Abstract geometric pattern in navy and steel blue tones suggesting network nodes and contractual risk boundaries in a transaction
M&A Advisory

One in Five Deals Now Skips the Cybersecurity Rep

In 2024, only 5 percent of private-target acquisitions closed without a cybersecurity representation. That figure has climbed to 22 percent, and the risk did not disappear, it just moved.
KAS Advisors • September 10, 2026 7 min read

A representation in a purchase agreement is a promise about a fact, and every promise a seller makes is a promise a buyer can later sue on. Sellers have quietly started declining to make one particular promise: that the business has not been breached. In 2024, only 5 percent of private-target deals closed without a cybersecurity representation. In the most recent full-year data, that figure reached 22 percent. When a seller stops warranting something, the underlying risk does not vanish. It gets repriced somewhere else in the agreement, usually in a place that costs the seller money.

What the data actually shows

The figures come from the 2026 SRS Acquiom M&A Deal Terms Study, which analyzes more than 2,300 private-target acquisitions worth roughly $569 billion that closed between 2020 and 2025. It is one of the more reliable windows into what private company purchase agreements actually contain, because the sample is drawn from deals the firm worked on rather than from public filings.

On cybersecurity, the study records a sharp reversal. The share of deals with no cybersecurity representation went from 5 percent to 22 percent year over year, an increase of roughly 440 percent. In practical terms, a bit more than one deal in five now closes without the seller making any standalone promise about the target's security history or posture.

That is unusual. Deal terms tend to move in small increments. Escrow percentages shift by a point, earnout adoption drifts a few percent, basket structures rotate slowly. A representation going from near-universal to absent in a fifth of transactions inside a single year is a structural change in how one category of risk is being allocated.

It is worth being precise about what a cybersecurity representation covers. Typically it is a set of statements: that the company has not suffered a data or security incident requiring notification to regulators or customers, that it complies with applicable privacy and data protection requirements, that it maintains reasonable safeguards, and that it is not aware of material unremediated vulnerabilities. Those are facts, not opinions, and a seller who gets them wrong is liable regardless of good faith.

Why sellers are backing away

The most cited explanation is artificial intelligence, and it is a reasonable one, though the mechanism is worth spelling out.

Over the last two years, most companies have expanded their software surface considerably. AI tools have been adopted by individual departments, often without central IT sign-off. Vendors have embedded AI features into products the company already licensed. Employees route company data through services the company never formally approved. Each of these adds an integration point, a data flow, and a third party with access.

The result is that a CEO or CFO signing a purchase agreement in 2026 has less confidence about the boundaries of their own environment than they did in 2023. That is not negligence, it is a real change in the difficulty of the question. Representations are not qualified by effort. A seller either has or has not suffered a reportable incident, and if a forensic review two years after closing turns up an intrusion nobody knew about, the language in the agreement does not care that the seller was acting in good faith.

There is a second factor that has nothing to do with technology. Buyers pushed representation packages steadily broader through the 2010s, and sellers with leverage have been pushing back. In a market where sellers have held reasonable negotiating position, refusing a rep the seller cannot verify is a rational trade, particularly when the alternative is a knowledge qualifier so heavily negotiated that it provides the buyer little comfort anyway.

A representation is not a statement of effort. It is a statement of fact, and the seller carries the consequence of being wrong about it.

Where the risk goes instead

Nothing about a deleted representation makes a buyer more comfortable. It makes the buyer look for protection elsewhere, and the same study shows where that protection is being found.

Escrows grew materially. Across all deals, average escrow rose from 10.25 percent of transaction value in 2024 to 12.1 percent in 2025. For deals without representation and warranty insurance, the average moved from 13.2 percent to 14.7 percent. Indemnification escrows specifically rose from an average of 7.8 percent to 8.8 percent of deal value, with the median climbing a full point to 10 percent. Buyers are holding back more cash at closing, and they are holding it longer.

Indemnification terms also shifted toward buyers. Deals with no survival of seller representations, sometimes called walk-away deals, fell from 18 percent to 11 percent among non-insured transactions. Deductible baskets, which require a buyer to absorb losses up to a threshold before recovering anything, dropped from 39 percent of deals to 32 percent, with first-dollar recovery and no-basket structures picking up the difference.

Read together, the picture is coherent. Sellers gave up ground on how long they stay on the hook and how much a buyer must absorb before claiming, while gaining ground on one specific promise they did not want to make. Whether that is a good trade depends entirely on the business.

Section divider

The insurance complication

Roughly 46 percent of deals in the study involved representation and warranty insurance, and that changes the calculation in a way sellers frequently miss.

Warranty insurance does not insure a business. It insures the representations in the agreement. An underwriter reads the rep package, reviews the diligence conducted, and prices coverage against that specific set of promises. Where a representation is absent, there is nothing to insure. Where a representation exists but diligence in that area was thin, underwriters commonly add an exclusion.

So a seller who successfully negotiates out the cybersecurity representation may find that the policy the buyer is buying now excludes cyber losses, which returns the buyer to the negotiating table asking for a special indemnity or a dedicated escrow to cover the gap. The seller has not removed the exposure. They have converted an insured exposure into an uninsured one that sits directly on their own proceeds.

For sellers with a defensible security posture, the better trade often runs the other direction: give a well-scoped representation, support it with credible diligence, let the insurer underwrite it, and keep the escrow small.

Key Considerations Before You Go to Market

What to watch

Three things over the next several quarters. First, whether the 22 percent figure holds or proves to be a one-year reaction to a particularly uncertain moment in enterprise technology. Second, whether the insurance market develops a standard product for the gap, since underwriters generally follow demand of this size. Third, whether buyers begin requiring third-party security attestations as a diligence condition, which would shift the cost of proof from the agreement to the pre-signing process and change the economics for sellers again.

The Bottom Line

A fifth of private-target deals now close without the seller promising anything about cybersecurity, and that shift is best understood as risk moving rather than risk disappearing. Buyers responded with larger escrows, shorter paths to recovery, and longer survival periods. For most owners the practical question is not whether to give the representation, but whether they know enough about their own environment to give a well-scoped version of it and be paid for the certainty. Finding that out costs far less before a process starts than it does during one.

Disclaimer: This article is for informational purposes only and does not constitute financial, investment, tax, or legal advice. KAS Advisors recommends consulting with qualified professionals before making business or financial decisions. Past performance and market trends discussed herein are not indicative of future results.