By Ryan Windt | Head of Growth Marketing | Updated June 2026
Cyber insurance shows up in M&A transactions in ways that most deal teams are not fully prepared for, and the surprises almost always favor the other side.
A target company’s cyber policy can contain exclusions that survive the transaction and limit coverage for incidents that trace back to pre-close infrastructure. Coverage limits that looked adequate for a standalone company may be badly undersized once the target is integrated into a larger organization. A prior breach that was not disclosed, or was disclosed but not fully remediated, can make the acquired entity uninsurable on favorable terms for years. And private equity firms managing a portfolio of companies face aggregation risk that no individual company policy addresses.
This guide covers what acquirers, targets, and private equity investors need to understand about cyber insurance before a deal closes, during integration, and across a portfolio.
Why Cyber Insurance Belongs in M&A Due Diligence
Cyber diligence has become standard in most M&A transactions over the past five years. Security assessments, penetration test reviews, and SOC 2 audit examinations are routine asks in technology deals. What lags behind is the insurance piece: specifically, understanding what the target’s cyber policy actually covers, what it excludes, and what liabilities will transfer with the acquisition that existing coverage does not address.
The gap matters because cyber losses do not always surface immediately. A breach that occurred pre-close may not be discovered until months after the transaction. If the target’s policy has already expired or been replaced, and if the acquiring company’s policy excludes known incidents or has a retroactive date that does not reach back to the pre-close period, the acquirer can be left holding an uninsured loss from an event that happened before they owned the business.
This is not a hypothetical. Several high-profile post-acquisition breach disclosures have resulted in significant disputes over which policy responds, whether the breach was a known condition that should have been disclosed, and whether the acquisition itself triggered coverage changes that neither party anticipated.
The Cyber Insurance Due Diligence Checklist
Before a deal closes, acquirers should request and review the following from the target company.
Current Policy Documentation
Request the full policy, not just the declarations page. The declarations page shows limits and premium. The full policy shows what is actually covered, what is excluded, and how key terms are defined. Coverage for ransomware, funds transfer fraud, and regulatory fines often varies significantly between carriers and policy forms, and a declaration that says “cyber liability: $5 million” tells you almost nothing about whether that $5 million would respond to the losses most likely to affect the target. For guidance on how to read a policy in detail, see our post on how to read a cyber insurance policy.
Claims and Incidents History
Request a five-year claims history and ask specifically about incidents that were reported to carriers, incidents that were remediated internally without carrier notification, and any open or pending claims. An undisclosed prior breach is a material issue in two directions: it may affect the target’s insurability post-close, and depending on deal structure, it may be a representation and warranty issue that creates post-close liability for the seller.
A prior breach does not automatically make a company uninsurable, but it does affect what carriers will offer and at what price. For a full explanation of how prior breaches affect coverage, see our post on cyber insurance after a prior breach.
Retroactive Date
Cyber policies are written on a claims-made basis, which means coverage applies to claims made during the policy period, not to incidents that occurred during the policy period. The retroactive date is the earliest date from which covered incidents can originate. If the target’s policy has a retroactive date of two years ago, incidents that originated before that date are not covered even if they are discovered today.
Understanding the target’s retroactive date, and ensuring that post-close coverage maintains that date or extends it, is a specific due diligence item that is frequently overlooked. For a full explanation of how retroactive dates work, see our post on retroactive dates in cyber insurance.
Change of Control Provisions
Most cyber policies include change of control language that affects coverage when the insured entity is acquired. Some policies provide an automatic extended reporting period following a change of control. Others require notification within a specified window and may allow the carrier to reassess terms or pricing. A few policies terminate coverage upon change of control without a tail.
The specific language varies by carrier and policy form. Reading it before close, not after, is the only way to avoid discovering a coverage gap in the middle of an integration.
Sublimits and Exclusions
The full limit of a cyber policy is rarely available for any single loss type. Sublimits for ransomware, funds transfer fraud, business email compromise, and regulatory fines are common, and they are frequently set well below the policy’s headline limit. A $5 million policy with a $500,000 ransomware sublimit is a $500,000 ransomware policy. For a detailed explanation of how sublimits work, see our post on cyber insurance sublimits.
