Buying a Business? Twelve Questions to Ask About Its IT Before You Sign

Before you sign to buy a business, ask twelve questions about its IT and get the answers in writing: who can still administer its systems, whether a backup has ever been restored, and what its cyber insurer was told. They belong in the due diligence file beside the leases and the debtors list, because on settlement day you own all of them. inSUPPORT has run more than 1,500 cyber audits for Australian businesses, and an acquisition is the one case where answers are worth more before completion than after.

Nobody sets out to skip this. Due diligence is already long and expensive, and the IT question lands on whoever in the deal team once set up a network. The seller says the systems are fine, and nothing in the standard checklist asks anyone to prove it.

The reality is that the first civil penalty under Australia's Privacy Act began with exactly that gap. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over a breach of the Medlab Pathology systems it acquired in late 2021, on a network the Commissioner says it had not sufficiently assessed before buying.

That case is cited as a judgment, not a forecast. Every question that mattered was answerable before anyone signed. If the deal is already done, the companion piece on what to check first in an environment you have inherited covers the order afterwards. This is the IT due diligence checklist for the moment before.

TL;DR: What to remember

  • ✅ Twelve questions, three groups: four about who can get in, four about what you are actually buying, four about what arrives with the data. Every one is answerable in writing before completion.
  • ✅ Useful replies come as spreadsheets, dates and reports. "It is all fine" is a reassurance, and you cannot attach a reassurance to a warranty.
  • ✅ Australia's first Privacy Act penalty followed an acquired network nobody had assessed, and the court recorded senior management in the integration decisions. That is why these questions sit beside the financial ones.
  • ✅ What you ask before signing can shape the warranties and the price. What you find afterwards is simply yours.

Contents

Who can get in: the four access questions

Start with access, because it is the one area where the transaction itself creates the risk. The set of people who can reach the systems was assembled over years by the seller, and nothing in the sale process edits it. The former bookkeeper, the contractor who built the website, the previous IT company with its remote tool on every machine: all of them keep whatever access they had until somebody removes it. Ask now, while the seller is still motivated to answer.

1. Who holds administrator access, and is there a written list?

Ask for a list of every account that can administer something, and be explicit that you want it to reach past the front door. Most sellers will produce the domain and the Microsoft 365 or Google tenant without being pushed. The ones that go missing are the accounting and line-of-business applications, the network gear nobody has signed into since the day it was installed, and the management consoles of the security tools, which are worth asking about twice. Each entry needs a person's name against it, and each name needs a reason to be there. What you want back is a file you can read in ten minutes. An answer that starts with "our IT bloke would know" tells you the list does not exist, which means nobody has ever checked it either.

2. Which former staff, contractors and providers still have a way in?

Departed employees are the obvious group and rarely the dangerous one, because their accounts at least belong to a known name. The harder group is everyone who was never on the payroll: the developer who set up the website, the consultant who ran the last migration, the previous IT provider whose remote access agent is still sitting on every computer. Ask the seller to name every third party with standing access and say what each one can reach. If the answer is "nobody", ask how they know, because that answer is only true in a business that has actually gone looking.

3. Is multi-factor authentication enforced on everything reachable from the internet?

Not available, not recommended, not switched on for most people. Enforced, for every account, on email, remote access, the cloud tenant and anything financial. Multi-factor authentication is one of the Australian Signals Directorate's (ASD) Essential Eight mitigation strategies, and ASD's assessment guidance is worth borrowing as a buyer's standard: it ranks watching a control work as excellent evidence, and a policy document or a verbal statement of intent as poor evidence. So ask to watch somebody sign in from outside the office. If the seller cannot show you, write it down as not done.

4. Where are the shared passwords, and who knows them?

Every business has a few: the bank portal, the supplier account, the router, the login that runs the backups. Shared passwords survive because changing them breaks something, and a sale is the moment they matter most, because the group of people who know them is about to stop matching the group who works for you. Ask where they are kept and how many people can open that place. A password manager with named access is a good answer. A spreadsheet called passwords.xlsx is an honest one, and it goes straight onto the day-one list.

What you are actually buying: the four inventory questions

The purchase agreement describes assets in general terms, and the IT schedule is usually the vaguest part of it. This group of questions turns "the systems" into a list, and the list into evidence. It is also where the Australian Clinical Labs case sits most uncomfortably, because every one of these four was answerable before that deal closed. The Essential Eight guidance cited in this article was checked against ASD's current published material on 18 September 2026, and framework guidance does move, so check the date on anything you are handed.

5. What is the full list of devices, servers and cloud services, and what is out of support?

Ask for an asset register: every server, workstation, network device, cloud subscription and software licence, with an owner and a support status against each. Then ask which operating systems and applications the vendor no longer supports, because those stop receiving security fixes and the gap widens every month you own them. ASD's assessment guide treats replacing unsupported operating systems and removing unsupported software and online services as Essential Eight controls, so an inherited estate full of them is a remediation programme you are buying along with the desks. Price it in, or negotiate it out.

