Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking & Finance Review®

Global Banking & Finance Review® - Subscribe to our newsletter

Company

    GBAF Logo
    • About Us
    • Advertising and Sponsorship
    • Profile & Readership
    • Contact Us
    • Latest News
    • Privacy & Cookies Policies
    • Terms of Use
    • Advertising Terms
    • Issue 81
    • Issue 80
    • Issue 79
    • Issue 78
    • Issue 77
    • Issue 76
    • Issue 75
    • Issue 74
    • Issue 73
    • Issue 72
    • Issue 71
    • Issue 70
    • View All
    • About the Awards
    • Awards Timetable
    • Awards Winners
    • Submit Nominations
    • Testimonials
    • Media Room
    • FAQ
    • Asset Management Awards
    • Brand of the Year Awards
    • Business Awards
    • Cash Management Banking Awards
    • Banking Technology Awards
    • CEO Awards
    • Customer Service Awards
    • CSR Awards
    • Deal of the Year Awards
    • Corporate Governance Awards
    • Corporate Banking Awards
    • Digital Transformation Awards
    • Fintech Awards
    • Education & Training Awards
    • ESG & Sustainability Awards
    • ESG Awards
    • Forex Banking Awards
    • Innovation Awards
    • Insurance & Takaful Awards
    • Investment Banking Awards
    • Investor Relations Awards
    • Leadership Awards
    • Islamic Banking Awards
    • Real Estate Awards
    • Project Finance Awards
    • Process & Product Awards
    • Telecommunication Awards
    • HR & Recruitment Awards
    • Trade Finance Awards
    • The Next 100 Global Awards
    • Wealth Management Awards
    • Travel Awards
    • Years of Excellence Awards
    • Publishing Principles
    • Ownership & Funding
    • Corrections Policy
    • Editorial Code of Ethics
    • Diversity & Inclusion Policy
    • Fact Checking Policy
    Original content: Global Banking and Finance Review - https://www.globalbankingandfinance.com

    A global financial intelligence and recognition platform delivering authoritative insights, data-driven analysis, and institutional benchmarking across Banking, Capital Markets, Investment, Technology, and Financial Infrastructure.

    Copyright © 2010-2026 - All Rights Reserved. | Sitemap | Tags

    Editorial & Advertiser disclosure

    Global Banking & Finance Review® is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    1. Home
    2. >Business
    3. >With deals set to surge in 2024, don’t forget to manage M&A cyber risk
    Business

    With Deals Set to Surge in 2024, Don’t Forget to Manage M&A Cyber Risk

    Published by Jessica Weisman-Pitts

    Posted on December 1, 2023

    6 min read

    Last updated: January 31, 2026

    Add as preferred source on Google
    A business team collaborates on managing M&A cyber risks, highlighting the importance of cybersecurity in mergers and acquisitions. This image underscores the article's focus on due diligence and strategic planning for 2024.
    Business team discussing M&A strategies and cyber risk management - Global Banking & Finance Review
    Why waste money on news and opinion when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe

    Tags:cybersecurityrisk managementfinancial servicesDue Diligence

    With deals set to surge in 2024, don’t forget to manage M&A cyber risk

    By Lawrence Perret-Hall, COO at CYFOR Secure

    It’s been a tough year for mergers and acquisition (M&A) deals, but the gloom may be lifting. Industry watchers and business leaders predict activity will bounce back in 2024, with 94 percent of European financial services CEOs expecting to pursue strategic transactions in the coming 12 months. They know dealmaking is fraught with risk for both buyers and sellers. But one factor that is often underestimated is the potential impact of cyber risk on M&A outcomes.

    Given the financial and reputational stakes involved, relying on self-disclosure to inform cyber risk is not enough. That’s why business leaders need to carry out comprehensive cybersecurity risk assessments to make better informed decisions. Anything less might lead to a heavy dose of buyer’s remorse.

    Due diligence is a must

    Although global dealmaking is some way from the highs of 2021, there are reasons for cautious optimism in the year ahead. Gartner claims that well capitalised enterprises may swoop for smaller tech-focused startups struggling to raise VC funding in a new wave of “techquisitions”. Moreover, Bird & Bird argues that both buyers and sellers are “prepared to deal” in order to scale their business and/or enter new markets.

    Those boards responsible for making such decisions are well versed in the typical legal, financial, and operational risks that M&A deals can throw up. They also understand the importance of due diligence in uncovering these risks early on in order to make better informed M&A decisions, but cyber risk is still too often overlooked despite the serious impact it can have.

    Acquiring companies need to look more carefully at target businesses: serious deficiencies in their security posture or unidentified breaches could have a major impact on deal price, or whether a deal can even be done. Even if a transaction has already gone through, risks should be identified as quickly as possible so remedial steps can be taken to minimise any long-term erosion of deal value.

    What might be wrong?

    Many organisations sport a blend of legacy on-premises systems and modern, distributed cloud architectures and, combined with a fast-evolving threat landscape, this can lead to cyber risks that even a target company may be unaware of. From cloud-native software development, to AI, Internet of Things, data analytics, and even home working laptops, countless modern investments expand the potential attack surface. And risks extend beyond an organisation’s network: many have opaque supply chains which are often left unmanaged. One 2022 study claims two-fifths of global organisations feel their cyber attack surface is “spiralling out of control”.

    Threat actors are primed and ready to take advantage. Tapping a cybercrime economy worth trillions annually, they target organisations at their weakest points. That could be the individual employee, susceptible to phishing links while working on an unprotected laptop at home, or it could be a remote desktop protocol (RDP) endpoint misconfigured to allow a brute force password cracking attack. They are spoilt for choice.

