When accounting firms evaluate acquisition targets, technology and security are almost always an afterthought. The deal team focuses on revenue, client relationships, partner compensation, and cultural fit. Technology gets a cursory glance — usually limited to "what software do they use?" — if it gets looked at all.
I've been directly accountable through 24 M&A integrations at Top 10 professional services firms. Deals ranging from $5 million to $100 million or more. And I can tell you that the technology issues discovered after close are almost always more expensive and more disruptive than anyone anticipated. The firms that catch these issues during due diligence can negotiate better terms, plan realistic integrations, and avoid the post-close scramble that derails so many deals.
Here are five red flags that should make any acquirer pay very close attention.
Red Flag #1: No Clear Technology Budget (or One That's a Black Box)
When you ask a target firm for their technology budget and what comes back is a single line item on the P&L — one big bucket where "all the IT costs go" — that's a red flag. It means nobody has visibility into what's actually being spent, where the money is going, or what's recurring versus one-time.
Smaller firms without a dedicated IT person are especially prone to this. Expenses show up on credit cards with vague descriptions. Recurring software subscriptions are buried in office expenses. Hardware purchases get mixed in with furniture. Sifting through these records to understand the true technology cost structure is incredibly difficult and time-consuming.
What you're really looking at when the budget is a black box is uncertainty. And in M&A, uncertainty means risk — which should mean either a price adjustment or a very conservative integration timeline.
Red Flag #2: Aging Infrastructure That's About to Become Your Problem
One of the firms we merged with had servers that were ancient. Not just old — end-of-life. They were going to need replacement within six months of our tentative close date. That cost was going to land on the acquiring firm's budget, not the seller's. If we hadn't caught it during due diligence, it would have been a surprise capital expenditure right when we were trying to manage integration costs.
This extends beyond servers. Workstations that can't run current software. Network equipment that can't support modern security requirements. Phone systems that haven't been updated in a decade. Each one of these represents a cost that the acquiring firm will inherit — and that should be factored into deal terms.
The hardware question also drives one of the earliest integration decisions: do you treat acquired employees like new hires (rip out everything, issue new equipment, clean start) or do you try to integrate their existing hardware into your environment? The clean approach is more expensive upfront but dramatically simpler. The integration approach saves money initially but creates months of compatibility issues and support headaches.
Red Flag #3: Vendor Contracts You Can't Get Out Of
This one has burned me personally. We inherited a five-year software contract from an acquired firm that was drastically overpriced. The vendor had locked them in, and now the contract was ours. We had to go back to the vendor as a much larger firm and essentially beg them to renegotiate — leveraging the fact that we could bring them significantly more business if they worked with us. It worked, but it cost months of negotiation time and the outcome was still worse than if we'd caught it before close.
During due diligence, you need to see every technology contract, its term length, renewal dates, and termination clauses. You're specifically looking for contracts that expire near the integration window (forcing rushed decisions), contracts with automatic renewal clauses that are about to trigger, and contracts where the pricing is significantly above market for the firm's size.
Every unfavorable contract you discover during diligence is leverage in the negotiation. Every one you discover after close is just a cost you have to absorb.
Red Flag #4: Undisclosed Security Incidents
One of the very first questions to ask during due diligence is whether the target firm has experienced any security incidents — and to ask for documentation of what happened and how it was resolved.
Most firms have had something. A phishing attack that succeeded. A near-miss ransomware incident. A data exposure that was quietly contained. The issue isn't that incidents happened — it's whether they were properly documented, disclosed, and remediated. A firm that experienced a breach and has a documented response, lessons learned, and improved controls is actually in better shape than a firm that's never been tested and has no incident response capability at all.
What you're really evaluating is the security culture. If the firm can't produce documentation of any security program, doesn't have basic controls like multi-factor authentication, and can't answer fundamental questions about how they protect client data — you're inheriting a security liability. And in an era where clients are sending security questionnaires and cyber insurers are requiring attestations, that liability has real dollar consequences.
Red Flag #5: No Documentation Trail
If I had to sum up the single biggest predictor of a painful technology integration, it would be documentation. Or, more accurately, the lack of it.
Firms that are ready for a smooth transaction have clean records: organized technology budgets with proper categorization, a current inventory of all hardware and software, contract files with expiration dates and terms, and an understanding of their cost per user. They know what they're spending and why.
Firms that aren't ready have expenses scattered across credit cards and office budgets, software that nobody knows the firm is paying for, contracts buried in someone's email, and hardware that IT hasn't inventoried in years. When you encounter this, everything takes longer. Integration planning can't start until you've completed a discovery process that the seller should have been able to hand you on day one.
Think of it like buying a house. If the seller has organized records of every repair, appliance warranty, and maintenance schedule, you feel confident about what you're buying. If they hand you a box of random receipts and say "it's all in there somewhere," you're going to find surprises after you move in. The same principle applies to technology due diligence.
For Sellers: The Other Side of the Table
If your firm is considering being acquired — or if you're trying to build toward an exit — every one of these red flags is something you can fix proactively. Clean up your documentation. Organize your budget. Renegotiate unfavorable contracts while you still have time. Replace aging infrastructure before it becomes the acquirer's problem.
The technology equivalent of staging a house before you sell it is having organized, transparent documentation of everything you spend, everything you own, and everything under contract. A firm that presents a clean technology picture signals operational maturity — and that translates directly to smoother diligence, faster closes, and better deal terms.
Let’s talk