← Media

Transactions

Cyber due diligence needs recovery evidence, not a policy checklist

For acquisitions, cyber findings become useful when they connect systems, data and resilience to deal terms and integration priorities.

Cyber due diligence needs recovery evidence, not a policy checklist

Cyber risk is increasingly material to transaction execution, but policy documents alone do not show whether a target can contain an incident, recover operations or quantify remediation work.

The incident data make cyber risk a transaction input

Australia recorded 1,205 notifiable data breaches in 2025, the highest annual total since the mandatory reporting scheme began in 2018 and 8 per cent more than in 2024. The Office of the Australian Information Commissioner attributed 716 notifications to malicious or criminal activity [1]. Separately, the Australian Signals Directorate responded to 1,253 cyber security incidents in FY2024–25 and reported increasing financial losses and breach frequency [2]. The datasets measure different things, but together they show that cyber exposure is an operating issue rather than a remote technical scenario.

For acquisitions, the inference is that cyber risk can affect value, completion readiness and the first months of ownership. A target may depend on a small number of systems, hold data it does not fully map, or rely on third parties whose failure would interrupt revenue. Those conditions do not make the business uninvestable. They do mean the investment case should include the cost and sequence of bringing material weaknesses to the buyer’s required operating standard.

Policies describe intent; evidence shows resilience

A policy library can confirm that responsibilities and procedures have been documented, but it cannot by itself demonstrate that controls operate or that recovery is achievable. ASIC’s cyber pulse work identified gaps in third-party and supply-chain risk management, protection of confidential information and incident-response planning among survey participants [4]. The report is an older, voluntary-survey baseline rather than a current estimate for all Australian businesses, yet its categories remain directly relevant to the questions a buyer needs to test.

A transaction review can therefore test operational evidence proportionate to the target: the systems and data that sustain revenue, identity and privileged-access controls, known vulnerabilities, incident records, third-party concentration, backup coverage, restoration tests and response exercises. The commercial question is not whether every control is perfect. It is whether material exposure is understood, whether management can detect and contain an incident, and whether the recovery claim has been tested rather than assumed.

Third-party dependencies belong inside the target perimeter

The newest NIST due-diligence guide for information and communications technology suppliers assesses foreign ownership or control, provenance, resilience, foundational cyber practices and supply-chain tiers [3]. Its formal scope is ICT supplier risk, not corporate M&A. Even so, the framework supports a useful transaction inference: a target’s cyber perimeter extends beyond assets it owns to providers and products on which its operations depend.

A vendor register is only the starting point. Deal teams need to identify which providers can access sensitive data, administer systems, interrupt customer delivery or constrain recovery. They also need to understand concentration, substitution difficulty, contract rights and the evidence the target receives about provider controls. This connects cyber diligence with commercial, legal and operational workstreams, because a technically acceptable dependency may still carry material renewal, termination, data-location or continuity consequences.

Findings matter when they change transaction decisions

Cyber diligence is more decision-useful when it does not end as a long list of technical observations detached from the deal. Depending on verified facts and appropriate professional input, material findings may inform remediation budgets, completion conditions, specific contractual protections, disclosure to insurers, integration sequencing and the ownership of work after closing. A weakness that can be fixed before completion has a different transaction profile from one that requires platform replacement across several sites, even if both receive the same severity label in a technical report.

This is the bridge between cyber evidence and transaction design. The buyer needs an agreed view of what must be fixed, by whom, at what cost and by when. The seller needs clarity on which matters affect price or risk allocation and which are normal post-close improvement. Without that translation, diligence can produce extensive information while leaving the investment committee unable to distinguish a manageable remediation item from a threat to the operating thesis.

Incident readiness also shapes Day 1

For entities covered by Australia’s Notifiable Data Breaches scheme, the OAIC’s current response sequence is to contain the breach, assess it, notify where required and review the incident. Where an entity suspects an eligible breach, it must take reasonable steps to complete the assessment within 30 calendar days [5]. Those operating obligations can remain relevant during an acquisition. The practical implication is to establish clear incident ownership, escalation routes and access to the facts required for assessment from the first day of control.

Uncertainty remains. Public notifications and ASD response data do not capture every incident, and neither dataset is a sample of acquisition targets [1][2]. A clean public record does not prove that a target is clean; a past incident does not prove that current controls are weak. The durable approach is evidence-led and proportionate: test the systems, data and dependencies material to value, translate gaps into transaction decisions, and make recovery readiness an explicit part of the integration plan.

Sources

  1. Data breach notifications increase to all-time high in 2025, new NDB stats showOffice of the Australian Information Commissioner · 6 July 2026
  2. Annual Cyber Threat Report 2024–2025Australian Signals Directorate · 13 October 2025
  3. NIST Cybersecurity Supply Chain Management: Due Diligence Assessment Quick-Start GuideNational Institute of Standards and Technology · 8 July 2026
  4. REP 776 Spotlight on cyber: Findings and insights from the cyber pulse survey 2023Australian Securities and Investments Commission · 12 November 2023
  5. Quick reference guide for responding to data breachesOffice of the Australian Information Commissioner · 29 June 2026