The most expensive line item in your last acquisition is the one that was never on the term sheet.
Financial due diligence checks every material line. Cyber due diligence, in most Australian mid-market deals, closes at a folder marked โIT is handling it.โ The gap between those two disciplines is where valuation quietly moves at settlement.
๐ช๐ต๐ฒ๐ฟ๐ฒ ๐๐ต๐ฒ ๐๐ฎ๐น๐๐ฒ ๐๐ต๐ถ๐ณ๐๐
A mid-sized Australian professional services firm we work with completed an acquisition twelve months ago. The financial numbers were clean. The synergy case was solid. Six months after settlement, the buyer’s IT team discovered that the acquired business had five unpatched systems facing the internet, dormant staff accounts still active from the last leadership change, and no documented incident response plan. The remediation cost sat at approximately 4% of the original deal value. None of that had been priced. That is a structural gap in how most M&A due diligence is set up.
๐ช๐ต๐ฎ๐ ๐ฐ๐๐ฏ๐ฒ๐ฟ ๐ฑ๐๐ฒ ๐ฑ๐ถ๐น๐ถ๐ด๐ฒ๐ป๐ฐ๐ฒ ๐ฎ๐ฐ๐๐๐ฎ๐น๐น๐ ๐ป๐ฒ๐ฒ๐ฑ๐ ๐๐ผ ๐ถ๐ป๐ฐ๐น๐๐ฑ๐ฒ
Cyber due diligence that protects deal value asks five questions in writing before the price is agreed. A current Essential Eight maturity assessment, or equivalent framework mapping. A complete list of the target’s material service providers, and evidence of their security posture. Any past cyber incidents in the preceding 24 months, and what changed as a result. Documented and current incident response, business continuity, and disaster recovery plans, with evidence of last testing. Any current regulatory obligations the target is behind on, including Privacy Act, Cyber Security Act 2024, and SOCI Act obligations as applicable. A data room that can answer all five prices the risk correctly. One that can’t means the risk has moved from seller to buyer without anyone adjusting for it.
๐ช๐ต๐ฎ๐ ๐ฟ๐ฒ๐ด๐๐น๐ฎ๐๐ผ๐ฟ๐ ๐ต๐ฎ๐๐ฒ ๐๐ถ๐ด๐ป๐ฎ๐น๐น๐ฒ๐ฑ
ASIC has been increasingly clear that cyber failures sit inside directors’ obligations. The Federal Court’s decision in ASIC v RI Advice [2022] FCA 496 established that AFSL holders can breach Section 912A of the Corporations Act through inadequate cyber controls. ASIC commenced parallel proceedings against FIIG Securities in March 2025 on similar grounds. The Federal Court’s $5.8 million penalty against Australian Clinical Labs in October 2025 was the first civil penalty under the Privacy Act, and the Court examined whether ACL had documented and evidenced its organisational controls. IBM’s 2025 Cost of a Data Breach Report priced the average supply chain compromise at $4.91 million, with a 267-day identification and containment cycle. That is a full year of value drag on a business you already own.
A business acquired with that evidence in the data room prices its cyber risk into the deal. A business acquired without it inherits the same risk at settlement, priced or not. We build that five-question check into due diligence engagements, ahead of signing.
The Cyber Line Item That Never Makes the Term Sheet

Kiran Kewalramani
Kiran Kewalramani stands as an acclaimed technologist with over two decades of robust executive experience in technology, cybersecurity, data privacy and cloud solution enablement. His illustrious career has been marked by transformative roles in esteemed organizations, including Cyber Ethos, Queensland Department of Education, Gladstone Area Water Board, NSW Rural Fire Service, NSW Police Force, Telstra, American Express, and more.