Most cyber diligence still starts after exclusivity, when the only thing left to do with a finding is negotiate an indemnity. The more useful moment to look is earlier, when a finding can still change which targets stay on the shortlist.
What cyber information should be known before an IOI or LOI
Not a full technical audit. Before a letter of intent, the useful questions are structural: how concentrated is the target dependency on a small number of third party platforms, what does its public facing attack surface actually look like from outside, and are there any already public signals, breach disclosures, regulatory actions, exposed credentials, that a buyer would rather know about now than discover during confirmatory diligence.
How much diligence is enough before exclusivity
Enough to rank a shortlist, not enough to sign off on a number. Verizon own 2025 Data Breach Investigations Report found that third party involvement in breaches doubled from 15 percent to 30 percent year over year, the largest single year jump the report has tracked in eighteen years. That is a strong argument for screening every name on a shortlist for third party concentration before exclusivity, since a target whose dependency chain that already looks fragile is a different conversation than one whose diligence simply has not started yet.
Which cyber weaknesses can materially affect valuation
Not every finding belongs in a valuation conversation. The ones that do tend to share a shape: they point to a loss that would recur, not a one time remediation cost, and they touch a process the deal thesis actually depends on. A control gap that raises the annual expected loss on a revenue critical system changes the number differently than a gap in a system nobody in the deal model was counting on.
When a control weakness becomes a transaction risk
Roughly, when it changes either the cash the business needs to remediate it or the plausible severity of a loss event the buyer is underwriting into the price. A weakness that is expensive to fix but bounded in impact is a negotiating point. A weakness that sits under a business critical process and has no clear ceiling on downside is a different category of question for an investment committee.
What an investment committee actually needs
A number with a range attached to it, not a severity label. IBM own 2025 Cost of a Data Breach report puts supply chain compromise as the second most frequent initial attack vector and the second most costly, and notes it takes longer to contain than the average incident. An investment committee weighing a deal against that backdrop needs an exposure figure calibrated to a realistic and a severe case, not a red amber green rating that cannot be compared against the rest of the deal model.
Which evidence gaps should trigger deeper diligence
The honest answer is not every gap, since some information is genuinely unavailable before a target grants access. The gaps worth escalating are the ones tied to a process the deal thesis depends on: an unclear picture of who holds the keys to a revenue critical system, or a third party dependency nobody on the target side can fully describe. Those are the gaps that change the decision, not just the paperwork.
