Contact Deutsch

ISiCO GmbH
Skip navigation
  • Privacy

    Get a head start with our optimal data protection consultancy

    Secure your competitive advantage with our business-focused data protection expertise.

    • Data Protection Consulting
      • Data Protection Impact Assessment (DPIA)
      • Threat Modelling
      • Data Breaches
      • Records of Processing Activities (ROPA)
      • Communication & Procedures with Authorities
      • Employee Data Protection
      • Data Protection Management System
      • Erasure and Archiving Policies
    • External Data Protection Officer
    • Data Protection Audits
    • EU Representative
    • Whistleblower Protection Act
  • IT Security

    Reliable protection for your company

    Make use of our expertise and customised IT security solutions to protect your digital assets.

    • External Information Security Officer (ISO)
    • ISMS
      • ISMS Service Package
      • ISMS Service Package NIS2
      • ISMS Service Package ISO 27001
      • ISMS Service Package TISAX
    • ISO 27001 Certification
    • Ransomware Protection
    • Risk Management
    • IT Compliance
    • NIS2
    • DORA
    • TISAX Certification
    • IT Forensics
    • Cyber Resilience Act
    • Aerospace & Defense
  • AI Consulting

    Gain a competitive edge with the best AI advice

    Secure your competitive advantage with our business-focused AI expertise.

    • ISO 42001 Certification
    • External AI Officer
  • Data Strategy

    Make the most of your data

    We will show you how to unlock the full potential of your company's data.

    • Develop Data Strategy
    • Maturity Assessment
    • Data Governance
    • Data Product
  • Solutions

    We create solutions for all challenges

    Whether you need advice on data protection management, its implementation, or employee training, we can provide the solution you need as part of a corporate network.

    • Downloads
    • Workshops
    • DPO Coaching
    • Privacy Solution Software caralegal
    • E-Learning from lawpilots
  • Company

    Customised, efficient and business-oriented

    ISiCO is one of the top addresses in Germany for management consultancy in data protection, information security, AI and data strategies.

    • About ISiCO
    • Team
    • Offices
    • News
    • Contact
  • Make an appointment

03.09.2026

Share Deal in Aerospace & Defense: Data Valuation, Information Security and ISO 27001

In aerospace and defense, design data, test evidence, maintenance information and supply chain knowledge can be major drivers of enterprise value. At the same time, product approval, delivery capability and aftermarket services depend on the confidentiality, integrity and availability of technical information. Private equity due diligence must therefore combine data rights, information security, ISO 27001, cyber resilience and long-term usability in a single valuation model.

Schedule a no-obligation initial consultation
Your ISiCO-Expert:
Dr Jan Scharfenberg
Partner Information Security, Managing Director

Share deal: continuity of the company, not of data use

From a data protection perspective, a share deal is not a free pass. Although the target company remains the same legal entity and therefore, in principle, remains the controller for its data processing activities, the investor does not automatically acquire its own right of access or use in relation to operational data. Disclosure in the data room, later reporting lines, central platforms or group-wide analyses are already separate processing operations that must be reviewed in terms of purpose, necessity, role model and security.

In the aerospace and defense sector, further limits apply. Technical data may be contractually allocated to the customer, an OEM, an authority or a consortium. They may be subject to confidentiality levels, export controls, location requirements or special security requirements. A change of control may trigger notification, consent or review obligations outside data protection law. The question of whether the target continues to exist after closing is therefore only the first step, not the answer to whether its data can be used.

No automatic group access

Neither the PE sponsor nor other portfolio companies receive blanket access to technical or personal data after closing. Reporting, central security services, shared data platforms and cross-border support models must be structured separately. New connections may also change the ISMS context, the risk assessment and the certified scope.

Information security Is part of product and delivery capability

For technical data, confidentiality is only one dimension. Incorrect versions, manipulated parameters, incomplete change histories or unavailable PLM, test and maintenance systems can impair approval evidence, production decisions and safe maintenance. Data integrity and availability are therefore directly linked to revenue, liability risk and delivery capability.

