Could a single cyber incident wipe out months of deal value? Owners and directors of small English businesses often miss small security gaps. These gaps can cause lost revenue, regulatory fines or stalled sales during pre-sign valuation.
Small security gaps can cost a business weeks of value.
Quick process summary: 6 steps to run now
Collect verifiable evidence. Quantify likely losses. Run a broker pre-check. Decide negotiation levers. Agree remediation milestones. Decide escrow or W&I cover.
- Request evidence packet (3–7 days).
- Do an expected loss calc (1–3 days).
- Broker pre-check and insurer read (2–7 days).
- Negotiate price or reps/indemnities (3–10 days).
- Agree remediation plan and escrow (7–21 days).
- Post-close verification and insurance placement (7–30 days).
Step 1: evidence gathering and what to ask for
Ask for a concise, dated evidence packet covering the last 24 months. The packet lets buyer, broker and underwriter see what really happened. It avoids reliance on claims alone.
What to request from the seller
Request the incident register and any forensic reports. Ask for backup logs with restore evidence. Ask for pen-test or vulnerability assessment reports and the full current cyber insurance wording. Also ask for a list of systems holding personal data and key third-party contracts.
What counts as reliable proof
Signed forensic reports count as proof. Dated backup logs that show a successful restore also count. PDF pen-test reports signed by the provider meet underwriter standards.
Screenshots or untimestamped notes do not meet underwriter standards.
Legal deadline: supply dated evidence covering the last 24 months, including any ICO correspondence, to allow accurate underwriting review.
Step 2: risk quantification and how findings hit premiums
Translate each control gap into an expected cost. Show how underwriters map those gaps into premium or exclusions. This tells the buyer what to expect from insurers.
How to estimate likely costs
Use three pragmatic cost tiers for initial sizing: Low £5k–£25k, Medium £25k–£150k, High £150k–£750k+. For each finding estimate a credible loss range and an occurrence probability. Calculate expected values and run sensitivity scenarios for best, likely and worst outcomes.
Rather than apply a fixed ×1.5 multiplier, use a situational contingency. Use ×1.2 when documentation is robust. Use ×1.5 when records are partial. Use ×2.0+ when there is no proof or when investigations continue.
Document the assumptions behind probabilities and costs. The buyer then can justify escrow or price adjustment in negotiation.
How underwriters react to common findings
Missing MFA on admin accounts can increase underwriting scrutiny. This often produces a premium uplift or a specific exclusion. The exact range, for example 10–40%, depends on insurer appetite and policy limits.
Lack of tested backups frequently results in capacity restrictions, sub-limits or ransomware exclusions. The premium impact varies widely.
Prior unresolved breaches commonly prompt requests for a forensic review. They may lead to declinature or a retroactive date. Treat published percentage bands as illustrative and obtain a broker read for insurer-specific outcomes.
"The most frequent error at this point is accepting seller statements without documentary proof."
For resource-constrained SMEs, the decisive step is not just listing risks; prioritise remediations by impact versus effort.
A simple two-axis matrix lists items that give the biggest risk reduction per pound and hour spent. For example, enabling multi-factor authentication on admin and remote access accounts is typically high impact and low effort. Effort can be minutes to days and typical cost £0–£1k for licensing or configuration.
Patching exposed internet-facing systems is high impact and low to medium effort. Costs are often £1k–£5k for consultancy or engineering time. A documented restore test of backups is high impact and medium effort. Costs range £2k–£10k depending on environment.
By contrast, full network segmentation or rolling out EDR across endpoints is high impact and high effort. Costs can be £5k–£50k or more. Such items may be scheduled post-close.
SMEs should deliver an ordered list of quick wins into the remediation milestones. Buyers and underwriters expect to see these completed first because they change underwriting stance with modest investment.
A worked numerical model helps turn subjective concern into a negotiation figure. Assume three findings:
- (A) Admin accounts without MFA — likely loss if exploited: £40k; probability 30% → EV £12k.
- (B) No proven backup restore — likely loss: £150k; probability 20% → EV £30k.
- (C) An unresolved minor breach with customer data — likely loss: £75k; probability 15% → EV £11.25k.
