M&A due diligence checklists have entire sections for financials, culture, and legal exposure. Almost none of them have a real answer to a much simpler question: what's actually still running on the servers we just acquired — and has anyone ever properly erased what came before them?

In September 2016, Marriott International closed one of the largest hotel acquisitions in history, absorbing Starwood Hotels & Resorts and, with it, eleven new brands, hundreds of thousands of employees, and a reservation system that had been quietly compromised by an unknown intruder since 2014 — two full years before Marriott ever signed the deal. Nobody involved in the acquisition knew it at the time. The breach sat there, undiscovered, through the entire due diligence process, through the deal closing, and through nearly two more years of Marriott running Starwood's legacy IT infrastructure largely as-is. Full technical integration of an acquisition that size takes time, and Starwood's reservation system was one of the pieces Marriott hadn't gotten around to replacing yet.
Marriott finally discovered the intrusion in September 2018, when an internal security tool flagged unusual database activity. By the time the investigation wrapped, the numbers were staggering: roughly 500 million guest records exposed, including passport numbers for 327 million individuals, spanning reservation data that had been sitting on that legacy system the entire time.
The UK's Information Commissioner's Office (ICO) opened an investigation, initially signaling an intent to fine Marriott £99.2 million — later adjusted to £18.4 million after representations, but still one of the largest GDPR enforcement actions of its era. And the regulator's reasoning is the single most important detail in this entire story: the ICO wasn't primarily punishing Marriott for what happened on Starwood's watch before the acquisition. It was punishing Marriott for what happened after the deal closed — specifically, for continuing to run legacy Starwood infrastructure without adequately assessing what was on it, securing it, or replacing it, for roughly two years after inheriting it.
Marriott's own defense was that "acquisition due diligence is not a seemingly endless process" — an understandable position from a company that had just absorbed an entire competitor's global IT footprint overnight.
The regulator's verdict: That may be true, but the legal obligation to know what data you are responsible for, and to protect or sanitize it, does not expire simply because an integration project is complicated.
If your organization has acquired another company in the last two years, could anyone on your IT, compliance, or security team tell you, right now, exactly which of the acquired company's servers, databases, and employee laptops are still running on old infrastructure that has never been properly audited, sanitized, or decommissioned?
It's worth separating this problem into two distinct risks, because they get treated as one issue in most standard M&A playbooks, even though they operate on completely different timelines.
The Marriott scenario: data, active backdoors, or dormant vulnerabilities that already existed inside the target company before the deal closed. The acquirer now owns them legally and operationally.
The quieter, slower risk created after the deal closes. Redundant servers, duplicate SaaS tools, and orphaned storage units that pile up when nobody finishes the unglamorous work of sanitizing and retiring what's obsolete.
Both risks point at the same underlying gap: M&A due diligence and post-merger integration planning are built around financial models, legal structure, culture, and synergy milestones. Data disposition — figuring out what old systems and hardware need to be sanitized, verified, or destroyed — sits at the very bottom of the checklist, if it appears at all.
It would be easy to read the Marriott case as a story about corporate carelessness. It isn't. Marriott is a sophisticated, well-resourced global enterprise. The gap didn't come from indifference — it came from the structural mismatch between how M&A timelines work and how deep technical security audits must go.
Due diligence occurs under intense time constraints and confidentiality restrictions. A buyer cannot dispatch a team to audit every server rack or employee laptop closet before signing. Consequently, true technical reality only emerges after the ink is dry — precisely when leadership attention pivots to organizational restructuring, brand consolidation, and customer retention. Decommissioning legacy servers becomes an item for "Phase Two," and in many companies, Phase Two never actually arrives.
Result: Each department handles its slice competently, yet the holistic task of "find every inherited system and verify standardized erasure" belongs to everyone collectively and to no one individually.
Global data privacy regulators have made it clear: they do not grade on a curve for corporate complexity. Under GDPR Article 5(1)(f) (integrity and confidentiality) and Article 32 (security of processing), an organization is held strictly accountable for any data it retains, regardless of whether that data was collected organically or absorbed through a corporate acquisition closed eighteen months earlier.