Exclusions deserve equal attention. Nation-state attack exclusions, war exclusions, infrastructure exclusions, and prior acts exclusions can eliminate coverage for the scenarios most likely to affect a target company in a specific sector. For a full breakdown of common exclusions, see our post on cyber insurance exclusions.
What Happens to Coverage at Close
The answer depends on deal structure, and it is more complicated than most deal teams expect.
Asset Acquisitions
In an asset acquisition, the buyer is purchasing specific assets, not the legal entity. The target’s insurance policies typically do not transfer with the assets. The buyer needs to arrange its own coverage for the acquired assets and ensure that coverage is in place from the moment of close. Any incidents affecting those assets that occurred pre-close and are discovered post-close will need to be addressed under either the seller’s policy (if it extends to cover the assets after they were sold, which it typically does not) or through representations and warranties insurance.
Stock Acquisitions and Mergers
In a stock acquisition or merger, the legal entity continues to exist and its insurance policies remain in force. The practical issue is what happens at the next renewal: the carrier now has a different insured than it underwrote, and it can reassess terms, pricing, or appetite based on the acquiring company’s profile. If the acquired company is being integrated into the acquirer’s own cyber program, the transition needs to be managed carefully to avoid gaps.
The Tail Coverage Question
Regardless of deal structure, the question of tail coverage for the target’s pre-close cyber exposure needs to be addressed. An extended reporting period endorsement, sometimes called a tail policy, extends the window during which claims can be reported under the target’s pre-close policy for incidents that occurred before close. Tail periods of one to three years are common in M&A transactions. Who pays for the tail, and how long it runs, is a negotiated deal term.
The most common post-close cyber insurance dispute in M&A is not about which policy has higher limits. It is about which policy’s retroactive date and reporting period covers the incident at hand. Getting clarity on this before close is far less expensive than litigating it after.
Private Equity Portfolio Coverage: The Aggregation Problem
Private equity firms managing a portfolio of companies face a cyber risk dynamic that individual company policies do not address: aggregation.
Each portfolio company carries its own cyber insurance. From the perspective of any individual policy, the coverage looks adequate. From the perspective of the PE firm, the portfolio is exposed to scenarios where a single attack affects multiple portfolio companies simultaneously. A shared IT service provider, a common software platform, or a shared managed service provider used across multiple portfolio companies can create a common point of failure that no individual company policy was designed to cover.
This is not hypothetical. Several large ransomware campaigns have propagated across MSP client bases, affecting multiple companies that shared a managed service provider. If those companies were portfolio companies of the same PE firm, the aggregate loss could far exceed any individual policy limit, and the PE firm’s own insurance would likely not respond to portfolio company losses.
Portfolio-Level Cyber Programs
Some PE firms address this by establishing a portfolio-level cyber insurance program that sits above individual company policies. These programs are structured differently from company-level policies and require specific broker expertise to place. The mechanics involve either a master policy with each portfolio company as an insured, or a captive arrangement where the PE firm retains some risk and purchases excess coverage. Neither is a commodity product, and the market for portfolio-level PE cyber programs is more specialized than the broader cyber insurance market.
Coverage Requirements for Portfolio Companies
Even without a portfolio-level program, PE firms can reduce aggregation risk by establishing minimum cyber insurance requirements for portfolio companies and monitoring compliance. Common requirements include minimum limits scaled to company revenue and industry, specific coverage for ransomware and funds transfer fraud, and requirements for certain security controls as a condition of maintaining coverage. Formalizing these requirements as part of the investment process, rather than discovering coverage gaps at the time of a loss, is the baseline approach.
Representations and Warranties Insurance and Cyber
Representations and warranties insurance has become a standard component of M&A transactions in the middle market and above. R&W insurance covers losses arising from breaches of the seller’s representations and warranties in the purchase agreement, including representations about the target’s cybersecurity posture, incident history, and compliance with applicable data protection laws.
The intersection of R&W insurance and cyber insurance creates coverage questions that need to be addressed at deal time. R&W policies typically exclude known breaches, meaning incidents that were disclosed or discovered during diligence. Cyber incidents that surface post-close may fall into R&W coverage, standalone cyber coverage, or neither, depending on when the incident occurred, when it was discovered, what was disclosed in the purchase agreement, and how each policy’s coverage triggers are written.
