Cybersecurity concerns are paramount in all merger and acquisition transactions. To overcome the risks, the cybersecurity due diligence process tends to be onerous and time-consuming, focused on what is being performed, not on the results of the activity. As a result, most due diligence efforts focus on the presence of controls and descriptions of activities performed by the seller’s cybersecurity function, not on how effectively cybersecurity exposures are managed.