This pattern is not isolated to hospitality. The 2022 merger bringing Change Healthcare into UnitedHealth Group's ecosystem was followed by a catastrophic ransomware event affecting over 100 million individuals, in an environment where complex, multi-entity legacy IT integrations formed the backdrop. Frameworks like the HIPAA Security Rule,FTC Safeguards Rule, and banking regulations enforce the exact same standard: there is no regulatory exemption for "we are still integrating."
The same vulnerability emerges in reverse when an organization spins off a subsidiary or sells a business division. Divestitures typically rely on Transition Services Agreements (TSAs), where the seller provides shared IT infrastructure for 6 to 24 months while the buyer builds independent capacity.
This in-between period is where severe compliance cracks form:
When a data incident occurs during or after a TSA period, "the transition was still underway" does not satisfy regulatory inquiries. A TSA without verified, tamper-proof erasure records is simply an open invitation to litigation.
If your company completed an acquisition, merger, or major divestiture in the past 24 months, ask your IT leadership these three questions:
Ask for a current, comprehensive inventory of every server, database, and laptop inherited from the acquired entity — an actual serial-tracked list, not a ballpark estimate.
Ask how many of those systems have undergone formal data sanitization or security assessments since deal close, versus how many are running simply because nobody turned them off.
Ask whether there is a dated decommissioning schedule with verified erasure records, or if "we will get to it during phase two" is the working plan.
If question three produces a shrug, you have pinpointed the exact vulnerability that resulted in Marriott's £18.4 million regulatory fine.
Review these 4 criteria with your integration director, IT asset manager, and data protection officer:
Exemplary posture. Your integration program is far ahead of standard industry averages.
Actionable gaps exist in tracking and retiring inherited infrastructure. Decommissioning plan required.
Critical inherited risk. Your company is likely harboring unmonitored zombie systems holding sensitive customer data.
To eliminate the legacy system erasure gap permanently, forward-thinking enterprises deploy a structured 7-pillar framework:
Treat inventory creation as an independent workstream with its own hard deadline, cataloging every acquired server, laptop, and data volume.
Separate operational uptime goals from decommissioning duties. The engineer tasked with keeping systems running cannot be the sole champion for turning them off.
Apply the same zero-trust validation to legacy systems that you would apply to an unverified third-party appliance.
Replace open-ended 'during integration' milestones with contractual retirement dates to prevent zombie systems from lingering for years.
Ensure every retired drive, SSD, or virtual instance is purged using software compliant with NIST 800-88 Rev. 1/2 or IEEE 2883-2022, generating tamper-proof audit trails.
Dormant legacy databases are high-value targets. Maintain active threat telemetry until the final sanitization certificate is generated.
Integrate secure sanitization protocols into deal milestones alongside legal reviews, tax structure, and HR integration.
The core lesson of the Marriott breach is not that M&A is inherently perilous or that due diligence must be infinite. The lesson is simpler and more operational: regulatory accountability does not pause while you integrate. Every day an unassessed legacy server stays connected, legal liability compounds.
Every corporate deal brings home more than financial balance sheets and intellectual property. It brings home someone else's old servers, outdated endpoints, and untracked databases. Organizations that avoid becoming headline case studies are those that pair deal closing with an automated, verified data erasure pipeline.
Transform "we'll get to it during integration" into automated, verifiable, serialized erasure reports that satisfy global privacy regulators.
Explore the full D-Secure data security suite
Meeting NIST 800-88 and GDPR standards with full audit trails.
Scalable solutions for ITAD partners and large organizations.
Trusted by global enterprises for zero-leakage data sanitization.
Your email address will not be published. Providing an email is optional.
Send us an enquiry regarding: Marriott Bought a Hotel Chain. It Also Bought a Breach That Had Already Been Running for Two Years.
No comments yet. Be the first to comment.