Information security due diligence must look at office IT, engineering networks, development and test environments, production and OT-adjacent systems, remote maintenance, cloud services and supplier access together. An attacker or flawed privileged access can not only steal data, but also change configurations, delay development programmes or make it harder to resume operations.

Security failure = value loss

In aerospace and defense, a security incident can affect data value, production capability, customer trust and programme timelines at the same time. Cyber resilience and operational resilience are therefore not secondary conditions, but components of the investment case and data valuation.

Which data assets drive enterprise value

Sector-specific data asset valuation should capture technical, operational and regulatory evidence separately. The following are particularly relevant:

  • Design, CAD, PLM and configuration data, including versions and change history.
  • Test, qualification, certification and evidence data with robust traceability.
  • Digital twins, simulation models and engineering libraries.
  • Maintenance, MRO, reliability and condition data for predictive maintenance.
  • Supplier, material, quality and serial number data along the supply chain.
  • Security, incident and vulnerability data, as well as information on cyber resilience.
  • Contractual and rights information that determines whether and how data may be reused or disclosed to third parties.

The value of data increases with uniqueness, reliability, long-term utility and direct connection to revenue or cost savings. It decreases when files exist without context, rights labelling, version history or technical readability. For long-running platforms, it is also crucial whether data remain migratable and traceable over decades.

Risk areas in M&A due diligence

Risk area Typical issue Impact on valuation
Rights and restrictions Technical data may be used only for a specific programme, customer or jurisdiction. Synergies and data monetisation may fall away; the addressable market becomes smaller.
Data integrity Changes, test conditions or serial-number references are not documented without gaps. Evidence must be reconstructed; certification and liability risks increase.
Cybersecurity Legacy systems, external remote maintenance, unclear privileged accounts or unpatched environments. Immediate investment, business interruption and potential incident consequences reduce enterprise value.
Data residency and access Cloud, support or adviser access conflicts with location or security requirements. Planned platform synergies can only be realised to a limited extent or with additional costs.
Supply chain Data originate from suppliers whose rights, security and availability are not adequately safeguarded. Third-party risk and dependency increase the risk discount.
Obsolescence Proprietary formats, old PLM systems or missing documentation make migration and long-term archiving more difficult. High replacement cost and extended integration timelines.
ISMS scope The ISO 27001 certification covers only office IT or individual sites; engineering, test labs, OT-adjacent systems or critical suppliers are excluded. The claimed security maturity does not cover the value-bearing data assets; scope expansion and remediation make integration more expensive.

Cyber due diligence is a value review, not just compliance

In this sector, a security weakness can directly destroy data value. This affects not only personal data, but also trade secrets, technical specifications and operational systems. Cybersecurity due diligence should therefore look at identities, privileged access, segmentation, vulnerability management, supplier access, backup, restart capability and incident history together.

It is particularly telling whether the target knows its critical data classes and actually controls access accordingly. A formal data governance framework without technical enforcement offers little protection. Conversely, clear classification with robust logging can strengthen digital trust and therefore the seller’s negotiating position.

Reviewing ISO/IEC 27001: scope, effectiveness and sector-specific gaps

ISO/IEC 27001:2022 provides a risk-based framework for an information security management system. In M&A due diligence, however, the certificate is only the starting point. The review must determine whether the scope includes the relevant entities, sites, engineering networks, PLM and lifecycle systems, test environments, cloud services and service processes. A clean office scope says little about the security of value-bearing technical data assets.

In addition, customer, programme, confidentiality, export, location or other sectoral requirements may go beyond ISO 27001. Due diligence should therefore reconcile the ISMS with the specific data classes, contracts and operating conditions. Relevant evidence includes, in particular, risk analysis, Statement of Applicability, risk treatment, internal audits, management review, corrective actions, vulnerability management, incident response, restart and restore tests, and the management of critical suppliers.

ISO 27001 review area Expected evidence Relevance for data valuation
Scope and boundaries Sites, engineering, test, production, service and cloud environments within the scope. Core systems outside the scope increase remediation, integration time and outage risk.
Classification and access Data classes, roles, segregation, privileged access, encryption and logging. Effective controls protect IP, traceability and permissible use options.
Vulnerability and incident Patch and exception processes, monitoring, incident history, exercises and lessons learned. Open vulnerabilities and untested response increase incident and operational risk.
Supply chain and remote access Critical providers, security requirements, remote access, sub-processors and exit rules. Third-party risk can dominate product, service and restart costs.
Continuity and improvement Backups, restore tests, restart objectives, audits, management review and corrective actions. Demonstrated resilience reduces outage discounts and protects long-term data availability.


Integration Rule

No automatic network or identity coupling on day 1. Technical integration should be approved only once data flows, privileged access, segmentation, critical vulnerabilities, recovery and sectoral restrictions have been assessed.

Data protection in the data room: less Is more

Even in a pure share deal, disclosure in the data room remains a separate review point. Personal data may be contained in maintenance reports, incident tickets, access logs, supplier contacts or test documentation. For the investment decision, aggregated maturity metrics, anonymised incident statistics, system lists and samples are usually sufficient. Names, access credentials, operational network details or complete security-critical documents should not be disclosed broadly.

  • Multi-stage data room with sector-specific approval levels.
  • Clean team for particularly sensitive technical, competitive or security-relevant information.
  • No operational credentials, secrets or exploitable attack information in the data room.
  • Traceable logging, download restrictions and erasure if the process is aborted.
  • Separate review of cross-border access and of the groups of persons on the investor side.
  • Provide the ISO certificate, scope, high-level Statement of Applicability information and audit status in a controlled manner; detailed vulnerability or attack information only through the clean team.

Opportunities: data as an engineering and aftermarket lever

If technical data are properly controlled, significant opportunities arise. Digital twins and linked lifecycle data can shorten development cycles, focus testing efforts and make changes more traceable. MRO and condition data enable predictive maintenance, better spare parts planning and new service offerings. Supply chain and quality data can reduce scrap, downtime and procurement risks.

The central value-creation lever is enterprise data governance: consistent classification, data lineage, clear data ownership, defined exchange formats and tiered security controls. These foundations not only increase operational efficiency. They also create the conditions for responsibly using data for simulation, analytics and AI governance. A robust ISO 27001 scope can also accelerate customer assessments, supplier qualification and the integration of new sites. The value lies in demonstrable control of risks, not in the certificate alone.

Optionality has value

A robust technical dataset creates strategic options: new services, faster approval and proposal processes, better reliability models or more efficient portfolio consolidation. This optionality may be valued, but only if rights, data quality and security actually allow the data to be used.

Data valuation: from gross value to risk-adjusted value

Income approach

The income-based approach values additional cash flows from maintenance services, higher availability, less scrap, faster development cycles or better proposal quality. For long product lifecycles, realistic useful lives and discounting are particularly important.

Replacement and reproduction cost

For test series, operating data and engineering libraries curated over many years, the effort required to collect the data again may be enormous. However, the cost approach must take into account whether reproduction would be technically, practically and legally possible at all. Non-repeatable data can have high strategic value.

Rights, security and integrity discount

Costs for rights clearance, reclassification, security remediation, ISMS scope expansion, format migration and traceability reconstruction must be deducted from the gross value. In addition, a risk discount must be applied for cyber incidents, production or service outages, supplier dependency, export and location restrictions, restart deficits or uncertain long-term readability.

Practical valuation logic

Net data value = present value of additional engineering, service and efficiency cash flows + avoided reproduction costs + strategic option value − security, rights-clearance, migration and cleansing costs − risk discount for use restrictions, integrity gaps and third parties.

Review programme for data due diligence and technology due diligence

  1. Which datasets are business-critical for products, certifications, maintenance and delivery capability?
  2. Which classifications, export, location, confidentiality or customer restrictions apply?
  3. Can rights, origin, version, approval and change history be traced for each critical dataset?
  4. Which systems store critical data, how long are they supported and how has restart capability been tested?
  5. Who has privileged access: internally, at the supplier, at the customer or at the cloud and service provider?
  6. Which incidents, vulnerabilities, reportable events or regulatory findings exist?
  7. Which sites, engineering, test, production and service environments are within the scope of the ISO 27001 certification?
  8. Are the Statement of Applicability, risk treatment, audit findings and corrective actions current and aligned with the critical data classes?
  9. When were incident response, backup, restore and restart last tested under realistic conditions?
  10. Which synergies require migration, cross-border access or a shared platform?
  11. Which investments are required to reach the target level for cyber resilience and operational resilience?

The results should be consolidated into a shared governance, risk and compliance view. The investor does not need isolated lists, but a prioritisation: which risks threaten closing, purchase price, ongoing programmes, customer relationships or the planned value creation?

Deal protection and 100-Day plan

In the purchase agreement, known gaps can be addressed through specific warranties, indemnities, covenants and conditions. Relevant statements include those relating to data rights, classification, cyber incidents, critical third parties, completeness of technical documentation and compliance with material security requirements.

  • Day 1: no automatic group, network or identity releases; confirm and log critical access, remote maintenance and privileged accounts.
  • By day 30: create a critical data register with owner, system, protection class, jurisdiction and rights profile; map the ISO 27001 scope, risk register and open findings against the value-bearing environments.
  • By day 60: prioritise and close privileged accounts, external access, critical vulnerabilities, segmentation and backup/recovery gaps; perform a restore test.
  • By day 100: adopt a target picture for PLM, engineering and lifecycle data, as well as the ISMS and ISO 27001 scope, including a migration, integration and long-term archiving plan.
  • Value-creation KPIs: data integrity, traceability, system availability, restore success rate, patch and access-review coverage, open high risks, security maturity and share of usable lifecycle data.

Conclusion: The most valuable dataset is the dataset under control

In an aerospace and defense share deal, data valuation is inseparable from usage rights, data integrity, information security and cybersecurity. The company itself remains in place, but the planned use may be limited by contracts, security requirements, jurisdictions and technical legacy issues. Integrated data due diligence therefore reviews ISO 27001 not as a tick-box exercise, but as an evidence-based ISMS. This makes risks relevant to the purchase price and turns opportunities from engineering efficiency to aftermarket services into robust assumptions.

FAQ: share deal, data protection and data valuation

#1 Why is traditional IT due diligence not enough?

Because the value of technical data depends on more than systems. Rights, classification, traceability, long-term readability, third parties and specific usage restrictions must be assessed together.

#2 May the PE sponsor centrally analyse technical data after closing?

Not automatically. Access must be designed according to roles, purpose, confidentiality, jurisdiction and, where applicable, further sectoral requirements. Particularly sensitive data may have to remain within the target.

#3 How are digital twins valued?

Through expected cash flows and cost savings from development, maintenance and availability, as well as through replacement cost. Rights, quality, security and integration risks are deducted.

#4 Which red flag has the strongest effect on the purchase price?

A critical dataset without traceable rights, versions and traceability, especially where it is indispensable for approval, operation or maintenance.

#5 Is an ISO 27001 certificate sufficient for cyber due diligence?

No. Scope and operational effectiveness are decisive. A certificate may cover office IT while engineering, test, production or service environments are outside the scope. Sectoral and contractual security requirements must also be reviewed.

Back to the news overview

Berlin
Köln
München

Ready for the next step?

+49 30 21300285-0
info@isico.de

Directly to get to know us

 

Outstanding work

ISiCO is also an active member of the German Association for Data Protection and Data Security (GDD) and the German Association for Information Technology, Telecommunications and New Media (Bitkom).

Top-Links
Skip navigation
  • External Data Protection Officer
  • Data Protection Management System
  • Data Strategy
  • Data Breaches
  • ISMS
Find out more
Skip navigation
  • About ISiCO
  • Contact

Language

DE EN

© ISiCO GmbH | Contact | Imprint | Privacy | Privacy Settings