Cyber Security Liability In Mergers Involving Data-Rich Businesses
- 1 hour ago
- 12 min read
Introduction : Data is increasingly becoming the main asset in a progressing share of mergers and acquisitions. Fintech platforms, health tech organisations, SaaS providers and e-commerce businesses are measured substantially on the power of the consumer, and behavioural and transactional data they hold, which makes the cybersecurity status of a target organisation inseparable from its monetary worth. The largely discussed Yahoo-Verizon exchange displayed consequences when a notable breach comes up during diligence, pre-signing. A more difficult and progressively routine issue arises when the breach, or proof that a target’s ecosystem was jeopardized, surfaces only after a closed deal, when depictions have been made, the purchase price has been paid, and the acquirer has obtained functional control.
This blog analyses the post-deal scenario particularly- whether a cyber episode unearthed after closing is properly interpreted as a breach of contractual depictions and warranties, or a separate indemnity claim, or a conflict over the measurement base of the transaction. The difference is essential as each category stimulates a varying remedy, a distinct burden of proof, and a disparate insurance reply. This piece taps into Indian, US and comparative structures and explores due diligence and insurance methods available to mitigate risk.
Legal Provision
A. Indian Statutory Framework
Section 43A, Information Technology Act, 2000: Deploys civil liability on a body corporate that possesses or handles fragile personal data in a computer source and fails to maintain sensible security procedures, where said failure leads to wrongful loss or gain. This stipulation is the main statutory pillar for a firm’s pre-deal cybersecurity bearing.
Section 72A, IT Act: Chastises disclosure of personal information attained under a legal contract without consent, which becomes important when a breach commences from an insider with access to the target’s systems.
Digital Personal Data Protection Act, 2023 (DPDP Act): Applies affirmative obligations on data fiduciaries regarding security safeguards, breach notification to the DP board and impacted persons, and data governance, with monetary penalties for non-compliance. As these obligations attach to entity handling data, acquirers inheriting non-compliant data surrounding inherits associated regulatory exposure as well.
B. United States Statutory and Regulatory Framework
Computer Fraud and Abuse Act, 18 U.S.C. 1030: Penalises unauthorised access to protected computer systems and underlies much of the litigation and enforcement activity surrounding corporate data breaches.
SEC cybersecurity disclosure requirements (Item 1.05, Form 8-K): Need public companies to disclose material cybersecurity incidents within four business days of a materiality determination, and to describe their cybersecurity risk-management and governance practices in periodic filings. These obligations extend to new entities following acquisitions.
Federal common-law and state doctrines of successor liability: As per general corporate law principles, an acquirer that purchases substantially all of a target's assets, or that structures the transaction as a merger or stock purchase, may assume the target's pre-existing liabilities, including latent cybersecurity non-compliance, unless the purchase agreement expressly allocates that risk elsewhere.
C. Contractual and Insurance Framework
Representations and Warranties: Contractual statements by the seller regarding the target's cybersecurity posture, prior incidents, and regulatory compliance, which form the basis of a breach-of-contract claim if untrue as of signing or closing.
Indemnification Provisions: Contractual undertakings, often subject to caps, baskets and survival periods, obligating the seller (or an escrow) to compensate the buyer for losses arising from breaches of the representations or from specifically identified cyber risks.
Representations and Warranties Insurance (RWI): A third-party insurance product that steps into the seller's indemnification obligations, increasingly used to bridge the gap where sellers limit or refuse to give unqualified cybersecurity representations.
Legal Analysis
A. Warranty Breach, Indemnity Claim, or Valuation Dispute: Three Overlapping Frames
A cyber incident discovered after closing rarely fits neatly into a single doctrinal box. It becomes a breach-of-warranty claim where the purchase agreement contains a representation that, as of signing or closing, the target had not suffered a material security incident, had adequate security controls, or had disclosed all known vulnerabilities; if that representation proves false, the buyer's remedy lies in contract. It becomes an indemnity dispute where the agreement instead treats cybersecurity as a specifically indemnified risk, independent of whether a representation was technically breached, often because the parties recognised during diligence that some residual exposure could not be eliminated.
Finally, it becomes a valuation dispute where neither the representations nor the indemnity squarely addresses the incident, and the buyer instead argues that the purchase price itself was calculated on a mistaken premise about the target's risk profile, inviting a price adjustment or, in extreme cases, a claim of misrepresentation going to the inducement of the entire transaction. The Yahoo!-Verizon transaction illustrates the last of these outcomes: the discovery of undisclosed historical breaches did not simply generate an indemnity payment but led the parties to renegotiate and reduce the purchase price by USD 350 million, alongside separate securities-law penalties. Because these three frames are not mutually exclusive, well-drafted agreements increasingly specify, in advance, which frame governs a given category of cyber risk.
