A cybersecurity due diligence checklist usually starts with posture, which is what the target can most easily present well, and reaches history late, which is what actually changes a price. An incident that happened is a fact with consequences: notification obligations, possible claims and a remediation cost somebody has to carry. A policy document is an intention. This page puts them in the order that reflects what matters.
History: what has actually happened
Known incidents, near misses, ransomware attempts, credential leaks and anything that triggered a notification. This is the area a target is least likely to volunteer and most likely to have. It is also the one with consequences that survive the transaction, which is what makes it a price conversation rather than a remediation plan.
Data: what is held, where, and under what commitments
Personal data, payment data, health data and anything held for customers under contract. The obligations attach to the data rather than to the company, so the buyer inherits them. In a regulated sector this can become a closing condition rather than an indemnity.
Posture: the basics, tested rather than described
Multi-factor authentication, backups that have been restored from, patching, access reviews and who has administrator rights. Asking for evidence rather than a policy is the whole difference: a policy says what should happen and a screenshot of the access review says what did.
Third parties, which is where most incidents come from
Suppliers with access, integrations with credentials, and anybody who can reach production. This is the most common route in and the least examined area of most diligence, because it requires a list the target has usually never assembled.
Questions people ask about cybersecurity due diligence checklist
What should be asked first?
Incident history. It has consequences that survive the deal, which makes it a price conversation, while posture is an intention.
Why does data matter more than systems?
Because the obligations attach to the data rather than to the company, so the buyer inherits them whatever the systems look like.
What is most often skipped?
Third parties with access. It is the most common route in and it needs a list the target has usually never assembled.