Clarify the document base first.
Structure the data-room evidence and open questions. Only then should the point be translated into price, warranty or condition precedent.
Cybersecurity due diligence in acquisitions: review NIS2 exposure, incidents, IT contracts, insurance and warranties before signing.
BRANDAUER Rechtsanwälte
Salzburg law firm for corporate, company and transaction law
Every transaction is handled by a coordinated team of lawyers, legal staff and specialists. In company acquisition matters we look at structure, contract, tax and liability together.
Cybersecurity due diligence is not merely a technical workstream. Unresolved security incidents, missing incident documentation or unclear NIS2 exposure can affect price, warranties and the closing plan. Buyers should understand before signing which systems are business-critical and whether personal data breaches under Articles 33 and 34 GDPR were handled properly. This article complements our pieces on data protection due diligence and IP and IT contracts.
Answer two questions on the specific finding.
Already know you want to get in touch? Go straight to the enquiry form.
The first finding determines whether documentation is enough or contract mechanics are needed.
Structure the data-room evidence and open questions. Only then should the point be translated into price, warranty or condition precedent.
If documents and contract align, the finding can be carried into negotiations, the signing list and the closing plan.
Generic wording is not enough. The contract should state which documents matter, who bears risk and which action is expected before closing.
The data room should include a system map, provider overview, access roles, backup concept, incident log, information security policies and material cloud contracts. Without these documents the buyer cannot reliably assess continuity or liability risks.
For targets with critical or important services, parties should also review whether NIS2 obligations or sector-specific security requirements may become relevant. Directive (EU) 2022/2555 is a regulatory framework, not an automatic defect of every company.
Data breaches are not only a privacy topic. Articles 33 and 34 GDPR concern notification, communication and documentation. In a transaction it matters whether incidents were detected, assessed and remediated.
Open vulnerabilities, unclear deletion concepts or missing processor lists can lead to warranties, indemnities or closing conditions. For digital business models, also review our guide to buying a software or SaaS business.
The SPA should not merely state that IT systems work. Specific warranties on known incidents, material contracts, security software rights, cyber insurance and technical measures are more useful.
If a finding can be fixed before closing, a condition precedent or closing deliverable may fit. If the risk remains open, price adjustment, holdback or indemnity should be considered. Existing insurance policies should also be reviewed.
The overview shows typical review points and contractual effects.
| Point | Why it matters | Contract effect |
|---|---|---|
| Systems Systems | Identifies critical applications and dependencies | Data-room schedule or closing deliverable |
| Incidents Incidents | Breaches and outages show liability risks | Warranty, disclosure or indemnity |
| Regulation Regulation | NIS2 and CRA may trigger post-closing cost | Cost clause or condition precedent |
| Insurance Insurance | Coverage gaps influence risk allocation | Review policy and continuation |
The contract, data room and economic relevance in the individual case are decisive.
Practical note: Cybersecurity should not be requested only at the end of due diligence. Early structure helps translate technical findings into warranties and the closing list.
No. Industry, size and activity are decisive. Still, NIS2 can be a useful review framework because buyers need to understand security organisation and incident processes.
They may trigger notification issues, authority correspondence, customer concerns and reputational risk. They belong in the data room, disclosure and contract negotiation.
No. Technical findings must be translated into legal mechanisms such as warranties, indemnities, closing deliverables or purchase-price logic.
GDPR, customer data and processing in acquisitions.
Review rights, licences and key IT contracts.
Secure source code, cloud and customer contracts.
Classify policies and coverage gaps in the transaction.
When buying a company, structure, review and contract decide. Call us directly or send an email, callback within one business day.
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg
Phone
+43 662 6280000