CIO Brief: When You Buy a Company, You Buy Its Breaches
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't discovered until 2018, and regulators held Marriott responsible.
Why cybersecurity belongs in deal due diligence
Financial and legal due diligence are standard in acquisitions. Cybersecurity due diligence is often a questionnaire. But an acquired company can bring an active breach, unknown data liabilities and weak systems that become your problem the day the deal closes.
The business impact
- Inherited liability for breaches that began before you owned the company.
- Regulatory fines for failing to assess and secure acquired systems.
- Deal value — Verizon cut its price for Yahoo after breaches were disclosed.
Questions to ask in any acquisition
- Has the target had security incidents, and how were they investigated?
- Can we run read-only security checks on its main cloud systems before closing?
- What sensitive data does it hold, and under which regulations?
- What is our day-one plan to secure its administrator accounts and logging?
What good looks like
Security due diligence with technical checks proportionate to the deal size, a compromise assessment before or immediately after close, a 90-day integration plan, and security findings reflected in the deal terms.
The decision
Make a cybersecurity review — including a hunt for existing compromise — a required step in your acquisition process, with authority to influence price, terms and timing.
- Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition Incident Teardowns
- How to Run a Cloud Security Due Diligence Review During M&A How-To & Hardening
- Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments Detection & Response