The Rook
Most security podcasts are built for practitioners. The Rook is built for the people who have to make decisions about security without being security experts.
Hosted by David Shaw — CISSP, fractional vCISO, and GRC consultant with 20 years in the seat — The Rook delivers board-ready intelligence for founders, PE operating partners, M&A attorneys, and executives who own security risk when security isn’t their day job.
Every episode covers one topic in depth with examples from a real incident, a regulatory development, a threat pattern, or a market shift. No vendor hype. No practitioner jargon. Just what it means for the business you're running or the deal you're working on — and what to do about it.
New episodes every other Tuesday.
The Rook
The Deal You Didn’t Know You Made: Cyber Risk in M&A
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode of The Rook, David Shaw, founder of Corvus Cybersecurity and principal vCISO, examines the most consistently overlooked risk in M&A transactions: inherited cyber exposure. From Yahoo's misrepresentation of its breach history during the Verizon acquisition to the Marriott-Starwood breach that went undetected for four years, the pattern is the same. Cybersecurity due diligence gets a questionnaire, while financial and legal diligence get exhaustive scrutiny. The result is that acquirers close deals and inherit compromised environments, undisclosed incidents, and compliance gaps that carry real remediation costs.
In this episode:
- How Yahoo's misrepresentations to Verizon held through signing, and what saved Verizon wasn't diligence
- How Marriott bought a four-year-old, undetected breach when it acquired Starwood
- Why the standard M&A cybersecurity questionnaire fails to catch material risk
- How R&W insurance carve-outs and cyber insurance pre-existing condition exclusions are changing the stakes for deal teams
- The four-stage cyber due diligence process used on the buy side, and the three-bucket model for translating findings into deal team decisions
- What sellers should be doing now to protect deal value
- Three artifacts every buyer should require, not just three questions to ask
The Rook · Corvus Cybersecurity · corvus-cyber.com · David Shaw, CISSP, GLEG
July, 2016, Verizon signs a $4.83 billion agreement to acquire Yahoo. In that purchase agreement, Yahoo makes a formal representation. They state in writing that there have been no significant data breaches. That was a lie, and Yahoo knew it was a lie. They'd known for nearly two years, 500 million user accounts were compromised. A state sponsored actor was sitting in their systems. They knew and they signed the rep anyway. Two months after signing Yahoo was forced to publicly disclose the breach. Three months after that, a second breach came out, another billion accounts. By the time the deal closed, Verizon and clawed back $350 million and pushed half the breach related legal liability back on Yahoo. The SEC later charged Yahoo with securities fraud over the delayed disclosure, and they paid a $35 million settlement. Now, here's the part that most people miss. Verizon didn't catch this in the due diligence. Their diligence missed it. The misrepresentation held all the way through. Signing what saved Verizon was a public disclosure that Yahoo was eventually forced to make. If that disclosure hadn't happened, Verizon closes at full price. They inherit the breach and they don't even know it. And this is a pattern that plays out in m and a deals all the time. Most don't make the headlines and most don't have an company like Yahoo involved, but most also don't get a forced disclosure that saves the buyer from themselves. You see, that's the deal you didn't know you made. I'm David Shaw. Welcome to the Rook. This show is for the people who own security risk. When security isn't their day job. It's the company founders, it's the investors, the executives, the boards. If that's you, you're in the right place. You'll get no product pitches here, no jargon that you have to translate. Just intelligence. You can use that same day. Whether you ever pick up the phone or not. So let's get into it. In September, 2016, Marriott had just completed its acquisition of Starwood Hotels and Resorts. It was a $13 billion deal, and it made Marriott the largest hotel company in the world. They had 11 new brands. Over 5,500 properties and unknown to anybody in the deal room. Chinese State sponsored attackers who'd been sitting inside Starwood's guest reservation system since 2014. That's two years before the acquisition. The attackers were already inside Marriott. Didn't find them at close, didn't find them six months later. They found them in September, 2018. Two years after the deal closed by then, the attackers had exfiltrated data on 383 million guests, including over 5 million unencrypted passport numbers. The financial damage, 18.4 million pounds in UK fines alone, $52 million to a coalition of US state attorneys General. They had an FTC consent order requiring a mandated security overhaul that Marriott is still operating under. Class action. Litigation is still ongoing, and that's all before you count the brand damage or the internal cost of a decade of remediation. But here's what makes this story so uncomfortable for acquirers, or it should. Starwood was a sophisticated company. Marriott was a sophisticated acquirer. The standard pre-acquisition cyber assessment didn't catch a state-sponsored compromise that had been sitting in Starwoods network for over two years. The attacker stayed in the deal closed, and Marriott inherited the breach. Now let's think about that for a minute. If Marriott can miss a 2-year-old state-sponsored compromise on a $13 billion deal, what do you think is happening on the $40 million deal your firm is closing next quarter where the diligence is a questionnaire? The IT manager fills out the questionnaire and everybody signs off. But here's the thing about questionnaires. They generally ask the right questions. Do you test your backups? Do you have an off-boarding process? Have you had any incidents in the past three years? Those questions are fine. The problem isn't what gets asked. It's