B. Cybersecurity Due Diligence and Its Structural Limits
Due diligence is the mechanism intended to prevent post-closing surprises, requiring the acquirer's counsel and technical advisers to review the target's security governance, network architecture, data flows, access controls, and history of security audits, certifications and penetration tests. Its principal limitation is that representations about the absence of prior breaches are almost always qualified by the seller's actual knowledge, because breaches are frequently undetected for long periods. Industry reporting places the average dwell time between initial compromise and discovery at well over six months, and notes that a majority of intrusions today involve no malware at all, relying instead on stolen or compromised credentials that leave few forensic traces. A knowledge-qualified representation therefore protects a seller that genuinely did not know of a breach, even though the buyer inherits the same undiscovered exposure. This structural gap is precisely why diligence, however thorough, cannot fully substitute for the risk-allocation tools discussed below.
C. Incident History as the Central Diligence Artifact
Because current security posture says little about latent compromise, the single most probative diligence artifact is the target's documented incident history: prior breach notifications, vulnerability assessment reports, penetration test results, security certifications such as ISO 27001 or SOC 2, and records of how previous incidents were detected, contained and remediated. A pattern of undocumented or informally handled incidents is itself a red flag independent of any single breach, since it signals that the target's monitoring and detection capability may be insufficient to have caught an ongoing compromise. Buyers increasingly request evidence-backed disclosure rather than bare representations, and independent security audits or penetration tests conducted shortly before closing, precisely to narrow the knowledge gap that qualified representations otherwise leave open.
D. Insurance as a Parallel Risk-Transfer Layer
Cyber insurance operates on a claims-made basis, covering losses discovered and notified during the policy period, which creates a distinct complication on a change of control: most policies automatically convert to "run-off," covering only pre-acquisition acts, while the buyer's own cyber programme, even where it extends automatic coverage to newly acquired entities, typically covers only post-acquisition events and does not automatically extend to prior acts. A buyer that assumes its own carrier will cover a target's undiscovered pre-closing exposure is often mistaken. The most reliable solution in practice is a cyber tail policy, obtained by extending the target's run-off period, ideally for at least twelve months, so that prior-acts coverage survives the transaction.
Representations and Warranties Insurance interacts with this layer but does not replace it: RWI underwriters frequently expect the target to already carry adequate cyber coverage before extending cyber-related protection, and some RWI policies are drafted to respond only to the extent losses are also covered under the underlying cyber programme, creating a risk that neither policy responds if the tail arrangement was never put in place. Because most sellers, in current market practice, limit their own indemnity for cyber losses to nil or a small percentage of the RWI deductible, the buyer's realistic recourse after closing is overwhelmingly insurance-driven rather than a direct claim against the seller.
E. Remediation Covenants and Post-Closing Integration Risk
System integration following closing is itself a distinct source of exposure, since combining networks, migrating data and consolidating access controls can propagate an undetected compromise from the target's environment into the acquirer's broader infrastructure before either party is aware of it. Purchase agreements increasingly include affirmative post-closing covenants requiring the target (or the surviving entity) to remediate identified vulnerabilities within specified timeframes, to segment networks pending a full security review, and to cooperate with the buyer's ongoing monitoring. These covenants convert cybersecurity from a one-time closing condition into an enforceable, time-bound obligation, and a failure to remediate as covenanted gives the buyer a contractual breach claim independent of whether the underlying vulnerability itself amounts to a breach of the original representations.
F. Allocating Risk Between Buyer and Seller
The allocation question is ultimately resolved through four negotiated mechanisms operating together rather than any single doctrine. First, the scope and knowledge-qualification of the representations determine whether an undiscovered breach is even actionable as a warranty matter. Second, indemnification structures, including baskets, caps and survival periods specific to cybersecurity representations, determine how much of the loss the seller bears even where a breach is established, and escrow or holdback arrangements provide a practical fund from which to satisfy such claims. Third, insurance, principally the tail policy and RWI, is increasingly the primary loss-bearing mechanism in practice, given how narrowly sellers now limit direct indemnities. Fourth, and increasingly significant, is the doctrine of successor liability: regulators are treating an acquisition as an assumption of the target's pre-existing compliance failures regardless of what the purchase agreement says as between the private parties, which means that even a buyer who has fully protected itself contractually may still face independent regulatory exposure that no amount of private risk allocation can eliminate.
