Quick answer: The most critical IT due diligence red flags include undisclosed security incidents, end-of-life or unsupported infrastructure, missing compliance certifications, absent disaster recovery planning, and excessive reliance on a single person or vendor. Catching these signals before closing prevents deal value erosion, protects your organization from inherited liability, and sets up integration for success rather than chaos.
Most acquirers walk into due diligence focused on financials, customer concentration, and market position. IT gets treated as a checkbox rather than a strategic conversation. That is a costly habit.
Seventy to ninety percent of M&A deals fail to deliver their projected value,1 and IT integration problems rank among the leading culprits. Eighty-four percent of IT integrations fail outright or experience significant setbacks,2 and when things go sideways, the cost compounds fast: deals lose 30 to 50 percent of projected value when integration drags or collapses.3
The difference between a deal that delivers and one that drains you often comes down to what you find, or miss, in the technology review. Red flags do not announce themselves. They hide in outdated documentation, ambiguous vendor contracts, and confident-sounding answers from IT teams who learned to speak the language of due diligence without fully passing the test.
Here is what to look for.
Cybersecurity is the highest-stakes section of any IT review. More than half of organizations going through M&A encounter critical cybersecurity issues during the process,4 and the financial exposure is real: when Verizon acquired Yahoo, two undisclosed security breaches resulted in a $350 million reduction in the purchase price.5
The warning signs to surface immediately:
No evidence of regular vulnerability scanning or penetration testing. If a target organization cannot produce test results from the past 12 months, assume they have not looked. What you do not know in cybersecurity costs more than what you do.
Missing or partial multi-factor authentication (MFA). MFA is baseline hygiene. If it is not deployed across critical systems, remote access, and administrative accounts, you are inheriting an organization that accepted a preventable risk.
An undisclosed data breach within the last 24 months. This is a deal-defining discovery. An undisclosed breach is not just a security event; it signals a judgment call on the part of the seller. When this surfaces, expect a 10 to 25 percent holdback in escrow while the exposure is assessed.6
No cyber insurance, or a policy with major exclusions. Cyber insurance does not just pay for incidents. It tells you whether a carrier thought the organization was insurable in the first place.
Technology ages fast. Equipment and software that were current five years ago can be a liability today, and the warning signs show up if you know where to look.
End-of-life systems in production. Servers, operating systems, or applications that no longer receive security patches or vendor support are a standing vulnerability. They are not just expensive to remediate; they are actively dangerous to operate.
Excessive customization that limits scalability. Heavily customized ERP, CRM, or core business systems create a double problem: they are difficult to integrate with your existing stack and expensive to maintain long-term. If every upgrade requires a custom engagement, that is a recurring cost the seller has not fully disclosed.
A "bus factor" of one. If one person is the only one who can deploy to production, manage a core system, or interpret the architecture, that is a deal-structuring problem as much as a technical one. Institutional buyers treat this as a deal-killer.7
No documented disaster recovery or business continuity plan. Seventy-three percent of organizations experience significant integration delays stemming from documentation gaps.8 A target with no disaster recovery documentation is telling you something about how they have prioritized resilience, and how much remediation work you will need to absorb post-close.
Regulatory and compliance exposure can turn a clean deal into a legal cleanup project. The gaps that surface most often:
Missing SOC 2 Type II certification for B2B software companies. This gap carries a standard 5 to 10 percent purchase price reduction.9 Beyond the price hit, it signals that the target has not formalized the controls around security, availability, and confidentiality that most enterprise buyers now require.
No auditable data handling practices. If the target processes customer data, they need documented, enforceable policies around PII, retention, and access. Missing documentation creates exposure under HIPAA, GDPR, state privacy laws, or PCI-DSS depending on the industry.
Unlicensed or open-source software with viral licensing. Code audits regularly surface software with licensing terms that conflict with proprietary use. This can trigger a 5 to 15 percent price reduction or kill the deal entirely for institutional buyers with strict IP policies.7
Missing employee IP assignment agreements. If developers do not have clear agreements assigning their work product to the company, you may be acquiring software with ownership ambiguity baked in. This one can block a deal entirely.
