The deal closed on a Friday.
By Tuesday morning, the new owner was sitting in a server room that nobody had documented in eleven years.
The financials were clean. Legal diligence was thorough. The QofE report came back solid. Everything on paper said this was a healthy 90-person business ready to integrate.
Then the IT picture started emerging.
No disaster recovery plan. A cybersecurity insurance policy set to lapse in six weeks because the underwriter had already flagged missing controls. Two servers running an operating system that stopped receiving security patches in 2020. A compliance obligation the seller never mentioned because the seller genuinely did not know it applied.
None of that was in the CIM. None of it surfaced in diligence. All of it now belonged to the buyer.
This scenario plays out over and over in small-cap M&A. The pattern is so consistent I can walk into any 25 to 200 employee acquisition target and predict within an hour which liabilities will be waiting on the other side of close.
Why Small-Cap IT Gets Under-Scrutinized
Large-cap deals have infrastructure around them. Investment banks. Big 4 IT advisors. Dedicated cyber diligence workstreams. A $2 billion acquisition gets six weeks of technology assessment before anyone signs an LOI.
A $30 million acquisition gets none of that.
The deal moves fast. The buyer is running lean. There is no dedicated IT advisor on the deal team, so IT diligence becomes a box on a checklist that a corporate development analyst fills in based on a conversation with the target’s office manager.
The target rarely helps. Smaller businesses often have no IT documentation. The person who built the systems left four years ago. The current setup is held together by one loyal vendor and institutional memory nobody wrote down.
The seller does not know what they have. Not because they are hiding anything. Because they genuinely never had a reason to know.
So the deal closes. And then reality shows up.
The Five Hidden IT Liabilities Almost Every Small-Cap Target Carries
After forty years watching this pattern, five liabilities show up in nearly every small-cap acquisition. Each one is invisible in standard diligence. Each one is expensive to fix after the wire hits.
1. No Real Documentation
Ask the target for a network diagram. What you get back is usually a hand-drawn sketch from 2018 or nothing at all.
Ask for a full software inventory. You get a spreadsheet of what accounting knows they paid for. That list will be missing 30 to 50 percent of what is actually running.
Ask which systems the business would die without in 24 hours. You get a shrug and a phone number for a guy named Kevin.
This is not a paperwork problem. It is a valuation problem. You cannot secure, patch, migrate, integrate, or optimize an environment you have not mapped. Every day post-close spent discovering what is running is a day of integration timeline slipping and cost creeping.
2. End-of-Life Hardware and Software Hidden in Fixed Assets
The balance sheet shows $340,000 in IT infrastructure at book value. The buyer models a normal depreciation schedule and moves on.
What the balance sheet does not show is how much of that $340,000 stopped receiving security patches years ago.
Servers running unsupported operating systems. Firewalls the manufacturer discontinued in 2021. Backup software the vendor sunset last spring. Line-of-business applications tied to a version of SQL Server that Microsoft stopped supporting before COVID.
All of it functional. None of it defensible. All of it now the buyer’s regulatory, insurance, and cyber problem the moment the deal closes.
Fixed assets on the balance sheet are not the same as functional assets in the business. Nobody explains this to the deal team.
3. Cybersecurity Exposure That Voids Cyber Insurance Post-Close
Cyber insurance is where small-cap deals get expensive quickly.
Every meaningful cyber policy today comes with an attestation the target signed at renewal. That attestation lists controls the target claims to have in place. Multi-factor authentication on all remote access. Endpoint detection and response. Immutable backups. Documented incident response. Regular vulnerability scanning.
Half those attestations are aspirational at signing. Nobody at the target verifies them because nobody knows how.
When the buyer’s cyber team does a real assessment three weeks post-close and finds MFA missing on a domain admin account, the insurance carrier now has grounds to deny coverage on any breach that touches that gap. The policy is technically still in force. Functionally it is worthless.
Then the ransomware event happens six months later, because ransomware events always happen, and the buyer discovers the policy will not pay. The $50 million target now has a $4 million uninsured incident on its books, and the buyer is answering to their investment committee.
4. Compliance Obligations That Transfer With the Acquisition
Small businesses often operate under regulatory obligations they do not fully understand.
The engineering firm handling designs for a defense subcontractor is subject to CMMC. The accounting practice touching healthcare clients has HIPAA business associate agreements they signed without reading. The insurance agency processing payments has PCI obligations. The private equity portfolio company preparing for a strategic exit will need SOC 2 within eighteen months to close that exit.
