Delfen
All articlesTechnical Due Diligence

OT due diligence: the blind spot in manufacturing M&A deals

Ransomware froze the target's plants in four countries while the deal waited for regulatory clearance — and the SEC filing that followed literally defines the term 'Cyberattack Amendments.' Here's the layer technical due diligence keeps missing, and the five questions that find it.

Jacques Domenie·9 July 2026·9 min read

In June 2019, Spirit AeroSystems was waiting for the last regulatory clearance on its $604 million acquisition of Asco Industries, a Belgian aerostructures manufacturer. On 7 June, ransomware hit Asco. Production stopped at plants in Belgium, Germany, Canada and the United States; roughly 1,000 of 1,400 employees were sent home. Five weeks later, the parties signed a letter agreement that now sits in SEC filings under a name you don't see often: the "Cyberattack Amendments." Escrow doubled to $80 million. A dedicated indemnity for cyberattack damages, capped at $150 million. Both sides reserved the right to argue the attack was a material adverse change. That October, the purchase price dropped from $604 million to $420 million — Spirit's own press release ties the reduction to cyberattack-driven delays. The deal was finally terminated in September 2020, mid-COVID, mid-737-MAX crisis, with the EU review still unfinished.

A ransomware attack on a manufacturer's operations rewrote a live deal — escrow, indemnity, price — in public, SEC-filed documents. And standard technology due diligence, as published and sold today, barely acknowledges that layer exists.

What technology due diligence covers — and what it misses

For this article I pulled the published technology-due-diligence scopes of ten firms: the Big Four transaction practices plus six advisory and specialist tech-DD firms (Alvarez & Marsal, West Monroe, Crosslake, Intechnica, RSM, Grant Thornton). The pattern is consistent: application landscape, infrastructure and cloud, IT organization and spend, software architecture and technical debt, cybersecurity of the corporate environment.

What none of them name in their standard methodology: PLCs, SCADA, MES, plant networks. One firm's scope list contains the words "operational technology" — a single line item in an enumeration, no method behind it. West Monroe's flagship study on cybersecurity due diligence in M&A contains no OT mention at all — while the same firm sells IT/OT integration work to utilities.

Let me be precise about the claim: this is a scoping gap, not a competence gap. The Big Four all have OT security practices. Specialists exist — Claroty markets its Edge product explicitly for M&A due diligence on industrial networks, NCC Group sells a distinct "Facility Due Diligence" service, DNV bought Applied Risk to build out its industrial-cybersecurity practice. But those are separate products you have to know to ask for. And the split matters: a passive-monitoring product like Claroty Edge only helps if you can get on the plant network pre-close — rare before signing; a facility-DD service works from documents, interviews and site walk-downs when you can't. The default tech-DD workstream a deal team commissions includes neither.

The term barely exists, either: when I searched "OT due diligence" while researching this article, nine of the first ten results explained operational due diligence — a different discipline entirely. This article uses the term anyway, because the gap needs a name.

What is OT due diligence?

Operational technology (OT) due diligence is the assessment of the systems that run physical production — PLCs and controllers, SCADA/DCS, data historians, MES, the plant network that connects them, the vendor remote-access paths into them, and the safety instrumented systems that sit beside them — as deal assets and deal liabilities.

The reason the IT playbook fails here is not subtlety; it's physics and lifecycle. Corporate IT refreshes every three to five years. Plant systems run fifteen to thirty. Microsoft's Digital Defense Report 2023 found that 25% of OT devices on customer networks run unsupported operating systems; a 2019 traffic study of 1,800+ production networks by CyberX (since acquired by Microsoft) found unsupported Windows versions at 62% of sites. You cannot patch what cannot stop producing — availability outranks confidentiality on a plant floor, which inverts most IT security logic. And the inventory usually doesn't exist: in Fortinet's 2026 State of OT report, only 14% of OT professionals report full visibility of their own OT environment — and that's the number after a year of improvement.

Now put that next to the deal clock. Manufacturing was the hardest-hit sector in Dragos's 2026 OT Cybersecurity Year in Review — more than two-thirds of the 3,300 industrial organizations hit by ransomware in 2025. The asset class most likely to carry undocumented, unpatchable, internet-adjacent systems is the one that gets the least diligence attention per euro of enterprise value.

What missed OT risk costs an acquirer

FedEx closed its $4.8 billion acquisition of TNT Express in May 2016 — its largest acquisition ever at the time. Thirteen months later, mid-integration, NotPetya arrived through the Ukrainian accounting software TNT used, and FedEx's own annual report puts the damage at roughly $400 million in the first half of fiscal 2018 — lost revenue from decreased shipments in the TNT network plus the cost of rebuilding IT systems, uninsured, while FedEx booked $380 million of TNT integration expenses at the Express segment in the same fiscal year. The systems that broke were the acquired company's; the P&L that absorbed it was the acquirer's.