Not every red flag is catastrophic. Some are operational patterns that tell you the IT organization has been running on inertia rather than intention.
No strategic IT leadership. An organization that has never had a CTO, CIO, or virtual CIO (vCIO) has likely made IT decisions reactively, without a long-term roadmap. You are not acquiring a technology capability; you are acquiring a cost center that has not been managed as an asset.
Significant inactive software licenses. Fifteen to 25 percent of seat-based subscriptions are typically inactive at review time.7 That is not just waste. It is a signal that IT governance and spend visibility are weak across the organization.
Vendor concentration without contract clarity. Single-vendor dependency is not automatically a red flag, but it becomes one when those contracts lack termination rights, SLA protections, or data portability provisions. Post-close, that relationship is yours to manage.
Finding red flags is not a reason to walk away. It is a reason to negotiate clearly. Every issue you discover before signing is leverage and information. The options are:
Price adjustment. Material findings routinely trigger renegotiation. In software-heavy acquisitions, price reductions of 5 to 25 percent are standard when significant IT issues emerge. Technology due diligence triggers renegotiation in 30 to 40 percent of these deals.7
Escrow holdback. For security or compliance exposure with uncertain remediation costs, an escrow holdback protects the acquirer while the liability is assessed and resolved.
Seller-funded remediation. Some issues, including outdated systems, missing certifications, and open IP questions, can be conditioned on completion before the deal closes.
Walk away. Some findings are disqualifying. A bus factor of one on a mission-critical system, undisclosed breaches with unknown scope, or unresolved IP ownership represent risks that no price adjustment adequately covers.
What you should not do is find these issues and file them away as integration tasks. They do not get easier post-close. They get more expensive.
For more on this topic:
Sentry Technology Solutions works with acquirers, private equity firms, and their portfolio companies to conduct structured IT due diligence that surfaces the risks that matter before you sign. We bring the same rigor to every assessment that our clients bring to their deals.
Schedule a consultation at sentryitsolutions.com.
The most frequently discovered issues include aging or end-of-life infrastructure, missing cybersecurity controls such as MFA and vulnerability scanning, absent compliance certifications like SOC 2 Type II, and inadequate or undocumented disaster recovery planning.
Yes. Specific findings, including a bus factor of one critical engineer, undisclosed security breaches, licensing contamination in proprietary code, or unresolved IP ownership gaps, are widely considered deal-killers by institutional acquirers.
Price reductions of 5 to 25 percent are standard when material IT findings emerge in software-heavy acquisitions. Undisclosed data breaches can result in 10 to 25 percent escrow holdbacks. Missing SOC 2 Type II certification alone typically triggers a 5 to 10 percent reduction.69
Ideally during or immediately after the letter of intent (LOI) phase, before significant legal fees are committed. Many acquirers now conduct a rapid red flag scan in the early stages and a full review after exclusivity is established.
A red flag is a warning sign that requires investigation. A deal condition is how that finding gets resolved, through price adjustment, escrow, seller remediation, or closing requirements. Not every red flag becomes a condition; context and deal structure determine the right response.
1. "50+ Post-Merger Integration Statistics (2026)," PMI Stack, https://pmistack.com/blog/post-merger-integration-statistics (2022 data).
2. Ibid. (2024 data).
3. Ibid. (2023 data).
4. UpGuard, "The Role of Cybersecurity in Mergers and Acquisitions," https://www.upguard.com/blog/the-role-of-cybersecurity-in-mergers-and-acquisitions.
5. Reuters / multiple published sources on Verizon-Yahoo price adjustment, 2017.
6. CT Acquisitions, "Technology Due Diligence in Mergers and Acquisitions (2026)," https://ctacquisitions.com/technology-due-diligence-in-mergers-and-acquisitions/.
7. Ibid.
8. "50+ Post-Merger Integration Statistics (2026)," PMI Stack (2025 data).
9. CT Acquisitions, "Technology Due Diligence in Mergers and Acquisitions (2026)."