None of this is in the CIM. None of it comes up in diligence because the seller does not know their own compliance surface.
It all transfers with the acquisition. And the remediation window is short, because the acquiring entity now has documented awareness of the gap the moment IT diligence completes. Regulatory bodies are unforgiving about newly-discovered violations that go unaddressed.
Fixing a compliance program post-close costs three to five times what it costs to structure the fix into deal terms pre-close. That is a rough operator’s rule from watching this play out, not a consultant’s projection.
5. Vendor Contracts With Unfavorable Change-of-Control Clauses
The target’s core IT vendor contracts almost always contain change-of-control language. Almost nobody reads them during diligence.
The MSP contract auto-terminates 30 days after change of control. The line-of-business software license requires re-negotiation at the vendor’s discretion post-transaction. The cloud hosting agreement triggers a right of the provider to re-price at prevailing market rates, which for the acquiring entity are always higher than the small-cap target was paying.
Each contract in isolation is a small problem. Ten of them in a portfolio company inheriting a new post-close IT budget adds up to a meaningful hit on the first year’s operating model.
The buyer discovers this in month two, when the vendors start sending notices.
What This Costs Pre-Close vs. Post-Close
Every one of those five liabilities is a lever in deal negotiation. Or a bill after close.
Documentation and inventory gaps found pre-close become integration timeline realism baked into the plan. Found post-close they become a three to six month delay on integration synergies, which shows up directly in year-one IRR.
End-of-life infrastructure found pre-close becomes a capex holdback or a purchase price adjustment. Found post-close it becomes an unbudgeted capital request the buyer has to approve while explaining to LPs why the model was wrong.
Cyber gaps found pre-close become an insurance and remediation escrow. Found post-close they become uninsured breach exposure the buyer carries.
Compliance obligations found pre-close become reps and warranties with meaningful indemnification. Found post-close they become regulatory risk the buyer owns with no recourse.
Vendor contracts found pre-close become renegotiation leverage with the seller still holding motivation to help. Found post-close they become vendor concessions the buyer negotiates alone, from a weaker position.
The cost of fixing any one of these post-close is meaningfully higher than the cost of structuring around it pre-close. Across all five, in a typical small-cap deal, the difference frequently moves the whole return profile.
Structuring IT Diligence Into a Small-Cap Deal Process
Real IT diligence on a small-cap target does not require six weeks and a Big 4 team. It requires the right operator asking the right questions in the right order.
The framework we run for buyers looks like this.
Phase one, pre-LOI. A three to five day environmental scan. Network topology, asset inventory, security posture snapshot, compliance surface identification, cyber insurance policy review. This produces a red flag report that informs LOI structure.
Phase two, between LOI and close. Deep assessment on any red flags surfaced in phase one. Vendor contract review with change-of-control focus. Formal cyber risk report suitable for deal insurance. Compliance obligation mapping. This produces a remediation cost estimate and deal term recommendations.
Phase three, closing conditions. Specific IT-related closing conditions or purchase price adjustments based on findings. Insurance requirements. Escrow amounts for identified gaps.
Phase four, day-one integration. A 100-day IT integration plan built before close, so the buyer walks in with a defined path rather than a discovery exercise.
Buyers running this framework catch the time bombs before they detonate. Buyers skipping it find out what was in the environment the same way the previous owner did. By having something go wrong.
The Deals That Get This Right
The private equity firms and strategic buyers who consistently protect deal value in the small-cap segment treat IT diligence as a required workstream, not a checkbox. They build the relationship with a technology partner before the deal, so they have capability standing by when the LOI signs.
That partner does not need to be the biggest name in the industry. Big names charge like Big 4 and often send junior teams to small-cap deals anyway. What matters is pattern recognition from having done this specific work in this specific size range, repeatedly.
The buyer’s job is to protect capital. The diligence process is how that job gets done before the wire hits. IT is a workstream in that process, not an afterthought.
Working With Strix on M&A IT Diligence
Strix Technology Group runs technology diligence for private equity firms and strategic buyers acquiring businesses in the 25 to 200 employee range. Our engagements are structured for deal timelines, priced for small-cap economics, and delivered by senior operators who have run these environments themselves.
If you are looking at a target and want a straight read on the IT picture before you sign, that is the conversation to have.
Learn more about our managed IT and diligence capabilities, or reach out directly to talk through a specific deal.
The time bombs are always there. Whether they detonate before or after close is the buyer’s decision.