Having both a cyber specialist and an M&A insurance specialist involved in deal diligence, rather than treating insurance as a box to check, reduces the risk of post-close coverage disputes that no one anticipated.
Post-Close Integration: The Coverage Gap Window
The period immediately following close is when coverage gaps are most likely to occur and most likely to go unnoticed. The target company’s policy is still in force but may be approaching renewal under new ownership. The acquirer’s policy may not yet reflect the acquired entity. IT systems are being integrated, which creates new attack surfaces. And the deal team that managed due diligence has typically moved on.
The practical steps to manage this period include notifying both carriers of the transaction and confirming coverage status, reviewing the target’s policy renewal terms under new ownership before the renewal date, confirming that the acquirer’s policy is endorsed to cover the newly acquired entity if integration is underway, and establishing a single point of accountability for insurance program management across the combined entity.
The renewal checklist for the first post-close renewal is more involved than a standard renewal because the coverage program needs to reflect the combined entity’s actual risk profile, not just the pre-close profile of either company. For guidance on renewal preparation, see our post on cyber insurance renewal checklist.
Sizing Coverage for Acquired Entities
Limit adequacy is a recurring issue in post-close cyber program reviews. Companies that were adequately insured as standalone entities may be materially underinsured once their revenue, data footprint, and third-party relationships are combined with an acquirer’s profile. The standard approach of sizing limits to a percentage of revenue often understates exposure for companies with large customer data sets, significant third-party dependencies, or operations in regulated industries.
Post-close limit reviews should model the combined entity’s exposure to ransomware, business interruption, regulatory action, and third-party liability rather than simply carrying forward the target’s existing limits. For a framework on how to approach this analysis, see our post on how much cyber insurance you need.
Frequently Asked Questions
Does the target company’s cyber insurance transfer in an acquisition?
In a stock acquisition or merger, the target’s legal entity continues and its policies remain in force, subject to change of control provisions in the policy. In an asset acquisition, policies generally do not transfer with the assets and the buyer needs to arrange separate coverage. In both cases, the specifics depend on the policy language and require review before close.
What is tail coverage and who pays for it in an M&A transaction?
Tail coverage, formally an extended reporting period endorsement, extends the window during which claims can be reported under the target’s pre-close policy for incidents that occurred before the transaction. It is a negotiated deal term. Sellers typically prefer longer tails and buyers typically prefer the seller to fund them. One to three years is the common range for cyber tail coverage in middle-market transactions.
Can a prior breach at the target company affect the deal?
Yes, in several ways. An undisclosed breach can be a representation and warranty issue that creates post-close liability for the seller. A disclosed breach can affect the target’s insurability post-close, the terms available at renewal, and the price of tail coverage. How it affects the deal depends on the severity of the incident, the quality of the remediation, and how it was disclosed in the purchase agreement.
How do PE firms manage cyber insurance across a portfolio?
Approaches range from establishing minimum coverage requirements for portfolio companies to building portfolio-level insurance programs that sit above individual company policies. The right structure depends on the size and composition of the portfolio, the degree of shared infrastructure or service providers across portfolio companies, and the PE firm’s appetite for retaining versus transferring risk. Most middle-market PE firms start with coverage requirements and move toward portfolio programs as the portfolio grows.
Does cyber insurance cover losses from a breach that occurred pre-close but was discovered post-close?
This is one of the most common post-close coverage disputes and the answer depends on several overlapping factors: the retroactive dates on both the target’s and acquirer’s policies, whether tail coverage was purchased, what was disclosed in the purchase agreement, and how each policy’s reporting requirements apply. There is no universal answer, which is why getting explicit clarity on this scenario before close is important.
Related Resources
• Cyber Insurance After a Prior Breach
• What Is a Retroactive Date in Cyber Insurance?
• How to Read a Cyber Insurance Policy
• Cyber Insurance Sublimits Explained
• Cyber Insurance Exclusions: What Most Policies Won’t Cover
• Cyber Insurance Renewal Checklist
• How Much Cyber Insurance Do I Need?
SeedPod Cyber works with private equity firms, acquirers, and their portfolio companies to structure cyber insurance programs that hold up through transactions and across portfolios. Contact us | Learn about our coverages | See who we work with