When Diligence Finds an Active Compromise

14 minute read
Intermediate

Your diligence team found an intrusion the seller did not know about. Who notifies, whether to pause, and how to price it into the agreement.

The Finding Is an Event, Not a Data Point

Every other diligence finding can wait for the next investment committee meeting. Unpatched hypervisors, a single-person dependency in the data engineering team, an expired SOC 2, a database running on a version that went end of support in 2021: all of those are inputs to a model. They sit in a spreadsheet until somebody prices them.

An active intrusion is different in kind. Statutory clocks are attached to it, and several of them started running before your vendor found anything. The question is no longer what the finding is worth. The question is what has to happen in the next seventy-two hours, and who is responsible for doing it.

The Seller Owes the Notice. The Buyer Owes the Seller.

The target is the data controller. Under Article 33 of the UK and EU GDPR, a controller must notify the relevant supervisory authority within seventy-two hours of becoming aware of a personal data breach, unless it is unlikely to result in a risk to individuals. Article 34 requires notice to affected individuals without undue delay where the risk is high. In the United States, every state has a breach notification statute with its own trigger, timeline, and attorney general notice requirement. HIPAA gives covered entities sixty days for breaches affecting 500 or more individuals. If the target is an SEC registrant, Item 1.05 of Form 8-K requires disclosure within four business days of determining that an incident is material, which is a separate and later clock than the awareness clock. See What Is the SEC Cyber Disclosure Rule for how that determination actually gets made.

The buyer is not the controller. Pre-close, the buyer typically owes nothing to any regulator in connection with the target's environment, and the buyer is not the party that can lawfully make the notification. That last point matters more than deal teams expect. A buyer who decides to be helpful and contacts a regulator, an affected customer, or a journalist has breached the confidentiality agreement, destroyed the clean team protocol, and handed the seller a claim that will be worth more than the finding.

There is exactly one correct first move. Written notice from buyer's counsel to seller's counsel, the same day, before the sun goes down on the finding.

The Notice to the Seller Is the Most Important Document in the File

Write it as a statement of observations, not a conclusion. Include the observed facts, the timestamps, the collection method, the data sources, and the name of the firm that collected them. Attach the raw indicators.

Leave out attribution. Leave out conclusions about scope. Leave out any legal characterization. Do not use the word "breach." A breach is a legal determination with defined consequences, and a buy-side diligence vendor is not the party that makes it. Use "indicators consistent with unauthorized access" and let the seller's counsel and forensics firm reach the characterization.

The document does three things that nothing else does.

  • It starts a clock the seller cannot later claim was never started. Awareness is the trigger under GDPR. The timestamp on your letter is the earliest date the seller can credibly assert it became aware, and the seller's own counsel will want that timestamp fixed.
  • It creates a record that the buyer acted on knowledge rather than sat on it. If this transaction is ever examined by a regulator, an insurer, a limited partner, or a litigant, the difference between a buyer who escalated within hours and one who did nothing for three weeks is the difference between a footnote and a theory of liability.
  • It converts an informal conversation into a disclosure event. Once delivered, the seller has to decide what to do with the disclosure schedules, and that decision is a negotiation you want on the record rather than in a hallway.

Why Buyer Knowledge Changes the Economics Without Creating a Duty

The buyer has no notification obligation. The buyer's knowledge still reprices the deal, through four distinct mechanisms.

  • Representations and warranties insurance. Underwriters exclude known issues. A matter identified in diligence and disclosed to the underwriter is typically carved out of the policy. A matter nobody looked for is also usually uncovered, because the underwriter will argue diligence was inadequate. Either way the policy does not absorb this. See Turning Diligence Findings Into Deal Terms.
  • Sandbagging. Whether a buyer who closes knowing a representation is false can still claim on it depends on the governing law and, more importantly, on whether the agreement says so expressly. That provision is now load bearing.
  • Post-close controller status. On the day the buyer takes control, the buyer becomes the party owing every notification duty the seller owed, on an incident the buyer already knew about. An unnotified breach does not stay with the seller. It moves.
  • Retrospective assessment of diligence quality. Regulators look backward at what an acquirer knew and did. The Marriott penalty notice is the canonical example, and it is discussed below.