Case Laws
A. Yahoo! Inc. and the Verizon Acquisition
During post-signing due diligence, Verizon discovered that Yahoo! had suffered undisclosed data breaches affecting over a billion user accounts. The disclosure led to a renegotiated purchase price, reduced by approximately USD 350 million, along with a USD 35 million penalty paid by Yahoo! to settle Securities and Exchange Commission charges for failing to timely disclose the breaches, and an additional USD 80 million paid to settle related shareholder securities litigation. The matter remains the clearest illustration that an undisclosed historical cyber incident can simultaneously generate a valuation adjustment, regulatory liability, and private litigation exposure, and that these consequences are not confined to the buyer-seller relationship but extend to securities regulators and shareholders as independent claimants.
B. Smith v. Van Gorkom, 488 A.2d 858 (Del. 1985)
Although decided decades before cybersecurity due diligence existed as a discipline, this Delaware Supreme Court decision remains foundational to M&A liability analysis. The Court held that a board of directors breached its duty of care by approving a sale without adequately informing itself, having acted hastily and without sufficient information to assess the transaction's fairness. Applied to a modern data-rich acquisition, the decision supports the proposition that a board's duty of informed decision-making necessarily extends to understanding the target's cybersecurity risk profile before approving a transaction, since inadequate diligence on a material risk factor can itself expose directors to liability independent of any breach of the purchase agreement.
C. DOJ Civil Cyber-Fraud Initiative Settlement Involving Raytheon, RTX Corporation and Nightwing (2025)
In an April-May 2025 settlement under the False Claims Act, the Department of Justice resolved allegations that a defense-sector business unit had failed to implement a security system plan compliant with NIST Special Publication 800-171 between 2015 and 2021. Significantly, the settlement named Nightwing, the entity that later acquired the relevant cybersecurity business, as the "successor in liability," notwithstanding that the acquisition occurred years after the underlying non-compliance. The settlement demonstrates that United States enforcement authorities now treat corporate restructuring and acquisition as insufficient, by themselves, to insulate an acquirer from a target's pre-existing cybersecurity non-compliance, reinforcing that successor liability operates as a risk-allocation mechanism that exists independently of, and cannot be fully displaced by, private contractual indemnities.
D. The Zomato Data Breach (India, 2017)
Zomato disclosed that approximately 17 million user records, comprising email addresses and hashed passwords, had been stolen following the compromise of an internal developer account. Although Zomato had represented compliance with recognised security standards, the incident exposed the gap between certification and actual security practice, a gap of direct relevance to any acquirer relying on ISO or similar certifications as diligence shortcuts. While Indian courts have not yet directly adjudicated an M&A dispute arising from an inherited breach of this kind, the enhanced obligations and penalty structure introduced by the DPDP Act since 2023 make it considerably more likely that an acquirer of a similarly situated Indian data-rich business would now face direct regulatory exposure for a pre-closing security failure it did not itself cause.
Practical Implications
Valuation methodologies that incorporate discounted cash flow analysis are directly affected by cybersecurity risk, since undisclosed vulnerabilities increase uncertainty about future cash flows and can justify a purchase price adjustment even absent a technical breach of representations.
Businesses in data-intensive sectors, including fintech, healthtech and SaaS, should expect cybersecurity diligence to be treated as a distinct workstream with its own legal and technical advisers, rather than folded into general IT or operational diligence, given the scale of potential post-closing liability.
Buyers should not assume that their existing cyber insurance programme automatically extends prior-acts coverage to a newly acquired entity, and should independently verify tail-policy arrangements before signing rather than after closing, when negotiating leverage over the seller's insurer has largely disappeared.
In cross-border transactions, particularly those involving Indian targets with EU or United States data exposure, parties must reconcile obligations under the DPDP Act, GDPR and applicable United States sectoral laws simultaneously, since a single incident can trigger overlapping and inconsistent notification timelines.
The DOJ's successor liability enforcement approach signals that acquirers of regulated or government-facing businesses should treat regulatory cybersecurity compliance as a diligence category distinct from, and in addition to, commercial and contractual cyber risk allocation.
Conclusion
If a cybersecurity incident uncovered post a deal becomes a warranty conflict, Whether a cybersecurity incident discovered after closing becomes a warranty dispute, an indemnity claim, or a valuation dispute depends less on the nature of the incident itself than on how the purchase agreement anticipated it. Where representations were broad and unqualified, a later-discovered breach naturally sounds in contrast9. Where sellers limited their representations to actual knowledge, as is now the market norm, the buyer's practical recourse shifts decisively toward insurance, principally a properly arranged cyber tail policy and, where available, Representations and Warranties Insurance. And where neither mechanism adequately addresses the loss, disputes increasingly resolve as valuation disagreements, as the Yahoo!-Verizon renegotiation demonstrates. Layered above all of this is the growing willingness of regulators, both in the United States and, prospectively, in India under the DPDP Act, to impose successor liability regardless of private risk allocation. The practical lesson for parties to a data-rich transaction is to treat cybersecurity due diligence, insurance arrangement and remediation covenants as an integrated risk-allocation exercise negotiated before signing, rather than a dispute to be litigated after the fact.