6. When did somebody last restore from the backups, and what came back?

A green tick on a backup console tells you a job finished. Whether the business could be rebuilt from what that job wrote is a separate question, and only a restore answers it. So ask for the last test restore: the date, what was recovered, how long it took, and the name of the person who signed it off. Ask separately whether the backups sit somewhere the same attacker could reach, because a backup encrypted alongside everything else has stopped being a backup. Where the only evidence is a monitoring screenshot, you are being asked to buy an assumption.

7. What can the internet reach?

Businesses open ports to solve a problem on a Tuesday and nobody ever closes them again. Ask for the list of what is exposed to the internet: remote desktop, the VPN, the web server, the camera system, the file transfer service somebody stood up for a supplier years ago. Then ask when each item was last genuinely needed. Put that list beside the answers to question two, because an internet-facing service and an account nobody owns are the two halves of the same problem, and you are about to own both halves.

8. When was the last penetration test, vulnerability assessment or security audit, and can I read it?

This is the question the Clinical Labs case turns on. The Commissioner's concise statement records that the buyer knew, before completing, that the business it was acquiring had not had a penetration test, a vulnerability assessment or an IT security audit in the preceding three years, and that it did not carry out a sufficient assessment of its own before buying. Justice Halley found that the company's most senior management were involved in the decision making around integrating the acquired IT systems and in the response to the attack, which is worth knowing if you are the one signing. Ask for the most recent report and read it, findings and all. If there is none, that is not a gap in the paperwork. It is a fact about the environment, and a reason to get an independent look before you sign rather than after. inSUPPORT runs internal and external penetration testing inside its Cyber Strength Audit, which is the kind of independent read this question is asking for.

What arrives with the data: the four obligation questions

Systems are the visible part of the purchase. Underneath them sit records about the seller's customers, staff and suppliers, the legal obligations attached to those records, and whatever has already happened to them that nobody noticed. These four are the questions an adviser is least likely to ask and a regulator is most likely to care about afterwards.

9. What personal information does the business hold, and does the Notifiable Data Breaches scheme apply?

Ask what categories of personal information the business collects, where it lives and how long it is kept. Then work out whether the Privacy Act's Notifiable Data Breaches (NDB) scheme covers it. The Office of the Australian Information Commissioner (OAIC) sets out that the scheme applies to organisations with an annual turnover of more than $3 million, and to certain businesses regardless of size, including private sector health service providers, credit providers and businesses that trade in personal information. The part that matters at signing is this: a small business that sat outside the scheme on its own may sit inside it once it is part of yours, so the obligations you are assessing are the combined entity's, not the target's.

10. Has there been an incident, and what would the logs show if there had?

Ask the direct question, then ask the one behind it: if somebody had been inside these systems, what records exist that would show when it happened and what was taken? The concise statement in the Clinical Labs matter records that firewall logs on the acquired network were deleted after one hour and that security alerts were not monitored, so when the attack came the company could not establish when it had occurred or whether data had left. Under the NDB scheme, an entity that suspects an eligible breach must take all reasonable steps to complete its assessment within 30 calendar days, and no amount of diligence recovers a record that was never kept. The $1.6 million of that penalty that related to assessment and notification is covered in detail in a separate piece. A seller reporting a clean history is telling you what was noticed, which in a business with no monitoring is a much smaller claim than it sounds.

11. What does the cyber insurance policy assume is in place, and what was the insurer told?

If the business holds cyber insurance, ask for the policy, the proposal form and the most recent renewal questionnaire, and read the technical controls the business said it had: multi-factor authentication, tested backups, patching timeframes, endpoint protection. Then set that list against the answers to questions one to eight. In the Clinical Labs matter, the Commissioner's concise statement records that the company's own insurance broker had identified a set of cyber security controls which it described as the insurers' minimum cyber security baseline for all businesses, regardless of industry or size. What any insurer makes of a distance between a questionnaire and an environment is the insurer's decision under its own policy terms, and nobody on the buy side is in a position to tell you otherwise. What you can do before signing is find out whether the distance exists.

12. What does the current IT provider hand over, and on what terms?

Most acquired businesses arrive with an incumbent provider and a contract the buyer has never seen. Ask for the agreement, the notice period, and what it says about documentation, credentials and data on exit. Then ask the provider directly for the handover pack: network diagrams, the asset register from question five, administrator credentials, licence records in the business's own name. ASD has published five questions for anyone engaging a managed service provider, last updated in October 2021: whether the provider implements the Essential Eight itself, administers systems securely, monitors activity, assesses its own services regularly, and is prepared for and able to respond to incidents. Check that date, the way you should check the date on any guidance somebody hands you, then ask the five anyway, because they are about operating discipline rather than any particular year's technology. It is the same commercial test as the twelve questions to ask a provider before you renew, asked one deal earlier. A provider who can hand over a folder on request has been running the environment. One who needs a fortnight to assemble it has been holding it.