Who Owes What, and When

PartyPre-signingSigning to closingPost-close
Target (controller)Full statutory notification duty from the moment of awarenessSame duty, plus SPA covenants on interim operations and cooperationDuty transfers with the entity; legacy exposure follows the balance sheet
BuyerNo regulatory duty. Contractual duty to the seller under the NDA. Practical duty to notify seller's counsel immediatelyRights under access, cooperation, and interim covenants. No independent notification rightBecomes the controller. Owes every outstanding notification, with documented prior knowledge
Seller equity holders or sponsorFund-level disclosure considerations; valuation and process decisionsIndemnity exposure is being negotiated in real timeSpecific indemnity, escrow release conditions, potential fraud carve-out exposure
Buyer if an SEC registrantGenerally nothing, the target is not yet a subsidiaryConsider whether the pending acquisition itself is materialItem 1.05 analysis on any material incident affecting the consolidated business

Read that table once more with the post-close column in mind. Everything the seller failed to do before closing becomes an item on the buyer's first hundred day plan, priced at the buyer's cost of capital, executed by a management team that just demonstrated how it handles bad news.

Preserve First. Do Not Tip. Then Investigate.

The next set of decisions is operational and the window on them is short. Get the sequence wrong and the investigation that determines your entire liability estimate becomes impossible to run.

Assume the Target's IT Organization Is Inside the Blast Radius

Every intrusion runs through a credential. A domain administrator account, a cloud tenant global administrator, a service account with a password committed to a repository in 2019, a former contractor whose access was never revoked. The person holding that credential may be compromised, may be negligent, or in a small number of cases may be the actor.

The instinct of every deal team is to call the target's CIO. In a compromise of unknown scope, that call may be a notification to the adversary. It is not paranoia. It is the reason incident responders run the first phase of an investigation out of band.

Two further facts should shape how you communicate. Threat actors read mailboxes, and they prioritize the ones with money moving through them. Announced or rumored M&A activity is a targeting signal, and the closing funds flow memorandum is one of the highest value documents in any corporate email system. Business email compromise against closing wires is an established pattern, not a hypothetical. Anyone with read access to a finance mailbox in a compromised environment can watch a wire being set up and insert revised instructions at the right moment.

So: no discussion of the finding on target email, target Teams or Slack, the target VPN, or any shared data room until scoping is complete. Use buyer counsel's systems and out of band voice. Limit the target-side circle to the CEO or board chair and general counsel, selected on the advice of the forensics lead, not on the org chart. For the underlying control failures that usually sit behind this, see What Is Privileged Access Management and What Is Identity and Access Management.

Evidence Evaporates on a Schedule Nobody Set Deliberately

The single most common reason a post-discovery investigation cannot answer the question that matters is that the data needed to answer it aged out while the parties argued about who was paying for the investigation.

Endpoint detection telemetry rolls on a retention window measured in weeks at typical licensing tiers. Cloud identity logs are worse: sign-in and audit log retention in identity platforms is frequently thirty days at entry level licensing, and the default console view for major cloud audit trails covers ninety days of management events unless a durable trail was configured to write to object storage. Firewall, VPN concentrator, and network appliance logs stored locally on the device often overwrite within days under normal traffic volume. Backup retention is not the same thing as log retention, and nobody at the target has checked.

Preservation is cheap, fast, and irreversible in the right direction. It happens before any decision about the deal. Forensic images of identified hosts, snapshots of relevant cloud volumes, retention extension on every identity and audit log source, export of EDR telemetry to cold storage, and a written litigation hold issued by seller's counsel that suspends routine deletion. This can be done in a day. It cannot be done retroactively.

