Half of M&A Cyber Audits Uncover Undisclosed Breaches That Derail Deals

Stu Sjouwerman | Nov 15, 2019

Cybersecurity diligence performed prior to a merger or acquisition often uncovers weaknesses in an organization’s security stance, which can spell doom for the company being purchased and a resulted phishing attack.Cyber Security on the Mechanism of Metal Gears.

It appears that a company’s lack of security can make or break an M&A deal. According to the new Cybersecurity Assessments in Mergers and Acquisitions report from (ISC)2, 100% of organizations perform some form of cyber audit of the company being bought.

But a bit more than half (57%) of organizations report finding a previously undisclosed (or potentially unknown) data breach as part of the audit. And nearly half (49%) of organizations have seen a deal be cancelled because of it.

Nearly all organizations (95%) consider cybersecurity to be a tangible asset. In fact, 82% of organizations believe the stronger a company’s cybersecurity infrastructure is, the higher the value assessed to the organization. According to the report, this includes “soft” assets such as risk management policies and security awareness training programs. In contrast, only 63% of organizations factor in IT security tools as assets.

It’s evident from the data that organizations are more focused on the overall cybersecurity stance, as well as the security policies, process, and culture establish rather than the kind and type of security solutions in place.

It’s good to see Security Awareness Training mentioned, as it has the unique potential to stop attacks where all other solutions fail; eventually a malware-laden email, attachment, or webpage is going to reach your users – it’s only Security Awareness Training that can educate the user to both spot the potential threat and reduce the risk of attack by not engaging with it.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.