Cybersecurity Due Diligence Case Study: A Real PE Acquisition

From Storage Units to Cybersecurity

From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition

How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities.

The short version:

  • Client: Single-location self-storage operator in Colorado (anonymized)
  • Buyer: Private equity-backed storage operator with 50+ facilities
  • My role: IT and security provider for 4.5 years, then transition lead on the seller side
  • Handoff: Three weeks, kickoff to done

It started with a breach

They found me the way a lot of my clients do: mid-incident. Their previous IT provider had gone defunct, and the provider’s abandoned website was serving malware. Someone at the storage company opened that site looking for support and infected their machine instead.

I took the call, cleaned the infection, recovered their systems, and combed through everything for leftover malicious code. Then I rebuilt their stack so it wouldn’t happen twice: antivirus, EDR through Huntress, cloud backup, and same-day helpdesk, remote and onsite. All of it sized and priced for a single-location business.

Four and a half years of quiet

For the next 4.5 years I ran their IT and security. Webroot and Huntress covered the endpoints. Backups ran to the cloud and got checked. When something broke, I fixed it the same day. No repeat incidents, no drama.

That stretch of quiet matters more than it sounds. When a buyer showed up years later, the company had a documented, monitored environment with a real security history behind it. Most small businesses walk into a sale with none of that.

Then a buyer showed up

A private equity-backed storage operator with 50+ facilities acquired the company. Deals like this live or die in diligence, and the buyer’s team had two questions about IT: is this environment secure, and is it cost-effective?

That’s technology due diligence in one sentence. Buyers want proof, and on small acquisitions they rarely get it, because the seller’s IT knowledge lives in one person’s head or a defunct vendor’s filing cabinet. Here, I had run the environment for years and could answer with documentation instead of guesses. That alone shortened the timeline.

The three-week handoff

Post merger IT integration for this deal came down to four workstreams.

RMM migration. The buyer standardized every acquisition onto their own remote management platform. Instead of touching each machine by hand, I wrote a script that deployed their agent and removed mine (ConnectWise Automate, at the time) across all systems in one pass.

Backup migration. I moved their cloud backups off my platform and onto the buyer’s, and verified restore points on both ends before cutting over. A migration without verified restores is a gamble, and nobody gambles during a closing.

Access control. The buyer’s team ran the access control migration themselves. I supported from the client side, kept credentials flowing, and made sure nothing on our end held them up.

Data cleanup and destruction. The buyer’s compliance requirements meant old data had to go, and go for real. I purged stale records the business no longer needed, then dealt with the retired hard drives that held customer data: a seven-pass wipe on each drive, and then I opened them up and pulled the platters out. Nobody is recovering that data. The platters make decent coasters, if you’re wondering.

Secure data destruction is the step small-business acquisitions skip most, and it’s the one that turns into a lawsuit years later when a drive full of customer records surfaces at a pawn shop.

Total time, including the buyer’s inspection and the back-and-forth between their team and my client: three weeks.

The result

The buyer got what diligence teams almost never get from a small acquisition: a documented environment, a working security stack, verified backups, and proof that legacy customer data was destroyed instead of forgotten in a closet. My client walked into closing without IT sitting on the deal as an open issue.

And the whole thing traced back to a malware infection five years earlier. The same work that saved them from a breach made them a cleaner company to buy.

Why this matters if you’re buying or selling

Most small businesses run on undocumented IT held together by whoever set it up. In an acquisition, undocumented becomes risk, and risk becomes a price reduction or a delayed close. Buyers now run cybersecurity due diligence on deals of every size, and sellers who can’t answer basic questions about their environment pay for it at the negotiating table.

If you’re a buyer, a searcher, or an owner planning an exit, the cheapest time to fix your technology story is before diligence starts. That’s the work I do: assess the stack, close the gaps, and run the handoff so the deal keeps moving.

Working a deal and want a second set of eyes on the technology? Get in touch.