Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogManaged IT

IT Due Diligence: What to Check Before You Buy a Business

Two empty server racks with coiled cables and stacked moving boxes in a vacated office, illustrating IT due diligence before a business acquisition

When you buy a company, you buy its network. That includes the servers nobody has patched since 2019, the shared admin password four ex-employees still know, and any breach already sitting quietly inside it.

Financial and legal due diligence are standard. IT due diligence usually isn't, and that's where the expensive surprises live.

The short version:

  • IT due diligence is a pre-close technical review that finds liabilities and integration costs before the price is fixed.
  • The three findings that most often move a deal are unlicensed software, unsupported systems, and a breach the seller never disclosed.
  • Start it the day you sign a letter of intent, not the week before closing.
  • Across the reviews we run, a sub-100-seat target takes one to two weeks — a rounding error against the purchase price.

Why does this matter? Ask Marriott.

Marriott acquired Starwood in September 2016. According to the UK regulator's penalty notice, an attacker had installed a web shell on the Starwood network on July 29, 2014 — more than two years before the deal closed.

Nobody caught it until an alert fired on September 8, 2018. Marriott disclosed that November, first estimating up to approximately 500 million guests affected. The figure was later revised to an estimated 339 million guest records.

The UK's data protection regulator fined Marriott £18.4 million, roughly $24 million at the time.

Marriott didn't cause that breach. It bought it.

What does IT due diligence actually cover?

IT due diligence is a pre-close review of the target company's technology, security, contracts, and licensing to find liabilities and integration costs before the price is fixed. It answers three questions: what do they actually own, what's already broken or compromised, and what will it cost to fold it into your business?

You're looking at:

  • Assets. Every server, firewall, laptop, and phone. Age, warranty status, and whether the operating system still gets security updates.
  • Identity. Who has admin rights. Whether MFA is on everywhere. How many accounts belong to people who left.
  • Security posture. Endpoint protection, patching cadence, backups someone has actually restored from, and any incident history.
  • Contracts and licensing. Software the seller is running but not licensed for. Auto-renewing MSP and telecom agreements with painful termination clauses.
  • Data. What regulated data they hold, where it lives, and who can reach it.
  • Key-person risk. Whether one person is the only one who knows how anything works.

Why IT due diligence gets skipped

Time, mostly. In a Forescout survey of 2,779 IT and business decision makers, only 36% strongly agreed their IT team got adequate time to review a target's cybersecurity standards. The same study found 53% had hit a cybersecurity issue during a deal serious enough to jeopardize it.

The other reason is that IT feels like a post-close problem. It isn't.

A survey of 250 M&A professionals published in 2019 by (ISC)² found 57% had seen an acquirer surprised by an unreported data breach. Nearly half — 49% — had watched a deal collapse because of it. Notably for smaller buyers, 47% of those respondents worked at companies with 250 employees or fewer.

Both are vendor and trade-body surveys, and both are dated now. The underlying incentive isn't — sellers still don't volunteer breach history.

What should you ask for before you sign?

Put these in the document request. A seller who can't produce them is telling you something.

  1. A current asset inventory: servers, endpoints, network gear, with OS versions.
  2. A list of every admin account and who holds it.
  3. Microsoft 365 or Google Workspace tenant details — license counts, MFA coverage, conditional access policies.
  4. Backup configuration and the date of the last successful test restore.
  5. Every software and SaaS contract, with renewal and termination terms.
  6. The current MSP or IT vendor agreement, including notice period.
  7. Any cyber insurance policy and the application they filled out. The application is often more revealing than the policy.
  8. A written statement of any known security incident in the last three years.
  9. Cabling, ISP, and phone contracts tied to the physical location.

Then verify a sample of it independently. A security assessment run against the seller's environment, with their permission, finds what the questionnaire misses.

The five red flags that should change your price

Five findings belong in the negotiation, not in your first-week to-do list:

  • Unlicensed software. A direct liability. A vendor audit after close lands on you, not the seller.
  • Unsupported operating systems. A hardware refresh you haven't budgeted for, due immediately.
  • No MFA on email at a business that wires money. Assume you're inheriting an active business email compromise until you've proven otherwise.
  • Backups nobody has restored from. Those aren't backups. They're a folder.
  • An MSP contract with a twelve-month notice period. You'll pay two providers for a year.

Price these. Don't absorb them.

Your first 30 days after closing

Assume the seller's credentials are compromised until proven otherwise, and work in this order:

  • Reset every administrative credential and revoke the departing owner's access on day one.
  • Enforce MFA across the acquired tenant before you connect anything to yours.
  • Inventory what's actually on the network, not what the spreadsheet said. Forescout found 53% of IT decision makers discovered unaccounted devices after integration was complete.
  • Get endpoint detection onto every machine you just acquired.
  • Keep the two networks separate until you've done all of the above.

Rushing the connection is how one company's problem becomes both companies' problem.

Only then start the real integration work — email, file shares, identity. Our guide to what drives Microsoft 365 migration cost covers the tenant-to-tenant piece.

Who should run IT due diligence?

Not your deal attorney, and not the seller's IT person. You want an independent technical read from someone who'll still be there to fix what they find.

For most small acquisitions that's a virtual CIO engagement scoped to the deal: a week or two of review, a written findings memo, and a cost estimate for remediation and integration. The NetSys Group runs these for buyers across New York, New Jersey, Connecticut, Pennsylvania, and Southwest Florida.

Set against a purchase price, it's a rounding error. Set against inheriting someone else's breach, it's the cheapest line item in the deal.

Frequently asked questions

How long does IT due diligence take?

One to two weeks for a company under 100 employees, in our experience, from document request to findings memo and assuming the seller cooperates. Scanning and interviews take a few days. Waiting on the seller to produce contracts and inventories is what usually stretches it.

Can we do IT due diligence without alerting the seller's staff?

Partly. Document review, contract review, and external footprint checks are quiet. Anything touching the network needs written permission and one person on the seller's side who knows it's happening — which is how most sellers prefer to handle it anyway.

What if the seller refuses to share IT details?

Treat refusal as a finding. If they won't confirm whether MFA is enabled or whether they've had an incident, price the deal as though the answers are bad, or push the risk into representations and warranties with a holdback. Silence on security questions is rarely good news.

Does the seller's cyber insurance transfer to us?

Usually not in a way that helps. Most policies are claims-made and tied to the named insured, and a change of control often ends coverage for anything after close. Assume you need your own policy in force on day one.

Do we need this for an asset purchase rather than a stock purchase?

Yes, though the liability picture differs. In an asset deal you can leave some contracts and legal exposure behind. You still inherit the hardware, the data, the licensing questions, and any malware sitting on the machines you bought.

Get the review scoped

If you have a deal in progress, or one you're considering, we'll scope an IT and security review against the target and give you a written findings memo you can take into the negotiation. Get in touch for a free risk assessment.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.