Questions buyers ask before they sign

Is there an IT due diligence checklist I can hand to my adviser?

The twelve questions above are that checklist, and they are written so a lawyer, an accountant or a corporate development lead can put them to the seller without a technical translator. Ask for every answer in writing and attach the responses to the due diligence file, because a written answer can inform a warranty and a verbal one cannot. Where the seller cannot answer, record that too. An IT due diligence checklist is only useful if the blanks are as visible as the ticks.

The seller's IT provider says the environment is in good shape. Can I rely on that?

Treat it as given in good faith, then verify the parts that carry money. That provider has run the environment for years and has a natural interest in it looking well run, which is not dishonesty, it is human nature. An independent assessment before completion is usually limited by how much access the seller will grant, but even a scoped external test and a proper read of the documents behind questions five to eight moves you from being told to being shown. That shift is the whole reason to spend the money.

How long does this take, and can it be done before completion?

The questions themselves take an hour to ask and about a week for a cooperative seller to answer, because most of the evidence already exists somewhere. How long a technical assessment takes depends on how big and how complicated the environment is, which is ASD's own position on assessment approach, and on how much access you are granted before settlement. Start early in diligence rather than in the final week, so that a poor answer still has time to change the deal instead of only the integration plan.

We have already signed. Where do we start?

Start with access, while the people who can explain it are still taking your calls. A handover window closes faster than anyone plans for, and the old accounts, the shared logins and the third-party arrangements are precisely the things that live in somebody's memory rather than in the documentation. Work through who can reach what, and end anything that belonged to the previous arrangement. Then build the inventory, test a restore, and get the environment assessed against a framework, so what you inherited stops being a vague worry and turns into a priced sequence you can put in front of a board. Everything else you fix is only as sound as the access list underneath it.

Find out what you are buying before you buy it

Run the twelve on the seller first, and read what comes back as evidence rather than reassurance. If the answers are thin, or the deal is already done and the environment is now yours, the next step is an independent look at what is actually configured. A Cyber Strength Audit documents the environment, tests what can be reached from outside and from inside, reads the findings against the compliance frameworks that apply to your industry, and returns a plain English risk picture ranked by business impact, with a costed path to closing each gap. More than 1,500 of them sit behind how inSUPPORT approaches an environment it has never seen before, for Australian businesses of roughly 30 to 300 users. Finding the problems is the easy half. We are still here for the other half.

Book a Cyber Strength Audit →

Citations

  • "Australian Clinical Labs ordered to pay penalties in relation to Medlab Pathology data breach in first for Privacy Act", Office of the Australian Information Commissioner, published 9 October 2025. The $5.8 million civil penalty ordered by the Federal Court, its three components ($4.2 million, $800,000 and $800,000), the more than 223,000 individuals affected, the February 2022 breach, Justice Halley's finding on senior management involvement in the integration of the Medlab IT systems, and that the company admitted the contraventions. oaic.gov.au
  • "Australian Information Commissioner v Australian Clinical Labs Limited, concise statement", Filed in the Federal Court of Australia on 24 November 2023, NSD1287/2023, and published by the OAIC. The late 2021 acquisition of the Medlab systems, the absence of a sufficient pre-acquisition cyber security assessment, the three years without a penetration test, vulnerability assessment or security audit, the separately operated network, the firewall logs retained for one hour before deletion, and the broker's minimum-controls baseline. oaic.gov.au
  • "Part 4: Notifiable Data Breach (NDB) Scheme", Office of the Australian Information Commissioner, published February 2025. Which entities the scheme covers, including the $3 million annual turnover threshold and the categories covered regardless of size. oaic.gov.au
  • "Quick reference guide for responding to data breaches", Office of the Australian Information Commissioner, published 29 June 2026. The requirement to take all reasonable steps to complete an assessment of a suspected eligible data breach within 30 calendar days. oaic.gov.au
  • "Essential Eight assessment process guide", Australian Signals Directorate, last updated 2 October 2024. The four levels of evidence quality from excellent to poor, the controls requiring unsupported operating systems to be replaced and unsupported software and online services removed, and the position that the approach to an assessment depends on the size and complexity of a system. cyber.gov.au
  • "Questions to ask managed service providers", Australian Signals Directorate, last updated 6 October 2021. The five questions ASD suggests putting to a managed service provider: Essential Eight implementation, secure administration, monitoring activity, regular assessment, and preparation for and response to incidents. cyber.gov.au
Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE