Cybersecurity due diligence checklist for M&A sellers and their advisors
A cybersecurity due diligence checklist for M&A covers incident history, access control, authentication, backups, vendors and governance. Advisors use it before launch so sellers can answer buyer questions fast. The same controls decide whether records can be exported safely if the company later licenses them to AI developers.
Why run a cybersecurity checklist before a sale?
A seller who cannot answer a buyer's security questions risks delay or a price question. This checklist helps M&A advisors prepare a client for those questions: incidents, access control, backups and multi-factor authentication, plus the secure export paths that also govern any delivery of licensed records.
Work through it in the first weeks of engagement, before the teaser goes out, so findings can be fixed or explained. The confirmatory due diligence stage is too late to discover an unlogged incident.
The checklist
Incident and breach history
- A written list of security incidents in the past several years, with dates, scope and resolution
- Notices sent to customers, regulators or insurers, and counsel's view on whether any were required
- Open investigations, claims or ransom events, if any
- Post-incident reviews and the changes they produced
Access control
- Current list of admin accounts for email, cloud, CRM, finance and code repositories
- Joiner, mover, leaver process with last-review date
- Shared and service accounts, with an owner for each
- Former employees and vendors confirmed removed
Authentication
- Multi-factor authentication enabled on email, remote access, admin consoles and finance tools
- Exceptions listed with reasons and compensating controls
- Password manager or single sign-on in use
Backups and recovery
- Backups of critical systems, kept separately from the production environment
- Restore tested within the past year, with the result recorded
- Documented recovery plan and an owner
- Archives of retired systems located and readable
Endpoint, network and vendors
- Patching cadence and device inventory
- Endpoint protection and logging coverage
- Key vendors with access to company data, and the contract terms covering security
- Cyber insurance policy, limits and application answers
Governance
- Named security owner, even if part-time or outsourced
- Written policies, with approval dates
- Employee training records
How should advisors read the results?
| Result | What it means | Next action |
|---|---|---|
| Item complete with evidence | Buyer can verify quickly | Place evidence in the data room index |
| Item partly complete | Gap explainable if remediation is under way | Prepare a short written explanation and a dated plan |
| Item missing | Likely to draw a price or indemnity question | Fix before launch where feasible; brief the client on exposure |
| Undisclosed incident found | Disclosure and legal questions | Stop and involve the client's counsel before any further sharing |
Cyber findings often feed later negotiations on representations and warranties; see survival periods for reps and warranties and the questions insurers raise in RWI underwriting calls. If the client is a financial institution, the FTC's Safeguards Rule guidance says covered businesses must maintain a written information security program; counsel should confirm whether it applies. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
What does a secure export path look like?
The controls above also decide whether a company can safely hand over records in any later transaction, including a data licensing deal. When SourceX works with a company, de-identification and redaction requirements are agreed before any work begins, and delivery happens only after an executed agreement and the company's authorization. Large deliveries stay in the seller's own storage or ship on encrypted drives. The company needs:
- A named person who can run exports from each system.
- Least-privilege access for that person, with logging switched on.
- An encrypted transfer method and a record of who received what.
- A tested way to remove temporary copies afterwards.
Advisors never touch the records. You note the system names and years, and the company handles the rest.
Which clients fit a data licensing introduction?
Security-conscious companies with long histories are good candidates. They typically have 50+ full-time employees at peak (contractors excluded), several years of documented operations, records across many systems and rights to license the data; see who qualifies. Run the company fit checker with the owner for a preliminary view. For deal context, the site visit preparation checklist pairs well with this list, and the sector lists for staffing agencies and manufacturers add industry questions.
How do advisors earn from an introduction?
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 cumulative per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; a lead, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. Check your own rules on referral fees and disclosure, and your engagement letter terms, before registering. See referral opportunities for M&A advisors and the program terms.
Red flags
- An incident that was never documented or reported to the right party
- Admin accounts nobody can explain
- Backups never restored
- Records of a retired system with no one able to read them
- A client unwilling to discuss an exclusive license
Next step
Send the checklist to your next mandate and review the answers together. If the client also holds years of operational records, register as a partner to introduce it, or have the owner apply at sourcex.si/apply. Buyers beyond the usual acquirers are covered in the buyer list guide.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
When should a seller run a cybersecurity review?
Before the teaser goes out, so findings can be fixed or explained. Buyers may raise security questions after the letter of intent, and an unlogged incident discovered then costs time and trust.
Do sellers have to disclose past breaches to buyers?
Buyers ask, and purchase agreements often include representations about incidents. Whether a specific disclosure or notice is legally required depends on the facts and the jurisdiction. Raise any past incident with the client's counsel before sharing detail with a buyer.
Is multi-factor authentication expected by buyers?
It is a common diligence item for email, remote access and admin tools, and cyber insurance applications may ask about it too. Missing coverage does not end a deal, but a dated remediation plan and a clear list of exceptions lets the seller answer credibly.
What evidence belongs in the data room for security?
Policies, an incident log, access reviews, backup test records, the cyber insurance policy and vendor security terms. Redact customer names and personal data first. Share only what the buyer needs at each stage, as advised by counsel.
How do security controls relate to data licensing?
A company licensing operational records must be able to export them safely, with logging and encrypted transfer. SourceX agrees redaction rules and requires an executed agreement before delivery. Advisors only introduce the company; they never handle or describe confidential records.
Related pages
- What is confirmatory due diligence, and what happens after the LOI?
- How long do reps and warranties survive, and how do data licenses affect claims?
- RWI underwriting call questions: data, privacy and AI topics to prepare
- Which US businesses are a fit for a SourceX data licensing introduction
- Check Company Fit for Data Licensing
- How should a seller prepare for an M&A buyer site visit?
Free resources
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment