Back to Blog

R&W Insurance or Price Reduction? How to Use a Quantified Cyber Number at the Negotiating Table

They picked R&W. Eighteen months later, the known-findings carve-out did exactly what those carve-outs always do. Here's when each commercial option actually works.

Quick Answer

They picked R&W. Eighteen months later, the known-findings carve-out did exactly what those carve-outs always do. Here's when each commercial option actually works.

The deal team got the cyber report on Friday. By Monday they had to decide: push for a price cut, demand an escrow, or rely on the R&W policy. They picked R&W. Eighteen months later, the carve-out for "known security findings" turned out to do exactly what those carve-outs always do.

Representations and Warranties (R&W) insurance is a deal-specific policy that covers an acquirer if the seller turns out to have misrepresented something material in the purchase agreement — financials, litigation, contracts, or increasingly, cybersecurity posture. It's designed to bridge a fundamental M&A tension: the seller wants a clean exit with no lingering indemnification obligations; the buyer wants recourse if something was wrong at close. R&W hands that indemnification obligation to an insurer rather than leaving it as a dispute between buyer and seller. For PE deal teams specifically, it's become near-standard on mid-market buyouts because it makes the seller whole at close while preserving the buyer's ability to recover losses post-close without suing the seller directly.

The R&W insurance decision in M&A is almost always made under time pressure, with incomplete information, by people who haven't read the policy exclusions carefully enough. That combination produces claims denials that feel like surprises but are, in retrospect, entirely predictable.

The right framework for choosing between R&W insurance, purchase price adjustment, and escrow depends on one thing: whether you have a quantified number. Without a number, none of the three options can be negotiated effectively. With a number, the choice between them follows from the specific facts of the deal.

68%
of R&W claims related to cybersecurity are denied or reduced on known-findings grounds (AIG M&A Claims Report, 2024)
$3.2M
average cyber-related M&A claim filed against R&W policies (AIG, 2024)
34%
of PE acquirers use escrow for cyber findings vs. 19% who use price adjustment (Marsh McLennan, 2024)
12 months
typical R&W survival period for non-fundamental reps — often shorter than post-close breach discovery (Willis Towers Watson, 2024)

The three options explained

Option
How It Works
Best For
Purchase Price Adjustment
Reduce the agreed purchase price by the quantified cyber risk amount. Risk transfers permanently to buyer at close.
Competitive deals where escrow demand would kill the deal; material findings with clean remediation path
Remediation Escrow
Hold a portion of proceeds in escrow. Released to seller when specific remediation milestones are verified post-close.
Findings with defined remediation cost and timeline; seller is motivated to fix quickly
R&W Insurance
Policy covers seller breaches of representations. Cyber reps typically have broad carve-outs for known findings.
Unknown risks you can't quantify at close; supplement to — not replacement for — price adjustment or escrow

The crucial distinction: R&W insurance is not a substitute for price adjustment or escrow when findings are known at close. The policy is designed for unknown risks — things that weren't discoverable in due diligence. When you've run a quantitative cyber diligence assessment and documented findings in a CCOD, those findings are by definition known. The policy will say so.

The known-findings carve-out: why it always does what it does

Every R&W policy covering cybersecurity representations includes some version of this exclusion: claims arising from "known" or "specifically identified" security findings are not covered. The definition of "known" is broader than most buyers realize at signing.

How Courts Define 'Known'

In practice, "known" in an R&W cyber claim means: if the finding was documented anywhere in the due diligence process — the target's data room, the buyer's assessment report, management interview notes, even email threads between deal team members — it is "known." The carve-out doesn't require that the buyer flagged it as material. Documentation of the finding is sufficient to establish knowledge, which is sufficient to deny the claim.

This means the standard QCD assessment — which documents every finding in detail — creates the very paper trail that voids the R&W coverage for those findings. You can't run thorough cyber due diligence and then rely on R&W to cover the things you found. You've already converted those unknown risks into known risks by the act of documenting them.

The R&W policy is still valuable — for the things you didn't find. A breach that originates from an undiscovered vulnerability, a regulatory investigation that stems from pre-close conduct that wasn't visible in the data room, a third-party claim arising from an incident you had no way to identify. These are the scenarios R&W covers. The scenarios you documented in the CCOD are not.

When to push for price reduction

A purchase price adjustment is the cleanest transfer mechanism when the commercial context supports it. The cyber risk becomes a permanent component of the valuation — no escrow account to administer, no milestone verification process, no post-close relationship friction.

Price Reduction Is Right When

The deal is competitive and a significant escrow demand would drive the seller to another bidder. The findings have defined financial exposure that can be cleanly expressed as a valuation haircut. The seller's counsel is unlikely to accept escrow on these findings specifically. The remediation timeline extends beyond the typical escrow release window (90–180 days).

The negotiation mechanics: you need the CCOD number before you can negotiate a price adjustment. Without a quantified number, the seller's counsel will challenge any proposed reduction as arbitrary. With a CCOD built from published benchmarks and independently verified remediation costs, you have a defensible basis for the specific dollar amount.

A typical negotiation: buyer presents CCOD of $736K with $238K remediation cost. Seller counters that the findings are "manageable" and offers $150K price adjustment. Buyer accepts $200K, which represents the remediation cost plus a partial risk premium. Both sides have a number they can defend to their respective principals.

When escrow is the right tool

Escrow aligns incentives better than price adjustment when the remediation is well-defined and the seller is motivated to complete it quickly. The seller gets the full proceeds — minus the escrow amount — and recovers the escrowed funds when milestones are hit. This preserves the deal economics for a seller who wants to argue the findings will be fixed promptly.

Define the milestone precisely

The escrow release condition must be specific and independently verifiable. "Complete MFA deployment" is specific. "Improve security posture" is not. Milestone: third-party audit confirms MFA enforced on 100% of production system access, zero exceptions.

Set the timeline based on remediation reality

90-day escrow windows are standard but often too short for complex remediation. Use the vendor quotes and project timeline from the QCD assessment — not an optimistic estimate — to set the release window.

Specify the verification mechanism

Who verifies completion? Buyer-selected third party is standard. Seller's internal attestation is not sufficient. Build the verification cost into the deal structure.

Address partial completion

What happens if the seller completes 70% of the remediation by the deadline? Define in advance whether partial release is available and at what thresholds.

Carve out the known-findings rep

If you're using escrow for specific cyber findings, the R&W policy should explicitly exclude those findings from the cyber rep. Leaving them in creates an overlap that both the insurer and the seller's counsel will exploit.

When R&W actually helps

R&W insurance for cyber is most valuable as a supplement to quantitative diligence, not a replacement for it. Here's what it's actually covering:

Pre-close breaches you couldn't find: an attacker compromised production systems three months before LOI and the access isn't visible in any log you could review. A claim surfaces post-close. The R&W policy — if the breach is genuinely undiscoverable — may cover this.

Regulatory investigations from pre-close conduct: a regulator opens an investigation into data handling practices from before close that weren't visible in the data room. This is classic R&W territory if the specific conduct wasn't documented in due diligence.

Misrepresentations about controls: the target certified in the reps that MFA was deployed on all production systems. Post-close, you discover it wasn't. If this wasn't in your assessment (because the target actively misrepresented it), R&W covers the resulting loss.

The R&W Stack

The sophisticated buyer uses all three mechanisms: R&W for the unknown risks; escrow for the known, remediable findings with defined costs; and price adjustment for the known findings that don't fit the escrow timeline or where competitive pressure precludes escrow. The CCOD quantifies the known-risk bucket. R&W handles the residual unknown-risk bucket. The policy limit for cyber should be set to reflect only the unknown-risk exposure — not the total CCOD.

How the CCOD number changes the negotiation

Every commercial option above requires a quantified number to work. Without it:

Price adjustment: "We want a discount for cyber risk" produces "How much?" which produces "We're not sure" which produces "Then no." The negotiation stalls at the first question.

Escrow: "We want $X in escrow for the cyber findings" requires knowing what X is. If X is calculated from a documented CCOD, the seller's counsel can challenge the methodology but not the existence of the number. If X is a guess, they challenge the guess.

R&W: "The policy limit should reflect cyber risk" requires knowing how much of the cyber risk is known (covered by escrow or price adjustment) and how much is unknown (covered by R&W). Without a CCOD, you can't do this split — and you end up buying R&W coverage for risk you've already quantified and addressed through other mechanisms.

The CCOD isn't just an IC document. It's the foundation of the entire post-LOI commercial strategy. For a worked example of how the CCOD is built — five pillars, ALE calculations, and the IC slide — see Inside a Cyber Cost of Deal: A Worked Example for Investment Committee.

Practical checklist before the commercial decision

Before You Choose a Mechanism

1. Is the CCOD complete and signed off by the deal partner? If no — don't choose yet.
2. Are all material findings documented in writing? If yes — R&W won't cover them. Price them into escrow or adjustment.
3. Does each finding have a defined remediation plan with vendor quotes? If yes — escrow is viable. If no — price adjustment is cleaner.
4. Is the deal competitive enough that escrow demand creates deal risk? If yes — price adjustment with R&W supplement is the path.
5. Has the R&W policy been reviewed for the specific cyber exclusions that apply to your documented findings? If no — review before signing anything.

For the deal-team process that builds the CCOD before you reach this decision point, see The PE Buyer's Playbook for Cyber Due Diligence: From LOI to IC.

Get the number that makes the negotiation possible

Every commercial option in this article — price adjustment, escrow, R&W — requires a defensible CCOD before it can be negotiated. vCISO Lite's Quantitative Cyber Diligence platform produces that number: five-pillar ALE calculations, the finding-to-rep mapping for your R&W application, and the escrow milestone structure, all from a single assessment workflow.

If you're a deal team, M&A advisor, or R&W broker who needs a quantified cyber number before the commercial negotiation closes, visit diligence.vcisolite.com to learn more and get started.

Share this article:

Ready to build your security program?

See how easy it can be.