The acquisition due diligence the CISO has been involved in has become the diligence the CISO has been quietly dreading, the diligence that decides whether the enterprise buys the company the CISO is about to inherit the security debt of. The honest framing matters here, because the acquisition due diligence the finance team has been treating as the financial exercise sits as the acquisition due diligence the CISO will be living with for the next three years after the deal closes.
What follows runs as the working version of the field guide. The shorter version is what the CISO and the integration team actually have time to read.
What the CISO should review
Three things, in roughly that order of how much each one matters. The first runs as the breach history, where the history the target company has been quietly hoping the acquirer does not find, the breach the target disclosed, the breach the target did not disclose, the breach that will be inherited the day the deal closes, the history the CISO should reconstruct from the public disclosure, the regulatory filing, the dark web monitoring. The second runs as the security debt, where the debt the target company has been quietly accumulating, the debt that shows up as the legacy system, the unpatched service, the orphan admin account, the debt the CISO will inherit the day the deal closes, the debt the financial due diligence will not have surfaced. The third runs as the compliance posture, where the posture the target company has been claiming the posture is, the SOC 2 the target has been showing the enterprise, the ISO 27001 the target has been presenting the audit committee, the posture the CISO should verify rather than accept the marketing for.
What the typical review misses
Three things, in roughly that order of how often each one shows up. The first runs as the third party risk, where the risk the target company has been inheriting from the third party, the SaaS the target depends on, the supplier the target has been paying without the security review, the risk the CISO will inherit when the integration begins, the risk the financial due diligence will not have surfaced. The second runs as the incident response maturity, where the maturity the target company has been claiming, the runbook the target has been showing, the runbook the CISO should test before the deal closes, the maturity the CISO will discover in the first incident after the deal closes if the maturity does not actually exist. The third runs as the culture gap, where the gap the target company has been quietly maintaining, the gap between the security policy the target has been writing and the security practice the target has been following, the gap the CISO will discover in the first quarter after the deal closes, the gap the CISO should be probing for in the interview with the target’s security team.
How to make the review actually count
Three moves if you are the CISO who has been asked to sign off on the acquisition the CISO has been quietly dreading. Ask for the data room access, where the access the CISO should request, the access that includes the SOC report, the penetration test, the incident log, the access the finance team has been treating as the security team’s only need, the access the CISO should expand to include the actual data the CISO needs to make the call. Run the targeted interview, where the interview the CISO should run with the target’s security lead, the interview that asks the questions the SOC report cannot answer, the interview that probes the culture, the maturity, the gap, the interview the CISO should hold in person when the deal is far enough along. Make the deal contingent on the remediation, where the remediation the CISO should write into the purchase agreement, the remediation that the target has to complete before the deal closes, the remediation that includes the specific control the CISO needs the target to fix, the remediation that gives the CISO the veto the CISO has not had on the deal terms. The CISO that asks, interviews, and makes contingent serves as the CISO that has actually counted in the deal.

The bottom line
CISO and acquisition in 2026 sit as the diligence the CISO has been quietly dreading. The breach history, the security debt, the compliance posture, those three are what the CISO should review. The third party risk, the incident response maturity, the culture gap, those three are what the review misses. The data room, the targeted interview, the contingent remediation, those three are the moves. The CISO that does the three has actually counted in the deal. The CISO that signs off based on the SOC 2 alone serves as the CISO who will be writing the postmortem the deal produced.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