Sum EV = £53.25k. Apply a contingency multiplier for uncertainty (use scenario testing rather than a single rule): if documentation is partial use ×1.5 → contingency figure ~£79.9k. Add estimated immediate remediation cost to achieve insurer-acceptable state (e.g. MFA rollout £800; restore test £3,500; basic forensic review £3,700 = £8k). A sensible negotiation position is the contingency figure plus remediation cost ≈ £88k (round to £90k), which can be offered as escrow or price reduction. Separately quantify expected annual premium uplift (e.g. baseline premium £3k pa; 25% uplift = £750 pa) to include recurring insurer cost in valuation discussions.
Step 3: map findings to negotiation levers
Convert quantified exposures into price adjustment requests, escrows, or specific reps and indemnities. The buyer must show figures, not feelings, to make these levers work.
Price reduction and escrow math
If expected value of cyber exposure equals £30k, propose that figure for escrow or price reduction. Then multiply by 1.5 for uncertainty.
Use a tiered escrow release tied to remediation milestones and post-close validation.
Warranties, indemnities and insurance options
Ask for a seller representation covering incidents in the last 24 months backed by documents. Add a specific indemnity for any pre-closing breach that causes regulatory fines or remediation costs. Consider buyer-side W&I for general risks and a specific cyber W&I or bespoke run-off if insurers will not transfer cover.
How findings translate directly into insurer decisions
This section gives a clear mapping buyers can use during negotiations or when briefing a broker. It links concrete controls to likely insurer outcomes.
Mapping examples buyers can use
- Missing MFA on admin accounts: likely 10–40% premium uplift or ransomware exclusion.
- No backups or no restore proof: likely ransomware sub-limit or loss of ransom cover; premium uplift 25–100% if ransom cover remains.
- Prior unresolved breach: likely cover declinature or retroactive date; insurer may require remediation and reassessment before binding.
Case example
A 20-person marketing SME experienced a small ransomware incident; the seller had no evidence of restore. The buyer negotiated a £75k escrow and required the seller to replace backups pre-close. The insurer refused to accept prior acts without a three-month remediation window, pushing completion 21 days later.
A compact before/after SME case illustrates the mechanics.
- A 12-person e-commerce SME disclosed a small ransomware event 18 months earlier but produced no restore evidence.
- Initial broker feedback was: declinature for prior acts unless retroactive date or major remediation, and an indicative premium uplift of c.60%. The buyer required (i) a £60k escrow, (ii) immediate remediation: MFA on admin/remote accounts, daily immutable backups and a full restore test, and (iii) a post-close verification window of 90 days. Remediation cost to the seller was £16.5k and took 18 days.
- Insurer re‑assessed and withdrew the declinature, offering cover with a 15% premium uplift instead of 60%.
Escrow was released in three tranches over 12 months tied to the restore test and absence of new incidents. Lessons: a modest remediation spend and clear milestones reduced insurability friction, cut the premium uplift materially and avoided a stalled completion.
Table: typical insurer responses to common findings
| Finding |
Typical premium uplift |
Likely exclusion or sub‑limit |
Underwriter action / time |
| Missing MFA on admin accounts |
10–40% |
Possible ransomware exclusion |
Request remediation plan, 3–10 days |
| No tested backups / no restore proof |
25–100% |
Ransomware sub‑limit/exclusion |
Possible declinature, 5–14 days |
| Prior unresolved breach |
50–200% or declinature |
Retroactive date or exception |
Forensic review required, 7–21 days |
Deal flow for cyber due diligence
1
Request evidence packet (3–7 days)
2
Compute expected values and contingencies (1–3 days)
3
Broker pre‑check and insurer read (2–7 days)
4
Negotiate price, W&I or escrow (3–10 days)
5
Agree remediation milestones pre/post close (7–21 days)
6
Place final insurance and post‑close verification (7–30 days)
Templates: due diligence questionnaire
Below are templates that can be copied and pasted into an email or contract draft. Each is short and tuned for SMEs with limited IT resources.
DD questionnaire
Please provide dated documents for the last 24 months:
1. Incident register with dates and outcomes
2. Any forensic reports or breach notifications (ICO letters)
3. Full cyber insurance policy wording and claims history
4. Penetration test or vulnerability assessment reports
5. Backup logs and documented restore test evidence
6. List of systems holding personal data and vendor contracts
7. Admin account list and MFA status
Risk matrix
Impact / Likelihood matrix for quick scoring:
Score Impact (1–5) x Likelihood (1–5) = Risk
Low: 1–5, Medium: 6–12, High: 13–25
Use to prioritise remediation and escrow sizing.