The instruction that matters most is the one deal teams find hardest to give: do not let the target remediate before scoping. A well meaning IT director who resets every password, reimages three servers, and blocks the command and control domain over a weekend has destroyed the ability to determine whether data left the environment. Whether data left determines whether notification is required. Notification is the largest cost driver in most incidents. A target that cleans up before scoping has converted a knowable, quantifiable liability into an unknowable one, and unknowable liabilities price far worse than large ones. See What Is Data Exfiltration and What Is Digital Forensics and Incident Response.

Privilege, and the Insurer's Panel

Two structural mistakes are made in the first forty-eight hours and both are expensive.

The first is privilege. If the target engages a forensics firm directly, under an existing master services agreement, with the report delivered to IT, the resulting document is a business record. In 2020 a federal magistrate judge in the Eastern District of Virginia ordered Capital One to produce a Mandiant incident report in the consumer data breach litigation, finding it was not protected work product, in part because the work resembled what Mandiant already performed under a pre-existing business services arrangement. Labeling a document privileged after the fact does not make it so. The engagement has to be structured by outside counsel, under a new engagement letter scoped to anticipated litigation, with the report delivered to counsel.

The second is insurance. Most cyber policies carry a panel of pre-approved breach counsel and forensics firms, and most carry consent-to-incur provisions requiring the insurer's agreement before expenses are incurred. Engaging a non-panel firm without consent can forfeit coverage on what is frequently the largest single offsetting asset in the situation. Somebody has to read the target's policy, including the retroactive date and the prior knowledge exclusion, before anyone signs an engagement letter. The prior knowledge exclusion is the one to read twice: if the intrusion predates the policy's retroactive date, or if a target executive knew of circumstances likely to give rise to a claim, coverage may be void regardless of everything else. See What Is a Cyber Insurance Attestation.

The order of operations, in sequence:

  • Hour zero to four. Buyer's counsel notifies seller's counsel in writing. No target systems used for the communication.
  • Hour four to twelve. Seller's counsel pulls the cyber policy, identifies panel counsel and panel forensics, and places the carrier on notice. Litigation hold issued.
  • Hour twelve to forty-eight. Panel forensics engaged by outside counsel. Preservation executed across endpoint, identity, network, and cloud log sources. Target-side circle held to three or four people.
  • Day two to five. Scoping begins: entry vector, dwell time, accounts used, lateral movement, staging and exfiltration evidence. No remediation yet except containment actions the forensics lead specifically approves.
  • Day five to fourteen. Preliminary scope. Counsel makes the notification determination. Buyer receives a summary through a protocol agreed with seller's counsel, usually counsel to counsel and usually not the full report.
  • Week two onward. Eradication and remediation plan, which is the document that becomes the closing condition schedule.

Pause the Clock, Not the Process

Deal teams frame this as a binary: keep going or stop. That framing produces bad outcomes in both directions. The correct move is to freeze the timetable while preserving the transaction.

Extend exclusivity rather than let it lapse. An expired exclusivity period on a target with a known unremediated compromise gives the seller the option to run the problem to another bidder who has not seen it. That is not a hypothetical risk, it is the seller's rational move, and it is worse for the market than for you.

Stop everything that creates connectivity or commingling. No integration planning that puts buyer personnel on target systems. No network interconnect. No identity federation or tenant-to-tenant migration planning. No uploading buyer-confidential material into a data room hosted in the target's tenant. If a carve-out is involved, separation planning halts as well, because separation activity typically involves standing up new infrastructure using the credentials and images of an environment now known to be compromised. See Carve-Out Technology Separation.

Three questions set the length of the pause, and a competent forensics lead will tell you within a week whether the answers are coming.

  • Is the entry vector identified and closed? An open vector means the pause continues regardless of anything else.
  • What is the dwell time and how far did it move? Thirty days in one segment is a different deal than fourteen months across the domain.
  • Was regulated data accessed, staged, or exfiltrated? This single answer drives most of the eventual dollar figure, and it is the answer that disappears if preservation was botched.

