Michael J. Bannach: Five Cyber Questions Every Buyer Should Ask Before Signing

Alexandra Pierce ··4 Mins Read
Man in a suit and tie with a stylish hairstyle against a dark background

The Stealth Technology Group CEO, who built his company through three acquisitions, says cyber due diligence belongs next to the quality-of-earnings report. The same five questions tell owners what to fix before they go to market.

Buyers spend weeks on the quality of a target’s earnings and hours on the quality of its network. Michael J. Bannach, President and CEO of Stealth Technology Group (STG), thinks that ratio is backward, and he has sat on the buyer’s side of the table three times.

STG was built by combining three regional IT firms, GizmoFish in Boston, Savage Consulting in Tampa and Empire Computer Services in Sarasota, and Bannach led the technology integration of each. “In a stock deal you inherit everything, and even in an asset deal the systems, the accounts and the client expectations usually come with you,” he said. “The quality of the network is part of what you’re paying for, whether anyone priced it or not.”

The best-known example is still Verizon’s purchase of Yahoo, which closed in 2017 at $350 million below the original price after Yahoo disclosed data breaches that predated the deal. Few mid-market transactions make headlines, but Bannach says the pattern is the same. “Most targets aren’t hiding anything,” he said. “They just never looked.”

Five Requests That Replace Assurances With Evidence

Bannach, a CISSP with more than 25 years in enterprise IT and cybersecurity, asks for evidence rather than assurances. His diligence starts with five requests.

The first is a privileged-access inventory: every administrator, service account and outside vendor with elevated access, whether multifactor authentication protects each one, and how many active accounts belong to people who left years ago.

The second is a sensitive-data map showing where customer, employee and regulated information lives and which obligations travel with it, from client confidentiality terms to health-privacy or defense contract clauses.

The third is a dated restore test. A backup policy describes intentions; a restore test shows whether the business can recover from ransomware in hours or in weeks.

The fourth is the list of security commitments the company has already made in customer contracts, prime-contractor flow-downs and vendor agreements, because those promises become the buyer’s to keep.

The fifth is history: prior incidents, insurance claims and the answers on the most recent cyber insurance application. “The insurance application is one of the most revealing documents in the data room,” Bannach said. “It tells you what leadership believed about its controls. Your job is to find out whether it was true.”

For buyers, those answers are bargaining power. Issues found before signing can be priced, covered by a holdback or made a condition of closing. Issues found after closing are simply paid for.

What an Integration Taught Him

One integration shaped how Bannach thinks about evidence. A regional nonprofit that came to STG through the GizmoFish acquisition began its relationship with the firm on a single Azure server. When a donor asked the organization to show its cybersecurity posture, the nonprofit expanded into fully managed IT and cybersecurity with STG.

“The donor didn’t ask whether they felt secure. The donor asked for proof,” Bannach said. “Buyers, insurers and major clients ask the same question now. The companies that can answer it are worth more.”

His integration rule follows from that. Nothing connects to the acquirer’s network until the acquired environment has been assessed and brought to a known baseline, under a scoped plan that sets the order of credential changes, monitoring and consolidation. The sequence follows service to clients, not the org chart. “The worst time to learn how a company handles admin access is the day you connect it to yours,” he said. “Isolate first, measure second, connect last. It’s slower in week one and faster in year one.”

Acquired teams matter as much as acquired systems. They know which servers are fragile, which vendor holds a password nobody wrote down, and which process works only because one person remembers it. Bannach makes those conversations part of diligence rather than a surprise after closing.

Answer the Questions Before a Buyer Asks

The same five requests work in reverse for owners planning a sale, a recapitalization or a private equity partnership. Answering them before going to market turns a potential diligence finding into a strength in the data room, and it shortens the conversation that most often slows a deal down.

“Every CEO who has done a deal knows the quality-of-earnings report by heart,” Bannach said. “I want them to know the quality of the network just as well, before anyone else asks.”

For leadership teams that want that picture before a buyer, lender or insurer asks for it, STG’s Stealth 360°™ Assurance Baseline documents what is working and what needs attention.

Michael J. Bannach is President and CEO of Stealth Technology Group (STG), one accountable partner for IT, cybersecurity, compliance and AI for regulated mid-market companies and defense suppliers. STG is a Cyber AB Registered Practitioner Organization with teams serving Tampa, Sarasota, Boston and Greater Philadelphia. A CISSP with more than 25 years in enterprise IT and cybersecurity, Bannach also holds CCNP Enterprise and CCNP Collaboration certifications, a certificate in AI products and services from MIT, and an Executive MBA from Saint Joseph’s University. Learn more at michaelbannach.com and stealthtech365.com.

cybersecurityMichael J. BannachStealth Technology Groupdue diligenceIT acquisitionsdata breaches

CEO Times Contributor

Alexandra Pierce

Covers business, innovation, and leadership, with a particular interest in entrepreneurs and emerging brands.


This article features partner, contributor, or branded content from a third party. Members of the CEO Times editorial staff were not involved in the creation of this content. All views and opinions are those of the contributor alone.

You May Also Like