SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
Companies warned of inherited cyber risks in acquisitions

Companies warned of inherited cyber risks in acquisitions

Fri, 2nd Oct 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Quest Technology Management has warned that companies can inherit cybersecurity risks when they acquire another business. President and Chief Executive Officer Tim Burke said buyers can take on responsibility for unpatched systems, monitoring gaps, poorly configured security tools and legacy technology as soon as a deal closes.

He argued that cybersecurity should be reviewed alongside financials before a deal is signed, particularly for midmarket acquirers with smaller internal teams. While acquisitions often focus on customers, staff and revenue, a target company's technology estate can bring hidden liabilities. Weaknesses that have built up over years do not disappear when ownership changes and can move straight into the buyer's environment.

That can turn integration into a security issue from day one. The concern is not only whether a target has security products in place, but whether those tools still cover the full environment and whether known flaws are being fixed quickly enough.

"The mistake is treating the technology review as something to sort out after the deal closes," Burke said. "By then it is already your risk, and you have lost the leverage to price it in or walk away. The security condition of what a company is buying belongs at the same table as the financials, before anyone signs."

Due diligence

Burke said a list of software and systems is not enough to assess cyber exposure in a transaction. He pointed instead to incident history, visibility across connected devices and confirmation that monitoring still reflects the target company's current environment.

Buyers should verify what assets are present, which vulnerabilities remain unresolved and whether missing patches have been addressed before integration begins. Where that cannot be confirmed, the inherited environment should be treated as uncertain rather than secure.

"A checklist of security products tells you what a company bought, not what it actually protects," Burke said. "Ask to see the incident history, and confirm whether the monitoring still covers the environment they have today. Until that is verified, everything being inherited should be treated as unknown, not secure."

The issue is particularly acute in the midmarket, where buyers may not have the specialist deal teams that larger groups can deploy during an acquisition. In those cases, technology review can be pushed behind commercial and operational priorities, even though weaknesses in the acquired environment may create immediate exposure.

Integration risks

Burke also highlighted the period after a transaction, when the buyer and target begin linking networks and systems. He said that stage can expose weaknesses that had remained contained within one company's environment until the two sides were connected.

Legacy infrastructure, outdated devices and systems that have fallen out of routine review can become more significant once integration starts. Problems that were previously dormant may then affect the wider combined business.

"The most dangerous moment is the rush to connect the two networks, because that is when each company inherits the other's weaknesses," Burke said. "The companies that handle it well resist the urge to connect quickly. They get a clear picture of what they are joining, close the worst gaps first and treat integration as a planned project instead of an IT afterthought."

His comments reflect a broader challenge in mergers and acquisitions, where cyber due diligence has become more prominent as companies rely on larger and more complex digital estates. Buyers are assessing not only a target's financial position and legal obligations, but also the condition of its systems, the state of patching and the reliability of its monitoring tools.

For acquiring companies, that means understanding whether a target's technology environment has been maintained properly and whether any known weaknesses could create operational or security problems after completion. It also means recognising that inherited cyber exposure may affect valuation, integration planning and post-deal risk management.

Burke said review is safer and less costly before systems are connected than after a problem emerges.