Cyber Ethos

The Cyber Line Item That Never Makes the Term Sheet

The most expensive line item in your last acquisition is the one that was never on the term sheet.

Financial due diligence checks every material line. Cyber due diligence, in most Australian mid-market deals, closes at a folder marked “IT is handling it.” The gap between those two disciplines is where valuation quietly moves at settlement.

𝗪𝗵𝗲𝗿𝗲 𝘁𝗵𝗲 𝘃𝗮𝗹𝘂𝗲 𝘀𝗵𝗶𝗳𝘁𝘀

A mid-sized Australian professional services firm we work with completed an acquisition twelve months ago. The financial numbers were clean. The synergy case was solid. Six months after settlement, the buyer’s IT team discovered that the acquired business had five unpatched systems facing the internet, dormant staff accounts still active from the last leadership change, and no documented incident response plan. The remediation cost sat at approximately 4% of the original deal value. None of that had been priced. That is a structural gap in how most M&A due diligence is set up.

𝗪𝗵𝗮𝘁 𝗰𝘆𝗯𝗲𝗿 𝗱𝘂𝗲 𝗱𝗶𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗮𝗰𝘁𝘂𝗮𝗹𝗹𝘆 𝗻𝗲𝗲𝗱𝘀 𝘁𝗼 𝗶𝗻𝗰𝗹𝘂𝗱𝗲

Cyber due diligence that protects deal value asks five questions in writing before the price is agreed. A current Essential Eight maturity assessment, or equivalent framework mapping. A complete list of the target’s material service providers, and evidence of their security posture. Any past cyber incidents in the preceding 24 months, and what changed as a result. Documented and current incident response, business continuity, and disaster recovery plans, with evidence of last testing. Any current regulatory obligations the target is behind on, including Privacy Act, Cyber Security Act 2024, and SOCI Act obligations as applicable. A data room that can answer all five prices the risk correctly. One that can’t means the risk has moved from seller to buyer without anyone adjusting for it.

𝗪𝗵𝗮𝘁 𝗿𝗲𝗴𝘂𝗹𝗮𝘁𝗼𝗿𝘀 𝗵𝗮𝘃𝗲 𝘀𝗶𝗴𝗻𝗮𝗹𝗹𝗲𝗱

ASIC has been increasingly clear that cyber failures sit inside directors’ obligations. The Federal Court’s decision in ASIC v RI Advice [2022] FCA 496 established that AFSL holders can breach Section 912A of the Corporations Act through inadequate cyber controls. ASIC commenced parallel proceedings against FIIG Securities in March 2025 on similar grounds. The Federal Court’s $5.8 million penalty against Australian Clinical Labs in October 2025 was the first civil penalty under the Privacy Act, and the Court examined whether ACL had documented and evidenced its organisational controls. IBM’s 2025 Cost of a Data Breach Report priced the average supply chain compromise at $4.91 million, with a 267-day identification and containment cycle. That is a full year of value drag on a business you already own.

A business acquired with that evidence in the data room prices its cyber risk into the deal. A business acquired without it inherits the same risk at settlement, priced or not. We build that five-question check into due diligence engagements, ahead of signing.

Kiran Kewalramani

Kiran Kewalramani

Kiran Kewalramani stands as an acclaimed technologist with over two decades of robust executive experience in technology, cybersecurity, data privacy and cloud solution enablement. His illustrious career has been marked by transformative roles in esteemed organizations, including Cyber Ethos, Queensland Department of Education, Gladstone Area Water Board, NSW Rural Fire Service, NSW Police Force, Telstra, American Express, and more.