How to Run a Cloud Security Due Diligence Review During M&A
Retrospective: this article looks back at events from November 2018, written in 2026 with the benefit of hindsight.
When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence review — before and immediately after an acquisition.
Before signing: questionnaire and evidence
Request:
- Known security incidents in the past five years, with reports.
- Recent penetration tests and audit reports (SOC 2, ISO 27001).
- An inventory of cloud tenants and accounts: Microsoft 365, Azure subscriptions, AWS accounts, major SaaS.
- Identity setup: MFA coverage, admin counts, federation.
- Data inventory: where customer data is stored and under which regulations.
Before signing: technical sampling (if permitted)
With agreement, run read-only assessments such as CISA ScubaGear or Microsoft's Zero Trust Assessment for Microsoft 365, and Prowler or Security Hub results for AWS. Look for signs of compromise, not just weak configuration.
Day one after closing
- Take control of the highest-privilege accounts and break-glass access.
- Enforce MFA on all admin accounts if not already in place.
- Enable logging and send it to your SIEM.
- Run a compromise assessment: suspicious OAuth apps, mailbox rules, unknown admin accounts, unusual service principals, unexplained IAM users and keys.
First 90 days
- Decide for each environment: migrate, integrate or isolate.
- Apply your security baselines.
- Retire duplicate tenants and accounts.
Common mistakes
- Treating the target's environment as trusted because the deal closed.
- Connecting networks or establishing tenant trust before assessment.
- Marriott-Starwood (Nov 2018): A Four-Year Intrusion Inherited Through Acquisition Incident Teardowns
- Hunting for Long-Dwell Intruders in Cloud and Hybrid Environments Detection & Response
- CIO Brief: When You Buy a Company, You Buy Its Breaches CIO Briefings