what gets accepted as the answer. It's very easy for somebody to check off. Yes, we test our backups quarterly. Well, great. Did the test actually run? Did it recover systems to a working state or did it just verify that the files exist? Who ran the test? Can they show you the report or, yes, we have an offboarding process. Did anyone follow it? Can you produce a list of every employee who left in the last 24 months and confirm that they didn't retain any of their access after they left the organization, or no? We haven't had any incidents. What about incidents that may not have been raised to the level of material or publicly reported? And are you sure you'd know if you did have an incident? You see questionnaires create documentation, but it can't create assurance. The IT manager filling it out has every incentive to check the boxes, but your diligence has to verify what's behind the boxes. Now, three things have changed. That make this a more expensive problem to ignore than it was even two years ago. First representations in warranties insurance, which is now standard in middle market deals, is increasingly carving out cyber related claims, or at least conditioning coverage on proof that reasonable diligence was performed in plain English. If you skip the cyber assessment and there's a breach post-close, your r and w policy may not respond. Second, cyber insurance underwriters are not writing blank checks for inherited risk policies now routinely include preexisting condition exclusions. If the breach originated before the policy inception date, you may be entirely on your own for remediation, for notification costs, regulatory response for litigation, and in a Marriott Starwood scenario. That breach originated four years before the policy. And third, a 2026 industry study found that 84% of m and a professionals anticipate increased cybersecurity scrutiny in due diligence over the next 12 to 24 months. Now, that's not a fringe view, that's consensus, and it's filtering down to the middle market. You know the big four consultancies have built dedicated cyber transaction practices. The cybersecurity due diligence market itself is growing toward $8 billion a year. R&W underwriters are pricing cyber risk into every policy. But here's the gap. By at least one industry estimate only about 10% of m and a deals get a thorough cyber due diligence assessment. 10%. Now, most of the price adjustments and renegotiated structures from cyber findings won't make the headlines. They'll happen in confidential rooms, but the deal your firm is closing next quarter is going to face questions that didn't exist three years ago. So if you're a buyer, the question is whether you're doing the work. If you're a seller, the question is whether you can prove you already did. The cost of a thorough pre-deal cyber assessment is a fraction of what a single inherited breach demands in terms of remediation, legal exposure, reputational repair, and the market has arrived at a clear position. Cyber risk is a valuation driver. Not a compliance footnote. So if the questionnaire isn't enough, what is, well, let me walk you through what cyber diligence looks like When it's done right. I'll give it to you in the order The work happens because timing matters. Now this isn't a checklist you hand someone at signing. It's a four stage process that runs alongside the deal. From the first conversation through close stage one, this happens before you even signed a letter of intent. It's called passive reconnaissance. No credentials, no system access, no NDAs required. It's all open source. You're just looking at the targets. External attack service, the way an attacker would. What servers are exposed to the internet? What software versions are they running? Have their domains shown up in known breach data sets? Are there old credentials floating around on the dark web markets? This takes a few hours and costs almost nothing, and it tells you one critical thing before you commit. Is cybersecurity going to be a normal diligence work stream here, or is it a deal stopper conversation? Now I've seen pre LOI passive reconnaissance surface a target with active ransomware infrastructure indicators on day one. That's not a deal you want to touch without renegotiating the structure. You wanna know that before you've spent $200,000 on legal and financial diligence, not after. Now stage two starts after the LOI. So this is after you have the NDAs and the data room access. This is the technical assessment, and it runs on two tracks simultaneously. The technical track is the one most people think about. It's the endpoint security, identity and access management, patching, cadence, network segmentation, backup integrity, incident history. But the question isn't, do they have tools deployed? The question is, are the tools working? And does anyone check? You know, I've walked into environments with every best in class security product installed, and all of them are either unconfigured or generating alerts that nobody reads. So checkbox security is not security. The governance track runs in parallel and it asks a different question. Does the company actually operate like a security program exists? Do they have written security policies that reflect actually what people do? Do they run annual training? Have they ever tested their incident response plans? Not, do you have a plan, but have you ever run a tabletop exercise and watched your team try to execute it? The answers here are all diagnostic. A company with mediocre tools and a strong security culture will recover much faster from an incident than a company with expensive tools and no culture. Stage three is compliance and regulatory mapping. Now this is critical for regulated targets, healthcare, financial services, government, contractors, media companies, handling production IP. You need to know where they actually stand, not where the marketing materials say they stand. Are they PCI compliant? If they take cards, if they hold PHI, are their business associate agreements current and signed? If they're a government contractor, where are they on the CMMC path and is the timeline credible? Compliance gaps are