Your board does not think you have a security problem. Neither does your deal team. Not yet. That changes the moment due diligence starts.

We have watched it happen too many times to count. A PE-backed company runs a tight ship operationally. Revenue is growing. The leadership team is sharp. The deal is as close to done as a deal gets. Then the security assessment starts, and within 48 hours, the deal team is staring at a findings report that reads like a threat actor's wish list.

Suddenly everyone has questions. Who is accountable for this? How long has this been the case? What is it going to cost to fix? And the one nobody wants to ask out loud: does this change the number?

The answer is often yes, and that is the problem. Security gaps do not appear during due diligence. They were there the whole time. Due diligence just created the deadline that forced everyone to look.


An Expensive Assumption

The most common mistake portfolio company leaders make is confusing compliance with security. They have a SOC 2 report. They have passed their annual pen test. They have checked the boxes the board asked them to check, and so they assume due diligence will go smoothly.

It does not, not usually. Compliance frameworks tell an assessor whether your processes are documented. They do not tell them whether those processes work.

68%

Of PE portfolio leaders reported cyber incidents are increasing during the hold period, and nearly 80% experienced disruption from a cyberattack, per a February 2026 Kroll survey of 325 leaders. Average financial impact: $2.1 million per incident.

Source: Kroll, "Private Equity: Cybersecurity, a Significant Risk to Deals with $2.1M Financial Impact on Average"

That is not a compliance failure. That is a security failure that compliance did not catch. The gap between compliant and secure is where deals bleed value, and it shows up in three consistent places.


Finding One: Identity Security Is a Mess

Multi-factor authentication is the most cited control in cybersecurity frameworks. It is also one of the most inconsistently deployed in practice. When a deal team's assessors walk into a portfolio company environment, they are not asking if MFA exists. They are asking where it does not.

The answer is usually everywhere it matters most: finance systems, ERP platforms, remote access tools, cloud environments built by developers who bypassed IT, service accounts that have not been reviewed since the last CTO left.

BeyondTrust's analysis of M&A identity risk found that 42% of deals experience a reduction in valuation due to cyber issues, and a separate finding noted that 20% of transactions are delayed or paused entirely due to cyber red flags.

Source: BeyondTrust, "5 M&A Cyber Due Diligence Truths About Identity Risk"


Finding Two: Nobody Has a Tested Response Plan

A deal team wants to see evidence that you have prepared for a bad day. What they usually find instead is a document in a shared folder that has not been updated since the last time a compliance auditor asked for it.

Cybri's due diligence guidance notes that assessors reviewing incident history request breach logs from the past 24 to 36 months and specifically look to confirm a tested incident response plan exists. Tested, not just written.

Source: Cybri, "Cybersecurity Due Diligence: A Guide for M&A Transactions"

A plan that has never been exercised is a theory. Deal teams know the difference between companies that have run tabletop exercises and companies that are hoping the plan works when they need it. The former get credit for it. The latter get a finding.

There is also a regulatory dimension. The SEC's 2023 cybersecurity disclosure rules require public companies to report material incidents within four business days of determining materiality. Portfolio companies that are IPO candidates need to demonstrate they can meet that standard. Many cannot.


Finding Three: Nobody Knows What's Critical

Security is a risk management discipline. You cannot manage risk you have not mapped. One of the most revealing questions in a pre-transaction assessment is simple: show me your critical business processes and the systems that support them.

Most companies struggle to answer it cleanly. They know their revenue. They know their customers. But the connection between specific business outcomes and the IT assets, access points, and data flows that enable them is rarely documented.

EY's analysis of PE cybersecurity identifies announcement and onboarding as a period of heightened cyber risk specifically because the convergence of two technology environments creates blind spots that attackers target.

Source: EY, "How private equity cybersecurity can improve deal value creation"


Understanding the True Cost

Kroll's 2026 research found that 26% of PE firms reported reduced valuation or exit price due to cyber incidents. WTW's 2024 Cyber Claims Analysis reported average ransom demands of nearly $5 million, not counting forensics, legal costs, or business interruption.

Source: WTW, "Cyber Risks in Private Equity"

But the dollar figures miss the most expensive part: timeline. A cybersecurity finding during due diligence does not just affect price. It affects pace. Infosys's due diligence research notes that more than half of survey respondents reported a major undiscovered cybersecurity risk revealed during post-closing integration, not diligence. That is a problem that arrives after the leverage is gone.

Source: Infosys, "Cybersecurity Due Diligence in M&A"


The Case for Getting Ahead of It

The alternative is a pre-transaction security assessment, conducted 12 to 18 months before a planned exit or acquisition process, that covers the three areas deal teams consistently flag.

What to assess before a transaction

Identity security and access governance Close the gaps deal teams find first.

Incident response readiness A tested plan, not a document in a drawer.

Mapping business processes to IT assets So prioritization is not guesswork.

Companies that do this work in advance show up to due diligence with clean evidence. They have remediated the findings, tested their playbooks, and know what is critical and why. That is a negotiating posture, not just a security posture. The companies that learn this lesson before the LOI gets signed are the ones that close on their terms. For the specific findings that shift price or structure, see what your security review is missing before you sign the LOI.


One Provider. Named Accountability at Every Level.

Mid-market organizations face the same board scrutiny as enterprises. They face it with smaller teams, tighter budgets, and without the luxury of a full-time CISO.

Aetos One was built for that reality. Our Guardian module assigns a named fractional CISO who maps your critical business processes and owns your pre-transaction readiness. Our Bastion module closes identity and detection gaps before a deal team finds them.

Guardian

Named fractional CISO. Maps critical business processes to IT risk before a deal team asks.

Bastion

AI-driven security operations, closing identity and detection gaps with named analyst coverage.

Citadel

Continuous compliance automation, keeping evidence audit-ready ahead of any transaction timeline.

If your board is asking the right questions and not getting the right answers, schedule a 30-minute conversation.