For a mid-market environment with functioning endpoint detection and durable cloud logs, expect two to four weeks to a defensible preliminary scope. Without telemetry, the honest answer from the forensics firm will be that scope cannot be determined, and a buyer should treat "we could not determine whether data was exfiltrated" as materially worse news than a confirmed exfiltration of a known dataset.

Price It, Paper It, or Leave It

Once scope exists, the finding becomes a deal question again. There are four legitimate outcomes and the facts determine which one applies. The judgment is not about severity in the abstract, it is about whether the liability can be bounded, whether the seller will fund the work, and whether the entry vector reveals something about the business that the model did not price.

  • Closing condition. The right answer in most cases. Eradication confirmed, remediation list completed, notifications made, all verified by a named third party before funds move. Costs the seller time rather than money, which is why sellers accept it.
  • Specific indemnity backed by escrow. For the tail: regulatory penalties, individual notification and credit monitoring, class action defense, customer contract remedies. Sized against a plausible outcome, not the mean, and released on a schedule tied to the applicable statute of limitations rather than the general survival period.
  • Purchase price reduction. For the quantified, undisputed remediation cost: the forensics invoice, the credential and certificate rotation program, the endpoint tooling the target never bought, the identity rebuild. One-time and countable.
  • Walk. Reserved for three fact patterns: the seller refuses to investigate, the entry vector reveals an unpriced systemic defect such as a shared administrative credential across the entire customer base, or regulated data was exfiltrated in a volume that makes the eventual liability larger than the equity check.

The MAE Is Not the Tool You Want

Deal teams reach for the material adverse effect clause because it sounds like it was written for exactly this. It was not, and the case law is unkind.

Under Delaware law the bar is high and it is measured in duration. In 2018, Akorn v. Fresenius became the first Delaware decision to permit a buyer to terminate a merger agreement on the basis of a material adverse effect, and the facts involved a sustained collapse in the target's financial performance across multiple quarters combined with pervasive data integrity failures in regulatory submissions. Delaware courts have repeatedly said that an effect must be durationally significant, measured in commercially reasonable terms over a period of years rather than a quarter. A single intrusion, even a serious one, rarely clears that bar on its own.

Verizon and Yahoo is instructive precisely because the parties did not litigate it. When the parties amended the agreement in February 2017 following the breach disclosures, they reduced the price by 350 million dollars and expressly agreed that the breaches would not be taken into account in determining whether a business material adverse effect had occurred or whether the closing conditions were satisfied. Two sophisticated parties with excellent counsel looked at the MAE, decided it was not a reliable instrument, and negotiated around it.

Draw the conclusion. Do not rely on a general MAE. Draft a specific closing condition with an objective standard: delivery of a final report from a named forensics firm confirming eradication, completion of an enumerated remediation schedule, attestation of credential and secret rotation across defined scopes, and confirmation that required notifications have been made. Objective conditions get satisfied or they do not. MAE disputes get litigated in Delaware for eighteen months.

The Collision With the Disclosure Schedule

Every purchase agreement contains a representation that the target has not suffered a security incident or unauthorized access to its systems or data, usually with a lookback of three to five years and usually qualified by materiality. Your notice just made that representation false.

The seller now has two options and both hand you something to work with. It can supplement the disclosure schedules, or it can refuse and assert the matter is not material. In most negotiated agreements a supplement delivered after signing does not cure the representation for indemnification purposes and operates only on the closing condition, which is itself a heavily negotiated point. If you are pre-signing, the supplement simply becomes a disclosed known matter, which moves it out of the general representation regime and into the specific indemnity conversation.

Then there is sandbagging, which is now the most consequential three lines in the agreement. Whether a buyer who closes with knowledge that a representation is inaccurate can still bring an indemnity claim depends on governing law and, decisively, on express drafting. Some agreements contain a pro-sandbagging clause preserving the claim. Some contain an anti-sandbagging clause extinguishing it. Many are silent, which leaves it to case law that varies considerably by jurisdiction. The written notice you sent has made the buyer indisputably knowledgeable. That is the right call for every other reason, and it is exactly why the sandbagging provision needs to be argued immediately, with counsel, and not discovered in a markup three weeks later.