some of the most material findings in cyber diligence because they translate directly into known remediation costs and known regulatory timelines. Those are numbers your deal team actually can use, which brings me to stage four, and this is the one most cyber consultants skip because it requires speaking M&A language instead of security language. Every finding has to be translated into one of three buckets, bucket one, deal stopper, something so material that the transaction either needs to be renegotiated or walked away from. Things like an active compromise, ongoing litigation from a prior breach, regulatory sanctions and progress bucket. Two value adjustment, a quantifiable remediation cost that should come out of the purchase price, or at least be held in escrow, or maybe even be addressable by specific reps and warranties. Bucket. Three known risks. Now, these are the ones that are managed post-close. It's an issue that's real, but not deal threatening. It has to have a documented 100 day plan and an owner assigned to it before the close. That's three buckets. That's the output Investment Committees need, not a 40 page technical report. Three buckets, dollars attached decisions required. If your cyber diligence provider isn't giving you that, if they're not translating their findings into deal team language, you are not getting diligence. You're getting an expensive technical audit. Now, if you're on the sell side, because half of you listening are founders or executives who might be the target in the next two to four years, the single most valuable thing you can do right now is get audit ready before anyone asks. Not because a deal is imminent, but because a documented defensible security posture is a value preservation tool. When a buyer shows up and you can produce a current SOC two report, a recent penetration test with remediation status and a documented incident response plan, you've actually tested along with a clean identity environment and MFA everywhere. No orphan accounts. You've just compressed your diligence timeline by weeks and removed half of the common reasons for purchase price adjustment. The specifics, if you're a SaaS business or you handle client data, get your SOC two completed. If you haven't done a penetration test in the last 12 months, do one and more importantly, resolve the critical findings. Document your incident response plan and run a tabletop exercise against it, even if the exercise is just you and two other people in a conference room for an hour. Clean up your identity environment. Remove accounts for people who have left enforce MFA across every system that supports it, and document who holds privilege access, and why. Now, none of this is expensive. Most of it you can do with the team you already have. And all of it reduce, reduces your operational risk today, whether a transaction ever happens or not. So when a transaction does happen, it shifts the dynamic at the negotiation table from defense to confidence. Those are not small things when you're sitting across from a buyer. Negotiating final terms. Okay. Before I close out today, I wanna leave you with something that you can use. I just spent two segments telling you the problem with m and a cyber diligence isn't the questions, it's what gets accepted as the answer. So let me give you the practical version of that. Here's three things that you should require from the target. Not questions to ask them, but three things they have to produce. So number one, a documented log of every cybersecurity event the company has evaluated in the past three years. Not material events. Every event the company looked at and made a call on, including the ones they decided weren't material. Now that log may not exist for most middle market targets, and that in itself is the answer. But if the company doesn't have a process for tracking incidents, that means they don't know what they've had. If they do produce a log, you've at least got somewhere to start. Look at the events they decided weren't material. That's where the buried problems live now. Number two, you want a current inventory of every third party with privileged access to production systems or core data with a date showing when the inventory was last validated. Again, this inventory often doesn't exist as a current document. They have a list somewhere. It's in a SharePoint folder that someone updated maybe 14 months ago when they did their last vendor review. A stale inventory is not the same as an inventory. If they can't tell you who has access today with confidence, that's an inherited risk you are about to own. And number three. The last two years of penetration test reports plus a remediation tracker showing the current status of every critical and high finding from those reports. Notice what this is asking for, not whether they did a pen test the reports themselves, plus the tracker that shows what they did about the findings. If they hand you the reports and there's no tracker, the answer is they didn't fix anything. If they hand you the tracker and the criticals from 18 months ago are still open, well, you just found a material risk that no rep would've surfaced. Three artifacts, not three questions, three artifacts are the evidence. The questions are just a way to ask for that evidence. If the target can produce all three cleanly, you're working with a serious counterparty. If they can't, you've just learned something that a questionnaire would never have told you. Well, that's episode one of the book. If you take one thing from this episode, take this. Cyber risk doesn't reset at closing, it just transfers to a new owner. If this episode was useful, the most valuable thing you can do is send it to one person on the deal team who needs to hear it. That's how this show grows, and that's how this work reaches the people. It's meant for. If you're working on a deal right now and you want an independent view of the target security posture, or you're a founder who wants to get ahead of the diligence conversation before a buyer shows up, you can reach me at corvus-cyber.com. We drop new episodes every Tuesday. I'm David Shaw, this is the Rook. And now it's your move.