Marriott learned the same lesson through a regulator. It completed the Starwood acquisition in September 2016; Starwood's reservation system had been compromised since 2014, and nobody found out until September 2018 — two years post-close, 339 million guest records. When the UK ICO first announced its intention to fine (£99.2 million, later reduced to £18.4 million), it said Marriott "failed to undertake sufficient due diligence when it bought Starwood." The final penalty notice walked back the acquisition-stage DD finding but established something more useful for every acquirer: due diligence on acquired data operations is "not time-limited or a 'one-off' requirement" — it's a continuing obligation that transfers with the keys.

The survey data says these aren't outliers. In Forescout's 2019 survey of 2,779 IT and business decision-makers, 53% reported a critical cybersecurity issue during a deal that put the acquisition in jeopardy. A separate 53% — the number that matters here — said they found unaccounted devices, including IoT and OT, only after integration was complete. IBM's 2020 study with Oxford Economics found more than one in three executives had experienced data breaches attributable to M&A activity during integration.

Five OT due diligence questions that find the blind spot

You don't need a full OT assessment team to know whether the blind spot is live in your deal. Five questions, askable in any diligence process, separate targets that manage their plant systems from targets that hope:

1. Can the target produce an OT asset inventory — with OS and firmware versions — within 48 hours? This is my favorite test because it's falsifiable and it's cheap. IEC 62443 makes an asset inventory the foundation of any OT security program; Fortinet's 14%-full-visibility number tells you most targets will fail. A fail doesn't kill a deal — it prices the unknown. That's what escrow is for, and Spirit–Asco shows what the number looks like when it's negotiated after the incident instead of before.

2. What actually separates the plant network from the office network? Dragos found poor IT/OT segmentation in 81% of the assessments it ran in 2025. Segmentation is the difference between "ransomware in the finance department" and "production stopped in four countries" — NotPetya travelled from an accounting application to global logistics operations precisely because nothing stopped it. A flat network is a Day-100 capex line; get it into the model before signing.

3. Who can reach the plant from outside, and how? Machine builders, integrators, and maintenance contractors routinely hold remote access into production systems — and Dragos's 2026 Year in Review reports that 73% of its all-time incident-response cases involved compromised VPN or jump-host credentials. Every vendor access path the target can't enumerate is a liability you're buying. This is a transition-services and remediation clause, not a footnote.

4. Are the safety systems independent of the control systems? Safety instrumented systems exist to shut a process down safely when control fails; IEC 61511 requires them separate and independent enough that a control-system compromise can't take them down too. TRITON — the 2017 malware built specifically to compromise Triconex safety controllers at a petrochemical plant — is the proof this attack class exists. If safety and control share credentials, engineering stations, or network segments, that's not a finding for the report appendix; it's a specific indemnity or a walk-away conversation.

5. Which production systems run software the vendor no longer supports — and what does replacing them cost? The 25%-unsupported-OS figure has a euro consequence: forced modernization on the acquirer's budget, on the insurer's terms, on the regulator's clock. Getting that number before signing turns it from post-close surprise into price adjustment.

There's a sixth question forming: which AI tools can already reach the target's production data? Industrial data hubs increasingly expose historians and MES to copilots and agents, and a target's proud "AI pilot" may already have write-adjacent access to plant systems nobody scoped. If the target can't answer who approved that access, you've found the same blind spot wearing next year's clothes — the governance question I unpacked in what AI governance actually means in operation.

Finding the blind spot is the cheap part. Pricing it — scoping the assessment, scoring what comes back, converting findings into escrow language, TSA clauses and capex lines — is the due-diligence work itself, and it's more than one article can hold.

NIS2 just turned the blind spot into a compliance transfer

Until recently, an acquirer inheriting a weak plant environment inherited operational risk. Now it inherits regulatory exposure with a start date.

NIS2 — Directive (EU) 2022/2555 — pulls manufacturing into scope explicitly: Annex II (point 5) lists manufacture of machinery, motor vehicles and trailers, electrical equipment, electronics, and medical devices among the "other critical sectors," alongside chemicals and food production. Article 21(2) then requires, among other measures, supply chain security (21(2)(d)) and — the quiet one — asset management (21(2)(i)). The directive literally requires knowing what's in the plant you just bought.

In the Netherlands this stopped being theoretical this month: the Cyberbeveiligingswet (Cbw), the Dutch NIS2 implementation, passed the Eerste Kamer on 7 July 2026 and enters into force on 15 August 2026, bringing more than 8,000 organizations under a registration duty, a duty of care, an incident-notification duty — and personal accountability obligations for boards, including mandatory training. Law firm Loyens & Loeff had spelled out the M&A consequence a year before the Dutch law even passed: acquiring a target that was previously out of scope "may trigger full NIS2 compliance post-acquisition, especially if IT systems are integrated," and the cost of bringing a non-compliant target up to standard "can materially affect deal valuation and integration planning."

That's the argument of this series in one sentence: the compliance gap doesn't stay with the seller — it transfers at closing, with interest. The next article takes that apart properly: what NIS2/Cbw exposure looks like in a target, and how to put a number on it before the price is set.

If you're looking at a deal with plant systems in it right now and want an independent technical read before the data room closes, that's a conversation, not a pitch.

Sources & further reading

Continue reading

Get the next article in your inbox.

One deep-dive per week. Free. No pitch. Unsubscribe anytime.

Subscribe to the Delfen Briefing →