When the Seller Declines to Investigate

Some sellers refuse. The refusal usually arrives dressed as process discipline: the finding is "an artifact of the buyer's scanning tool," the timeline is "too tight to accommodate a forensic exercise," the matter is "already contained."

Treat the refusal as a finding, and rank it above the compromise. A compromise is a technical condition with a cost. A refusal to investigate is a statement about the management team you are proposing to buy and fund.

It answers three questions the rest of diligence cannot. What is this leadership team's posture toward bad news that arrives at an inconvenient time. What else has gone uninvestigated over the last five years under the same posture. And how will this team behave in month eighteen of your ownership when something breaks and you are the one who owns the consequence.

Escalate above the deal team. If the seller is sponsor-backed, the sponsor carries exposure of its own and will evaluate this differently than a management team protecting a process. See What Is Sponsor Cyber Liability.

If it still does not move, the position is simple and should be stated plainly: no closing without an independent investigation, funded from the escrow, performed by a firm the buyer selects, with a buyer termination right on a defined adverse finding. A seller confident the matter is immaterial loses nothing by agreeing. A seller who refuses that structure is telling you what the investigation would find.

What You Inherit If You Close Anyway

Closing with knowledge and without remediation is a decision, and it should be made explicitly at the investment committee rather than by default because the fund's deployment quarter is ending. Here is what transfers.

  • Controller status on day one. Every outstanding notification duty becomes yours, on an incident you documented knowing about.
  • Remediation on your operating plan. Forensics, eradication, identity rebuild, tooling, and the staff time to run it, all landing in year one against the plan you underwrote.
  • No insurance absorption. The R&W policy excludes the known matter. The target's cyber policy may exclude it under prior knowledge. You are the payer of last resort by construction.
  • Retrospective regulatory assessment. Regulators examine what the acquirer knew and what the acquirer did about it.
  • Disclosure obligations of your own. Lender covenants, LP reporting, and, if you are a registrant, an Item 1.05 materiality analysis on a consolidated basis.
  • A second diligence problem at exit. The next buyer's diligence will find the record of what you knew and when.

Why a Compromise Assessment Belongs in Diligence Scope

Most technology diligence excludes this workstream entirely, and the exclusion is rarely a considered decision. It is inherited from a scope template.

Documentary diligence is a control-existence exercise. It confirms that policies are written, that a SOC 2 Type II exists, that patching tickets close, that an incident response plan is on file. A SOC 2 Type II is an attestation about the design and operating effectiveness of selected controls over a defined period against criteria the service organization participated in scoping. It is a useful document. It is not a statement that the environment is free of adversaries, and the auditor did not go looking. Neither did the penetration test, which is a point-in-time assessment of exploitability, not a search for existing occupancy. See What Is a Compromise Assessment and What Is Threat Hunting.

The frequency data does not support the exclusion. Mandiant's M-Trends 2026 report put the global median dwell time at fourteen days in 2025, up from eleven days in 2024, with espionage operations and North Korean IT worker campaigns each averaging roughly four months of undetected presence. Slightly more than half of organizations identified the activity through internal investigation. Where an external party did the notifying, the median time to discovery was twenty-five days, more than double the prior year. The distribution has a long tail, and acquisition targets, particularly founder-led businesses with thin security functions, sit in it.

The cost anchor is equally unhelpful to the do-nothing case. IBM's Cost of a Data Breach Report 2025 put the global average at 4.44 million dollars and the United States average at 10.22 million dollars, a record for the country, with an average of 241 days to identify and contain. Against those numbers, the marginal cost of adding a compromise assessment to a mid-market technology diligence scope is a rounding error, and it is the only workstream in the entire exercise that directly tests the representation the seller is about to make.

The argument for excluding it usually comes down to timeline. That argument is worth examining, because the assessment that would have taken nine days during diligence takes nine months of litigation afterward. For what the full scope should contain, see Technology Due Diligence Checklist.

