A pre-acquisition security audit is the fastest way to find out whether the target’s technology is an asset you’re buying or a liability you’re inheriting. In a distressed deal, it’s the difference between pricing cyber risk into the bid and discovering a live breach two weeks after close. This checklist turns a security review into five discrete phases, each with a numbered list you can hand straight to your diligence team.
Work top to bottom. Each phase is designed to be completed in sequence, and each step can be answered as yes, no, or reinforce with evidence. Anything that comes back as “no” is a finding to quantify, not just a note to file.

The 5-Phase Pre-Acquisition Security Audit Checklist
Phase 1 — Breach History & Exposure (Days 1–2)
- Has the target experienced a material cyber incident in the past 24 months? Request the incident response report and root-cause remediation evidence.
- Are credentials from the target’s domain exposed in breach databases (Have I Been Pwned domain search, SpyCloud, DeHashed)?
- Is the target’s attack surface mapped — every internet-facing asset, API, and remotely accessible service inventoried?
- Are there any publicly disclosed breaches, CVEs, or security researchers’ reports referencing the target?
- Has the target disclosed the breach history honestly against what external scanning shows?
Phase 2 — Vulnerability & Patch Posture (Days 2–4)
- When was the last third-party penetration test? Obtain the full report, not just the executive summary.
- What is the mean time to patch (MTTP) for critical and high-severity vulnerabilities?
- Are there known unpatched critical vulnerabilities in production systems right now?
- Which software is end-of-life or unsupported (Windows Server 2008/2012, unsupported ERP, legacy custom apps)?
- Run an external vulnerability scan against all known internet-facing assets to validate the target’s claims.
Phase 3 — Identity, Access & Third-Party Risk (Days 3–5)
- Is multi-factor authentication enforced on email, VPN, admin consoles, and cloud platforms?
- Are there shared admin accounts with no individual accountability?
- Do any former employees or terminated contractors still hold active access?
- Map every third-party vendor with system access — what level of access, is MFA enforced, when was it last reviewed?
- Is privileged access management (PAM) in place for critical systems, or is it default/shared credentials?
- Is there single sign-on (SSO), or do identity silos create unmanaged access paths?
Phase 4 — Resilience, Compliance & Insurance (Days 4–6)
- Does a tested incident response plan exist, and when was the last tabletop exercise?
- Is there an incident response retainer with an external firm, and what are the target’s MTTD/MTTR metrics?
- Which certifications does the target hold (SOC 2, ISO 27001, Cyber Essentials), and are they current?
- What regulatory framework applies (GDPR, CCPA, HIPAA, PCI DSS), and what is the quantified penalty exposure?
- What cyber insurance coverage exists — limit, retention, ransomware/business-interruption cover, and any change-of-control clause?
- Has the target made any cyber insurance claims in the past 3 years?
Phase 5 — Downside Quantification & Deal Terms (Days 6–10)
- Build a conservative breach scenario: direct costs, business interruption, regulatory penalties, reputational impact.
- Price the remediation backlog — legacy replacement, MFA/IAM overhaul, vulnerability remediation, IR program build-out.
- Estimate the cyber insurance gap if the existing policy is minimal or voidable post-acquisition.
- Decide how findings translate to terms: purchase price reduction, holdback/escrow, cyber reps & warranties, R&W insurance, or walk-away right.
- Set the post-close remediation milestones with named owners and a tracked timeline.
Why These Five Phases Matter
Each phase targets a different failure mode in distressed deals. Phases 1 and 2 surface the undiscovered breach and the unpatched attack surface — the two things that destroy value immediately. Phase 3 catches the access paths nobody reviewed. Phase 4 converts vague “we have policies” claims into verifiable evidence and quantified penalty exposure. Phase 5 is where the audit stops being a security exercise and becomes a deal instrument, converting findings into price, holdbacks, and reps.
Download the Full Worked Example
For a complete walkthrough of a security review written as a real deliverable — including a fictional distressed carve-out with quantified findings and a remediation cost model — see our technical due diligence report example.
Frequently Asked Questions
What is a pre-acquisition security audit?
A pre-acquisition security audit is a structured assessment of a target company’s security posture — breach history, vulnerability exposure, identity and access controls, third-party risk, compliance, and insurance — conducted before a deal closes so cyber risk can be priced and negotiated into the transaction.
How long does a pre-acquisition security audit take?
A focused audit covering the highest-signal checks can be completed in 5 to 10 business days. Full penetration testing and architecture review extend that to 4 to 8 weeks. Distressed deals should run the accelerated sprint first, then deepen scope only where findings warrant it.
What is the difference between a security audit and IT due diligence?
IT due diligence asks whether systems work and what they cost. A security audit asks whether systems are secure and what risks they carry. IT DD covers performance and scalability; the security audit covers vulnerabilities, breach history, compliance, and residual risk that can change deal value.
Why is a security audit critical in a distressed acquisition?
Distressed companies typically run unsupported legacy systems, have skeleton IT teams, paused patching, and no tested incident response plan. They are more likely to have an active, undiscovered breach — and the buyer inherits every liability the moment the deal closes.
Can cyber findings actually change the purchase price?
Yes. Quantified cyber findings justify purchase price reductions, 12 to 18 month holdbacks tied to remediation milestones, specific cyber representations and warranties, and in some cases a walk-away right if pre-close testing reveals a material active breach.
