A cyber finding rarely kills a deal, it can and does, however what it does far more often, is move it: from a line in a due diligence report to a redline in the SPA. Deal teams that have been through a handful of processes know the pattern. A vulnerability scan turns up unpatched perimeter infrastructure, a governance review finds no board-level oversight of security, or a dark web sweep surfaces credentials, possible IP (intellectual Property) loss that should never have been exposed. Individually it is unlikely a few findings will stop the transaction. It changes the terms of it.
For deal teams and portfolio company management preparing for a sale, or for GPs weighing an acquisition, the useful question isn't "will cyber diligence find something." At current levels of buyer sophistication, it almost always does. The useful question is which of three mechanisms that finding will trigger, because each one has a different cost, a different negotiation dynamic, and a different amount of time it takes to resolve.
Price reduction: the direct route
The simplest response to a cyber finding is arithmetic. A buyer's technical advisers cost out what it will take to remediate what they've found, unpatched systems, missing multi-factor authentication, an absent or unmanaged EDR deployment, a supplier dependency with no contractual security obligations, and that figure comes straight off the purchase price (frequently with a premium attached). It is treated the same way a buyer treats a deferred maintenance liability on a piece of physical infrastructure: a known cost to be incurred post-completion, deducted now.
This is the category most sellers expect, and it's also the one where a vendor with clean, evidenced diligence has the most control. A remediation cost that has already been quantified and actioned by the seller isn't a live deduction; it's a closed item. Where sellers lose ground is when the finding is discovered by the buyer's side rather than disclosed proactively; the price adjustment tends to be larger, because the buyer prices in the uncertainty of not knowing what else wasn't found, not just the cost of the fix itself.
Governance findings behave slightly differently. A missing incident response plan or no evidence of board-level cyber oversight isn't a line item a buyer can cost directly, but it reads as a proxy for how well the whole business has been run. That soft signal tends to show up as pressure on the multiple rather than a specific deduction, which makes it harder to negotiate against because there's no single number to contest. Such soft signals often act in cumulative manner, they have a multiplying affect and will support other DD category findings to shift a maturity narrative within an organisation.
Warranty structuring: managing what can't be fixed before completion
Not every finding can be remediated on a deal timetable. A penetration test remediation programme that needs six months doesn't compress to fit a four-week exclusivity period, and a buyer isn't going to walk away from an otherwise attractive asset because of it. What happens instead is that the risk moves from the price into the warranty and indemnity package.
This is where the specific language matters. General warranties, no material breach in the past twelve months, compliance with data protection obligations, adequate security measures in place, are usually covered by a buyer's warranty and indemnity insurance if one is in place. A known, disclosed cyber finding is a different matter. Insurers exclude known issues from cover as standard, which means a specific indemnity has to be negotiated directly between buyer and seller: a defined sum, tied to a defined risk, sitting outside the insurance layer and often secured against an escrow retention or deferred consideration.
For a seller, this is a meaningfully worse outcome than a straightforward price cut. A price reduction is finite and known at completion. A specific indemnity is contingent, it can sit on the fund's balance sheet for months or years after exit, and it requires someone to keep track of whether the underlying risk has actually crystallised. Sellers who arrive at diligence with an unresolved cyber finding aren't just negotiating over money, they're negotiating over how long the deal stays open after signing.
Timeline extension: when findings cost time as well as money
The third mechanism is the one deal teams tend to underweight, because it doesn't show up as a number in the SPA. A cyber finding late in a process, particularly one the vendor didn't disclose, forces the buyer's advisers to go back and ask what else the existing diligence workstreams might have missed. That usually means a confirmatory review, a re-run penetration test, or additional legal analysis of regulatory exposure, none of which fits inside an already-agreed exclusivity window.
Timeline extension is expensive in ways that don't always get costed separately. Extended exclusivity means extended legal and advisory fees on both sides. Financing commitments that were priced to a specific completion date may need to be re-papered. Competing bidders, if there were any, get a longer window to be tempted back in. And a deal that has visibly lost momentum tends to lose negotiating leverage along with it, the vendor is now working against a clock, and buyers know it.
The structural fix is well understood but inconsistently applied: cyber diligence needs to run in parallel with financial, legal and commercial workstreams from the start of a process, not as a check performed in the final weeks before signing. A finding surfaced early is a negotiating point. The same finding surfaced late is a condition precedent, a delayed completion date, or a deal that quietly falls away while everyone waits for a retest that should have happened months earlier.
The common thread
Price, warranty and timeline aren't three separate risks. They're three ways the same underlying finding gets priced once a buyer has visibility into it, and which one applies is largely determined by when the finding surfaces and how well evidenced the response is. A vendor that has been continuously monitoring its cyber posture through the hold period, rather than assembling a picture of it under diligence pressure, controls which of these three outcomes it's negotiating from. That is the difference between a red flag that costs a few points on the multiple and one that reshapes the entire SPA.
Each of these three mechanisms traces back to a specific point in the deal lifecycle where the finding could have been addressed instead of negotiated. Our Private Equity Cyber Risk Checklist sets out exactly where: deal-stage due diligence run in parallel with financial and legal workstreams, while pricing leverage still sits with the seller, and an exit-readiness review that defines warranty and covenant responsibility before a buyer's advisers define it for you. Thomas Murray works with private equity deal and value creation teams across the full lifecycle, from pre-deal monitoring through to exit, to help portfolio companies close these gaps before they show up in a redline. Download the checklist, or speak to one of our experts, to see where your current process is still leaving pricing leverage on the table.

Private Equity Cyber Risk Checklist
Our PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness. Work through it and know exactly where your gaps are.
- 10 steps across five phases - deal, first 100 days, portfolio ownership, ESG, and exit.
- Self-assessment at every step - rate your current position and walk away with a clear gap count.
- Written for fund leadership, No jargon. Financial language throughout.
Insights

From Red Flag to Redline: How Cyber Findings Actually Change Deal Terms
A cyber finding rarely kills a deal, it can and does, however what it does far more often, is move it: from a line in a due diligence report to a redline in the SPA.

Why Summer is a Blind Spot in Private Equity Risk Oversight
Threat levels don't take annual leave. Why PE firms need continuous cyber oversight of portfolio companies, not seasonal assessment.

Private Equity Cyber Risk Checklist
The PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness.

Why Private Equity Has Underinvested in Asset Safety, and Why the Window Is Closing
Half of PE portfolio companies carry elevated cybersecurity risk. Here's why asset safety has been underinvested, and why that's changing fast.