Related Reading

Frequently Asked Questions

Who is legally required to notify regulators if a buyer's diligence discovers a breach at the target?

The target is. It is the data controller or covered entity, and the statutory notification duty attaches to it from the moment it becomes aware. Under GDPR that is seventy-two hours to the supervisory authority. US state statutes, HIPAA, and sector regulators each impose their own triggers and timelines. The buyer is not the controller and generally owes no regulatory duty before closing. The buyer also cannot lawfully make the notification on the target's behalf, and attempting to do so breaches the confidentiality agreement. The buyer's obligation is contractual and practical: immediate written notice from buyer's counsel to seller's counsel.

Should the buyer tell the target's IT team what was found?

Not initially. The intrusion runs through a credential, and the credential may belong to someone in the IT organization, either because they were compromised or because of negligence. Notifying the IT team can notify the adversary. Threat actors also monitor mailboxes in compromised environments, and deal correspondence containing closing funds flow instructions is a high value target for wire fraud. Keep the target-side circle to the CEO or board chair and general counsel, selected on the advice of the forensics lead. Communicate out of band, not on target email, Teams, Slack, or VPN.

Does an active compromise trigger a material adverse effect clause?

Rarely on its own. Delaware requires an effect that is durationally significant, measured over years rather than quarters. Akorn v. Fresenius in 2018 was the first Delaware decision to permit termination on MAE grounds, and it involved sustained financial collapse plus pervasive regulatory data integrity failures. Even in the Verizon and Yahoo situation, where breaches affecting billions of accounts surfaced mid-deal, the parties expressly agreed the breaches would not count toward a business material adverse effect and instead negotiated a price reduction and a liability split. Use a specific objective closing condition rather than relying on the MAE.

Should the deal be paused when a compromise is found?

Pause the timetable, not the transaction. Extend exclusivity rather than letting it lapse, because an expired exclusivity on a target with a known unremediated compromise lets the seller take the problem to a bidder who has not seen it. Halt anything that creates connectivity: integration planning access, network interconnects, identity federation, and uploading buyer-confidential material into target-hosted systems. Expect two to four weeks to a defensible preliminary scope in an environment with functioning telemetry. Without telemetry, expect the forensics firm to report that scope cannot be determined, which is worse news than a confirmed exfiltration.

What is the buyer's exposure if it closes knowing about the intrusion?

Substantial and largely uninsurable. On day one the buyer becomes the controller and inherits every outstanding notification duty, on an incident it documented knowing about. Remediation cost lands in year one against the underwritten operating plan. The representations and warranties policy will exclude the matter because underwriters exclude known issues, and the target's cyber policy may exclude it under a prior knowledge provision. Regulators assess retrospectively what an acquirer knew and did, as the Marriott penalty notice shows. Lender covenants, limited partner reporting, and SEC disclosure obligations may also attach.

What happens if the seller refuses to investigate or remediate?

Treat the refusal as a more serious finding than the compromise itself. A compromise is a technical condition with a cost. A refusal tells you how the management team you are buying handles bad news, what else has gone uninvestigated under the same posture, and how they will behave in month eighteen of your ownership. Escalate above the deal team to the seller's board or sponsor, who carry their own exposure. The correct position is no closing without an independent investigation funded from escrow, run by a firm the buyer selects, with a termination right on a defined adverse finding.

How do you preserve forensic evidence without destroying the investigation?

Preserve before you analyze and before you remediate. Endpoint telemetry, cloud identity logs, and network appliance logs all roll on retention windows measured in days or weeks. Take forensic images of identified hosts, snapshot relevant cloud volumes, extend retention on every identity and audit log source, export detection telemetry to cold storage, and have seller's counsel issue a litigation hold suspending routine deletion. Critically, do not let the target reset credentials and reimage hosts before scoping. That destroys the ability to determine whether data left, which is the answer that drives most of the cost.

Why is a compromise assessment not standard in technology due diligence?

