PE firms spend months on financial due diligence. They scrutinize revenue quality, customer concentration, EBITDA normalization, and working capital. They hire bankers, accountants, and lawyers. Then they acquire a company with unpatched vulnerabilities on every endpoint, no incident response plan, and one sysadmin who is the only person who knows the admin passwords.
Sound hypothetical? It is the norm. Security due diligence at the platform acquisition stage is either absent or performed as a checkbox by someone who is not a security professional. Sponsors absorb liability they did not price, delay post-close integration, and spend meaningful capital remediating problems that were discoverable before the transaction closed.
The U.S. average cost of a data breach in 2025, a record high, according to IBM's Cost of a Data Breach Report. A breach six months after close is not just an incident cost. It is regulatory exposure, customer churn, rep-and-warranty claims, and a distraction from the 100-day plan.
Why Security Risk Is a Valuation Issue, Not an IT Issue
Security gaps are financial liabilities. They belong in the same conversation as deferred maintenance on a manufacturing floor or a customer concentration above 40%.
Three categories of deficiency compress valuation or create post-close write-downs: unquantified breach exposure from a company that has never had an independent penetration test, compliance gaps that create timeline risk in a regulated vertical, and insurance misalignment where the target's current policy is underpriced for its actual risk or carries a gap an underwriter could use to deny a claim.
The Pre-LOI Security Checklist
This is a working framework. It will not replace a full technical assessment, but it will surface the red flags that change the conversation before you are committed.
Identity and Access Management
Ask the target: is MFA enforced across all accounts, including admin? Is there a documented offboarding process? Are shared credentials in use?
Phishing is the number one initial attack vector globally, accounting for 16% of all breaches and averaging $4.8 million per incident per the 2025 IBM report. A Microsoft 365 environment accessible with a username and password alone is one phished credential from a full breach.
Red flags: no MFA on email, VPN, or admin systems. Shared passwords for critical systems. No offboarding process.
Endpoint Visibility
Does the company have EDR deployed across all managed devices, and who monitors the alerts? An EDR tool nobody watches is not a control. The IBM 2025 report found the mean time from initial breach to containment is 241 days. If nobody is watching, an attacker has eight months to move laterally before anyone notices.
Red flags: no EDR, or EDR without active monitoring. No security operations function, internal or managed.
Patch Management
When were all systems last patched? Is there a documented vulnerability management process? Unpatched systems are the most predictable attack surface. If the target does not have a defined SLA for critical patches, assume exploitable vulnerabilities are waiting.
Red flags: no vulnerability scanning program. Patches applied reactively. Unknown asset inventory.
Incident Response Readiness
A plan that exists in a drawer and has never been rehearsed is a document, not a plan. Ask for the plan, ask who owns it, and ask when it was last tested. If the answer is "we haven't had an incident," that tells you they have never practiced.
Red flags: no IR plan. No designated IR lead. No relationship with an external IR firm or retainer.
Third-Party Risk
What vendors have access to the company's systems or data, and how are they assessed? Attackers target smaller vendors to reach larger networks. Thirty unassessed SaaS integrations are thirty potential entry points.
Red flags: no vendor security assessment process. Unknown list of active integrations.
Compliance Standing
What regulatory frameworks apply, and what is the current compliance status? This matters most for platform acquisitions in regulated verticals. If the seller cannot demonstrate compliance, the deal structure or price has to reflect the remediation cost.
Red flags: no compliance program, no documented controls, no audit history in a regulated vertical.
Cyber Insurance Coverage
What coverage does the company carry, and what were the conditions at renewal? Many policies now exclude social engineering losses or require specific technical controls as a condition of coverage. If the target had to add controls to keep coverage at last renewal, that tells you what the underwriter found.
Red flags: coverage below $1 million for a company handling sensitive data. Significant exclusions. Coverage gaps relative to revenue.
Red Flags That Compress Valuation
Some findings are material enough to affect price or deal structure. A company with no dedicated security function and no board-level security accountability is running a program by accident. Open critical findings from a prior assessment are an attack surface with a documented address. Shadow AI usage adds an average of $670,000 to breach costs per the 2025 IBM report, and unmanaged usage means the data exposure is real and unquantified. A prior breach handled without third-party forensics, or a regulatory finding settled without root-cause remediation, is a credibility issue as much as a technical one.
What to Do With What You Find
The goal of pre-LOI security diligence is not to walk away from every deal with gaps. Most mid-market companies have gaps. The goal is to price, structure, and plan accordingly. These are the same gaps that deal teams tend to notice too late if nobody looks for them before signing.
Minor gaps with documented remediation plans support a standard deal structure, closing and fixing issues in the first 90 days. Moderate gaps, including no EDR or no IR plan, support an escrow holdback or a price adjustment tied to remediation milestones. Material gaps, including open critical vulnerabilities or active regulatory exposure, change the risk calculus at the LOI stage and require a full technical assessment before you move forward, not after.
A qualified security team with M&A experience can scope and complete that assessment in two to three weeks without disrupting the deal process.
One Provider. Named Accountability at Every Level.
Mid-market organizations face the same board scrutiny as enterprises. They face it with smaller teams, tighter budgets, and without the luxury of a full-time CISO.
Aetos One was built for that reality. Our A la carte security architecture review and penetration testing engagements give deal teams a working picture of platform-level risk before an LOI is signed. Our Guardian module carries that program forward after close.
Named fractional CISO. Owns the 100-day security roadmap after close.
AI-driven security operations, including scoped penetration testing to quantify breach exposure.
Continuous compliance automation, closing the gaps that would otherwise surface post-close.
If your board is asking the right questions and not getting the right answers, schedule a 30-minute conversation.