For years, cybersecurity was considered a “check-the-box” discussion during the merger and acquisition (M&A) process. It was almost always examined to ensure there weren’t any glaring issues or major red flags—but there wasn’t a whole lot of care or thought put into it.
But this status quo process is no longer enough. History has shown that a lack of due diligence on cybersecurity during the acquisition process can be devastating to the acquiring organization. Luckily, there are tools available like Bitsight Security Ratings for Mergers & Acquisitions that can help you understand the true cybersecurity posture of your acquisition. Below is an information security due diligence checklist, highlighting the four reasons you should consider using Bitsight Security ratings before, during, and after any merger or acquisition.
4 Reasons To Use Security Ratings Before Your Next Acquisition
1. It saves you money in the immediate future.
You likely remember the newsworthy fiasco between Verizon and Yahoo: While Verizon was finalizing a deal to purchase Yahoo, Yahoo disclosed a major data breach. This news impacted the purchase price to the tune of $350 million. A detailed history of security issues at Yahoo emerged even after the deal was finalized.
Companies that conduct thorough due diligence of the security posture of acquisition targets using Bitsight Security Ratings review historical security data and can use that information to structure M&A deals. If their acquisition target has a long or constant history of security issues they may be able to negotiate a lower sale price to counteract potential cyber risks. More importantly, acquiring companies may also be able to help targets improve their cybersecurity posture, thereby reducing the level of risk incurred as a result of the transaction.
2. It saves you money in the long term.
While some companies have been breached during a merger or acquisition transaction, others have been breached well after the deal has gone through. A prime example is TripAdvisor’s 2014 purchase of Viator, a tour-booking company. Just a few weeks after the completed transaction, Viator’s payment card service provider announced that unauthorized charges occurred on many of its customers’ credit cards. The breach affected 1.4 million users and led to a four percent drop in TripAdvisor’s stock when the news broke.