Sample representation and indemnity
Seller represents there have been no material cyber incidents in the last 24 months, except as disclosed with documentary proof. Seller indemnifies Buyer for costs arising from any undisclosed pre-closing cyber incident, including regulatory fines, forensic costs and business interruption, up to £[cap]. Escrow of £[amount] to be held for [12/24] months.
Errors that commonly ruin the result
Relying on verbal assurances or screenshots instead of signed reports or logs voids negotiations. This warns the reader what wrecks deals.
Overlooking policy wording and transferability
Assuming an existing cyber policy transfers to the buyer with all cover intact is risky. Many policies contain prior acts exclusions or a retroactive date that leaves gaps for pre-closing events.
Focusing only on technical gaps
Ignoring business interruption, customer loss and regulatory exposure narrows the view. Underwriters price for business impact as much as technical weakness.
"This works well in theory, but in practice many buyers stop at a checklist and miss the valuation math needed for negotiation."
Opinion and main recommendation
Buyers should always convert control gaps into an expected monetary exposure before negotiating price or indemnities. The caveat is that this approach is useful only if the seller provides dated, verifiable evidence.
If documentary proof is missing, insist on remediation before completion. Alternatively increase escrow to cover the expected value plus a contingency.
This method does not apply if the transaction is a true asset sale that expressly excludes liabilities and transfers no personal data or operational continuity.
For faster certainty, involve an insurance broker early. Let insurers give a pre-binding indication based on the evidence packet and remediation plan.
FAQ: cyber due diligence in SME M&A
What is the minimum evidence an underwriter needs?
Underwriters typically want an incident register, full policy wording, proof of backups and pen-test reports. They rarely accept screenshots alone. Providing signed reports with dates cuts review time and reduces the risk of exclusions.
How big should an escrow be for cyber risk?
Start with the expected value of identified risks and multiply by 1.5 for uncertainty. For SMEs, typical escrow sizes range from a few thousand to several hundred thousand pounds, depending on exposure. Use documented costs, not guesses.
Can warranty & indemnity insurance cover cyber?
W&I can cover some cyber risks but underwriters often exclude known breaches or require a separate cyber W&I. Buyers should expect specific carve-outs for prior acts and agree remediation plans where needed.
How do ICO fines affect M&A risk?
Regulatory fines, investigations and required remediation add direct cost and reputational damage. The ICO can issue fines under UK GDPR up to £17.5m or four percent of global turnover, and these potential liabilities must factor into valuation and escrow decisions.
How long does cyber due diligence typically take?
For SMEs, a focused cyber due diligence can take 3–21 days, depending on evidence availability and complexity. Gathering documents often takes the longest part of the process.
Final recommended step‑by‑step plan with timelines
Pre-sign (days 1–7): Request and collect the evidence packet and incident register. The seller delivers dated documents within 3–7 days.
Pre-sign (days 2–10): Calculate expected values using the three-tier model and prepare a short remediation plan. This takes 1–3 days for a small SME.
Pre-sign (days 4–17): Broker pre-check and insurer read to identify potential uplift or exclusions. Expect 2–7 days for a basic read and allow longer if prior breaches exist.
Negotiation (days 7–30): Use quantified exposures to request price adjustments, escrows, specific indemnities or seller remediation. Negotiate retroactive date or W&I as needed.
Post-close (days 1–90): Validate remediation milestones, run restore tests and confirm insurer binding or policy placement. Release escrow in stages tied to evidence of remediation.
Key dates and figures to use at negotiation:
- 24 months evidence window
- expected cost tiers Low £5k–£25k, Medium £25k–£150k, High £150k–£750k+
- ICO fine ceiling £17.5m or 4 percent turnover (UK GDPR, 2018)
Refer insurers and NCSC incident guidance for process details NCSC incident management and ICO breach reporting guidance ICO breach reporting.
Will an existing cyber policy transfer?
Coverage transfer depends on the policy terms and insurer consent. Many policies have prior acts exclusions or require insurer approval to transfer. Buyers should obtain the full wording and ask the broker to confirm transferability early.