Because most scopes are inherited from templates built around documentary review. A SOC 2 Type II attests to the design and operating effectiveness of selected controls over a period. It does not assert the environment is free of adversaries, and the auditor did not look. A penetration test measures exploitability at a point in time, not existing occupancy. Neither tests the seller's no-incident representation. Given that IBM put the 2025 United States average breach cost at 10.22 million dollars, the marginal cost of adding an assessment to a mid-market diligence scope is not a serious objection.

Marriott and Starwood: Four Years of Dwell Time Across a Transaction

The intrusion into the Starwood guest reservation database began in 2014. Starwood was an independent company at the time. Marriott International agreed to acquire Starwood Hotels and Resorts in November 2015 and completed the acquisition in September 2016.

The Starwood reservation environment kept running after closing. It was not immediately consolidated onto Marriott's own platform, which is a common and often sensible integration decision on grounds of customer continuity and migration risk. It also meant that a compromised environment continued to operate, under new ownership, for two more years.

On 7 September 2018, an internal security tool alerted on an anomalous query against the Starwood reservation database. Marriott notified the Information Commissioner's Office on 22 November 2018 and disclosed publicly on 30 November 2018. Approximately 339 million guest records were affected globally, including roughly 30 million records relating to residents of the European Economic Area and around 7 million associated with the United Kingdom. Exposed fields included names, email addresses, phone numbers, passport numbers, and loyalty programme data.

In July 2019 the ICO issued a notice of intent to fine Marriott 99 million pounds. On 30 October 2020 the final monetary penalty notice landed at 18.4 million pounds, a reduction that reflected representations made by Marriott, remedial steps taken, and the regulator's stated consideration of the economic impact of the pandemic on the hospitality sector.

The part that should concern every sponsor is the reasoning, not the number. The ICO's position was that Marriott "failed to undertake sufficient due diligence when it bought Starwood." The regulator further took the view that the obligation to conduct due diligence is not a time-limited or one-off requirement, meaning the assessment covered both what Marriott did before the acquisition and what it did in the two years afterward while operating the inherited environment.

Three things follow for a deal team.

First, an acquirer absorbed the regulatory consequence of a condition that predated its ownership by two years. The liability did not stay with the seller. It came across with the entity.

Second, the quality of the acquirer's diligence became evidence. Whatever technology diligence was performed in 2015 and 2016 became a document a regulator evaluated in 2019 and 2020. Deal teams do not usually write diligence scopes with that reader in mind.

Third, the finding was available. This was not an unknowable condition. It was an adversary present in a production database for four years, two of them under the acquirer's ownership, discovered eventually by a security tool doing exactly the kind of query monitoring a compromise assessment performs. The information existed the entire time. Nobody looked until 2018.

GBP 18.4 million

That is what the UK Information Commissioner's Office fined Marriott in October 2020 over an intrusion that began inside Starwood in 2014, two years before Marriott closed the acquisition. The regulator's stated basis included the quality of Marriott's due diligence at the time of purchase. The acquirer absorbed a regulatory penalty for a condition it inherited, and the diligence file was part of the record.

How Cloudskope Can Help

Cloudskope runs technology and cyber diligence for private equity sponsors, corporate development teams, and their counsel. Our scope includes an active compromise assessment, not just a documentary control review, because the representation the seller is about to make is a statement about the state of the environment and the only way to test it is to look. Where we find something, we work to the sequence in this article: notice to counsel the same day, preservation before analysis, out-of-band communications, and findings expressed as specific closing conditions and indemnity language rather than a severity rating. See our M&A Cyber and IT Technical Due Diligence practice for how the engagement is structured and staffed.

When a live finding surfaces mid-process, the constraint is time and the risk is destroying your own evidence. Cloudskope SARTUS is built for that window: rapid scoping, forensically sound preservation across endpoint, identity, network, and cloud log sources, and a defensible written position on dwell time, lateral movement, and whether data left, delivered under counsel in a form your investment committee and the seller's counsel can both work from. We coordinate with panel breach counsel and the carrier so coverage is not forfeited by the first engagement letter anyone signs.