Annexure : Cyber-Diligence Questionnarie
The following questionnaire is intended as a starting checklist for acquirers evaluating a data-rich target, to be tailored to the specific industry and jurisdiction involved.
1. Governance and Policy
1.1. Does the target have a board-approved information security policy, and who has executive-level ownership of cybersecurity risk?
1.2. What certifications (ISO 27001, SOC 2, PCI DSS) does the target hold, and when were they last independently audited?
2. Incident History
2.1. Has the target experienced any security incident, confirmed or suspected, in the preceding five years, and how was each detected, contained and disclosed?
2.2. What is the target's average detection and containment time for security incidents, and does it maintain incident response logs and playbooks?
3. Data Mapping and Controls
3.1. What categories of personal, financial or proprietary data does the target hold, where is each category stored, and how is it encrypted in transit and at rest?
3.2. What access controls, authentication requirements and data-retention limits apply to each data category?
4. Third-Party and Vendor Risk
4.1. Which vendors or service providers have access to the target's systems or data, and are their security obligations governed by contract?
4.2. Has the target conducted security assessments of its critical vendors within the past twelve months?
5. Insurance
5.1. Does the target hold a cyber liability policy, what is the claims history, and does the policy include prior-acts coverage in the event of a change of control?
5.2. Is the target's insurer willing to negotiate a run-off or tail extension before closing?
6. Regulatory Compliance
6.1. Which data protection and sectoral regulations apply to the target (DPDP Act, GDPR, sectoral United States statutes), and has the target received any regulatory notice, inquiry or penalty?
6.2. Has the target completed a data protection impact assessment where required, and is documentation available for review?
7. Post-Closing Integration
7.1. What network segmentation will be maintained between the target's and acquirer's systems pending a full post-closing security review?
7.2. Which specific remediation actions, if any, will be required as covenants surviving closing, and within what timeframe?
Author: Yashvi Chaturvedi in case of any queries please contact/write back to us via email to content@khuranaandkhurana.com or at Khurana & Khurana, Advocates and IP Attorney.
References
Information Technology Act, 2000, § 43A, No. 21, Acts of Parliament, 2000 (India).
Information Technology Act, 2000, § 72A, No. 21, Acts of Parliament, 2000 (India).
Digital Personal Data Protection Act, 2023, No. 22, Acts of Parliament, 2023 (India).
Computer Fraud and Abuse Act, 18 U.S.C. § 1030 (2018).
Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, 17 C.F.R. §§ 229.106, 232 (Form 8-K, Item 1.05) (2023).
Smith v. Van Gorkom, 488 A.2d 858 (Del. 1985).
General Data Protection Regulation (EU) 2016/679, 2016 O.J. (L 119) 1.
Gowling WLG, Buyer Beware: Cybersecurity Due Diligence in M&A Transactions, National Law Review (2024).
U.S. Securities and Exchange Commission, In re Altaba Inc., f/d/b/a Yahoo! Inc., Release No. 10485 (Apr. 24, 2018).
Forbes / AllBusiness.com, Cybersecurity, Data Privacy, and Data Breach Risks in M&A Due Diligence (2019).
Marsh McLennan Agency / Insurance Business Practice Group, Cyber Insurance in M&A: The Risk of Latent Data Breaches (2023).
Denver Law Review Forum, Tanya Fuhrman-Wenman, Cyber Insurance in International Mergers and Acquisitions, 93 Denv. L. Rev. F. 361 (2016).
IBM Security, Cost of a Data Breach Report 2022.
CrowdStrike, 2023 Global Threat Report.
Federal Bureau of Investigation, Internet Crime Complaint Center, 2023 Internet Crime Report.
UK Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2024.
U.S. Department of Justice, Press Release, Raytheon Company, RTX Corporation, Nightwing Group LLC and Nightwing Intelligence Solutions LLC Agree to Pay $8.4 Million to Resolve Civil Cyber-Fraud Allegations (Apr.-May 2025).
Zomato Data Breach Disclosure, reported May 18, 2017 (CNN, Help Net Security, BankInfoSecurity).
National Association of Insurance Commissioners, Cyber Liability Policies (Topic Brief).
Gallagher, Representations and Warranties Insurance Market Report 2022.
NetDiligence, Cyber Claims Study (2012 and subsequent annual editions).




Comments