    The cybercrime underground provides a readymade marketplace for vulnerability exploits, stolen credentials, and even easy-to-use “as-a-service” offerings which lower the bar to entry for non-technical threat actors. With relatively little skill, a budding cybercriminal can gain or purchase access into a corporate network and move laterally unseen until they find sensitive data to steal and/or encrypt for ransom. That’s why 59 percent of mid-sized UK firms and 69 percent of large businesses experienced a breach in 2022. And it’s why 2023 is already a record year for publicly reported US data breaches.

    Some cautionary tales

    Cyber due diligence is essential to root out serious problems. It could be widespread vulnerabilities or misconfigurations that need fixing, or dangerously low levels of staff security training and awareness. It could be the presence of malware or even threat actors inside the network. Or it may be an undiscovered and/or undisclosed data breach. Any of these issues and a range of others may expose the acquiring company to serious financial, reputational, and regulatory risk.

    Nor are these merely theoretical risks. Consider the infamous Verizon acquisition of Yahoo, when the discovery of historic data breaches at the internet pioneer led Verizon to negotiate down its purchase price by $350m, or around 7% of deal size. Marriott International was not so fortunate when it acquired Starwood Hotels in 2016: its due diligence failed to spot a 2014 mega-breach at the firm which, when finally revealed in 2018, led to major regulatory fines, negative publicity, and class action lawsuits for Marriott.

    How to mitigate M&A risk

    So how should acquiring firms proceed with their cyber due diligence process? How deep they want to peer into a target organisation will depend on risk appetite. But at a bare minimum, things like vulnerability assessments and penetration testing can provide useful insight into the cyber-resilience of an organisation’s internal and external networks, devices, and assets.

    More broad-based risk assessments may help to uncover a target company’s approach to breach management, disaster recovery, business continuity, and compliance with industry regulations and standards like GDPR or ISO 27001. Dark web monitoring allows organisations to see if corporate data or credentials from a target company have been breached and put up for sale.

    With this context, an acquiring company will be able to make better informed decisions. It may mandate that a target company remediates any serious issues before transaction, it may want to reprice the deal, or even walk away altogether. Even after a transaction has been completed, due diligence can provide critical insight to reduce risk exposure and support compliance programmes as quickly as possible. A virtual CISO service can be invaluable here in helping the acquiring company to develop relevant policies and awareness.

    Cyber risk is an increasingly important business risk. Organisations that understand this will be best placed to make a success of their M&A deals. But boards that continue to dismiss IT security as a mere cost centre may have some nasty surprises in store next time they go shopping for a new acquisition.

    Frequently Asked Questions about With deals set to surge in 2024, don’t forget to manage M&A cyber risk

    1What is cybersecurity?

    Cybersecurity refers to the practice of protecting systems, networks, and programs from digital attacks. It involves implementing measures to safeguard sensitive information and maintain the integrity of technology systems.

    2
    What is due diligence?

    Due diligence is the process of investigating and evaluating a business or investment opportunity. In M&A, it involves assessing financial, legal, and operational aspects to identify potential risks and benefits.

    3What is M&A?

    M&A stands for mergers and acquisitions, which are transactions where companies consolidate through various types of financial transactions, including mergers, acquisitions, and asset purchases.

    4What is a cybersecurity risk assessment?

    A cybersecurity risk assessment is a systematic process to identify, evaluate, and prioritize risks to an organization's information systems and data, helping to inform security measures and strategies.

    5What is a breach in cybersecurity?

    A breach in cybersecurity occurs when unauthorized access to data or systems is gained, potentially leading to data theft, loss, or damage, impacting an organization's operations and reputation.

    More from Business

    Explore more articles in the Business category

    Image for Submit Your Entry for Years of Excellence Awards 2026
    Submit Your Entry for Years of Excellence Awards 2026
    Image for Nominations Open for Travel & Hospitality Awards 2026
    Nominations Open for Travel & Hospitality Awards 2026
    Image for Submit Your Entry Today for Telecom Awards 2026
    Submit Your Entry Today for Telecom Awards 2026
    Image for Submit Your Entries for The Next 100 Global Awards 2026
    Submit Your Entries for the Next 100 Global Awards 2026
    Image for Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Submit Your Entry: Public Sector & Governance Excellence Awards 2026
    Image for Nominations Invited for Real Estate Development Awards 2026
    Nominations Invited for Real Estate Development Awards 2026
    Image for Submit Your Entry: Process & Product Awards 2026
    Submit Your Entry: Process & Product Awards 2026
    Image for Call for Entries: HR & Recruitment Awards 2026
    Call for Entries: HR & Recruitment Awards 2026
    Image for Submit Your Nominations Today for Education & Training Awards 2026
    Submit Your Nominations Today for Education & Training Awards 2026
    Image for Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Join the Corporate Governance Awards 2026: Showcase Your Organisation’s Leadership
    Image for Submit Your Entry Today for Business Awards 2026
    Submit Your Entry Today for Business Awards 2026
    Image for Decentralized Masters’ ‘family culture’ building trust instead of hierarchy
    Decentralized Masters’ ‘family Culture’ Building Trust Instead of Hierarchy
    View All Business Posts
    Previous Business PostThe Future of Logistics: Lucas Grizz’s Vision for a Tech-Driven Industry With Raven Cargo
    Next Business PostNew Jersey Business Formation Checklist