IT due diligence

In the context of M&A transactions, thoroughly examining potential risks is essential to avoid making poor legal, financial, and strategic decisions. While financial and legal due diligence has long been standard practice, IT due diligence is often underestimated. Given the increasing complexity of IT and the growing cyber threat, it is one of the most important components of a successful transaction.

What is IT due diligence?

IT due diligence is a structured process that identifies, evaluates, and addresses potential risks in a company's IT infrastructure, IT security, IT governance, including IT licensing and data organization. It aims to avoid serious consequences such as data loss, business interruptions, or reputational damage and to incorporate identified risks into the decision-making process regarding the transaction.

Why is IT due diligence so important?

In an era where cyber attacks increasingly threaten companies, inadequate IT infrastructure protection or improper data handling can cause lasting damage:

  • For buyers: Acquiring a company with inadequate protection or unidentified risks carries the risk of costly security incidents.
  • For sellers: Inadequate cyber security can result in warranty and compensation claims and have a negative impact on the sales price.

With an IT due diligence, the transaction parties can analyze the IT landscape of the target company, eliminate weaknesses and thus proactively minimize risks or regulate corresponding indemnifications and limitations of liability.

What are the advantages of an IT due diligence?

Comprehensive IT due diligence reduces the liability risk for both parties to the transaction by identifying potential threats and unaddressed security gaps at an early stage and addressing them in a targeted manner, both technically and legally. At the same time, the structures can be checked for compatibility with the potential buyer during the process. This not only protects the company from potential security incidents, but also from failures, data loss and reputational damage that can occur in crisis situations. In addition, a detailed audit ensures increased transaction security: buyers receive clarity about the IT security of the target company, while sellers can emphasize the value of their IT infrastructure and its resilience. Another advantage lies in the optimization of integration and migration after an acquisition, as the thorough analysis of the IT structure facilitates the integration process and ensures a smooth merger in the long term.

Our IT due diligence services

Our experienced team will support you in carrying out an IT due diligence, regardless of whether you are a buyer or a seller:

  • Analysis and evaluation of guidelines and processes
    We analyze the data protection strategy, security concepts and IT governance.
  • Clear and darknet monitoring
    We identify potentially published data, e.g. access data, as well as fake stores, domain squatting or other fraudulent activities at the expense of the target company.
  • Identification of weak points
    We investigate critical security vulnerabilities that can affect the company's valuation.
  • Review of third-party risks
    We evaluate service provider management in order to assess risks from external partners.
  • Preparation of a comprehensive report
    We provide a detailed description of the target company's IT governance and cyber security, including red flags, potential exclusion criteria and suggestions for improvement.
  • Recommendations for action and roadmap
    We develop concrete measures for you to eliminate weak points, including a cost and time frame for their implementation.

Contact persons

Dirk Koch

Dirk Koch

Attorney at Law | Partner

CEHv11 – Certified Ethical Hacker | Data Protection Risk Manager | CIPP/E

Olga Stepanova

Olga Stepanova

Attorney at Law | Partner

LL.M. (Berkeley) | CIPP/E | Certified Specialist for Intellectual Property Law | Certified Specialist for IT Law | Data Protection Officer (TÜV)

IT Due Diligence

The review covers, among other things, the IT systems and software licences in use, existing IT contracts, data protection compliance and any ongoing or threatened IT-related litigation. The IT security position, previous security incidents and a dark web analysis also play an important role in the risk assessment. In particular, it may be examined whether stolen employee access credentials are circulating and could enable attackers to access the company’s systems or data. The aim is to identify hidden legal, technical and financial risks before the transaction is completed.

Data protection breaches by the target company can place a considerable economic burden on the purchaser. A distinction must be made between the transaction structures. In a Share Purchase Deal, only shares in the target company are transferred. The target company remains the same legal entity and therefore itself remains the addressee of administrative fines, claims for damages and measures by supervisory authorities based on breaches from the period before the acquisition. There is no succession in law in the person of the purchaser in this respect; the purchaser bears the risk not as the debtor liable for the relevant obligations but economically, because legacy issues reduce the value of its investment and are realised after Closing at the expense of the company it holds. The position may be different in an Asset Deal and in transformations, where, depending on the structure, liabilities may transfer and, in the area of administrative fines, legal succession under Section 30 OWiG (German Act on Regulatory Offences) may occur; the data protection requirements applicable to the transfer of data holdings themselves must also be considered. Irrespective of the structure, deficient data protection organisation can materially reduce the actual value of the company, for example where customer data holdings include newsletter subscribers without verifiable Double-Opt-in. A thorough review before the contract is concluded makes it possible to take such risks into account in the purchase price, warranties and indemnities or through escrow arrangements.

Common problems include insufficiently licensed software, unclear rights of use in individually developed code or the use of open-source components with restrictive copyleft licences. Expiring or non-transferable licence agreements and change-of-control clauses may also cause problems after an acquisition. These risks should, where possible, be safeguarded contractually before the contract is concluded or taken into account in the purchase price.

The duration depends heavily on the scope of the IT landscape and the number of contracts to be reviewed. For smaller companies, a few days to a few weeks is usual; in more complex structures, it may take considerably longer. Good preparation by the target company, for example through a well-structured data room, can significantly accelerate the process. Time pressure in the transaction should not result in material review points being omitted.

Previous security incidents, inadequate protective measures or a lack of contingency plans may involve significant hidden costs and liability risks, for example because of impending administrative fines or necessary upgrades. Compliance with sector-specific and regulatory requirements, such as those arising from the implementation of NIS-2 or from DORA, should also be reviewed. These findings often feed into purchase price negotiations or warranty clauses.