maturity level, control assessment (Annex A), risk management.
Deliverables: Compliance report , action plan.
Microsoft 365 Assessment
Analysis of the security and compliance configuration of the Microsoft 365 environment. Areas examined include identity management, multi-factor authentication, data classification, and security features such as Microsoft Defender.
Key Areas: Identity management (Azure AD, MFA), data classification (DLP), security configuration (Defender for Endpoint).
Deliverables: Best-practice checklist, risk analysis, optimization recommendations.
External Penetration Test
Identification of immediately exploitable vulnerabilities in externally accessible systems such as web applications, APIs, or networks. This allows for the assessment of acute technical risks before a transaction is completed.
Focus areas: Black-box testing, scope (IP addresses, web applications, APIs).
Deliverables: Penetration test report, prioritized list of vulnerabilities.
Compromise Assessment
Forensic investigations help identify existing compromises or undetected attacker activities before closing the deal. This reduces the risk of inheriting existing cyber incidents when acquiring a company.
Focus areas: Forensic analysis, log analysis.
Deliverables: Forensic report, recommendations for action.
Three developments are having a particularly strong impact on cybersecurity due diligence in the M&A environment:
Early Involvement as a Deal Enabler:
Increasingly, security assessments are being incorporated at an early stage into strategy and target evaluation. This allows risks to be identified early, surprises to be avoided, and transactions to be better prepared.
Regulatory requirements are increasing:
New and existing regulations in the EU and Switzerland are increasing the importance of robust cyber risk assessments. Companies must increasingly be able to demonstrate that security risks are identified, assessed, and appropriately addressed.
Post-Merger Integration as a Key Risk Factor:
Differing security levels and cultures delay integrations. Security objectives defined early on and a clear integration strategy help reduce risks after the acquisition and are critical to long-term success.
Cybersecurity due diligence is no longer merely a technical review. It supports strategic decisions throughout the entire M&A process—from the initial evaluation of a target company to successful integration.
It creates measurable added value by:
Protecting corporate value
Better decision-making foundations for purchase price and contract structuring
Reducing liability and reputational risks
Faster and more secure post-merger integration
Cybersecurity is now a critical component of every M&A transaction—and the early identification of cyber risks helps reduce financial, operational, and regulatory risks.
A structured cybersecurity due diligence process provides the necessary transparency regarding a target company’s actual security maturity level and delivers a robust foundation for strategic decisions, from the initial assessment through to successful post-merger integration.
At the same time, it supports informed decisions regarding purchase price, contract drafting, and integration planning, and helps secure long-term enterprise value and resilience.
Cybersecurity is therefore not a technical detail, but an essential component of corporate valuation. Those who address digital risks early on create the conditions for well-informed M&A decisions and lay the foundation for a successful and secure integration.
We are passionate about actively supporting you throughout your M&A process— please feel free to contact us at any time!
Caption: AI-generated image