TREADSTONE LAW · ONTARIO · DIGITAL LEGAL SERVICES · EST. MMXXI ·TSL
Home/Case Studies/Mergers & Acquisitions
№ 295 Case Study — Mergers & Acquisitions

Her own incident log told a different story than the one she gave us

A Petawawa records-management founder described a minor system glitch, but the incident log her buyer's diligence team turned up told a longer, messier story that had to be resolved before closing could happen.

Mergers & Acquisitions9 min readPetawawa, OntarioCybersecurity diligence
All Mergers & Acquisitions case studies
ClientYing, selling the records-management company she built in Petawawa
The issueYing's own incident logs contradicted the account she had given the buyer of a past data security event
ServiceRebuilt the incident response disclosure and negotiated it into a closing condition both sides could accept
ResolutionClear win — the deal closed with the incident properly disclosed and priced in

The situation

Ying and Feng had built the company together before Feng stepped back to focus on his real estate practice, but he stayed close through the sale process, sitting in on calls as the person Ying trusted to tell her when something did not sound right. It was Feng who first flagged, three months into the diligence process for the sale of Ying's Petawawa records-management company, that the story Ying was telling the buyer's team about a security incident two years earlier did not quite match what he remembered from the time it happened.

Ngozi, Ying's older sister and a librarian with three decades spent building institutional archives, had no role in the deal itself, but her reaction when Feng mentioned his unease over dinner changed how Ying approached the problem. A librarian's instinct is that memory and record are never the same thing, and that whichever is more convenient to believe is usually the less reliable one. Ngozi told her sister plainly that if the company had kept any contemporaneous record, that record was the only account worth trusting.

The company managed physical and digital records for a range of municipal and small-business clients across the region, a business built on trust that data would stay confidential and available, and that trust was exactly what the buyer, a mid-sized document management firm looking to expand into eastern Ontario, was paying for in a deal valued in the fifteen to thirty million dollar range. Cybersecurity diligence on a records business of this kind is not a formality. It is close to the center of what the buyer is actually acquiring.

Ying had disclosed, early in diligence, that the company experienced a security event roughly two years earlier involving unauthorized access to a client file server, which she described as contained quickly, affecting a limited number of records, with no confirmed data loss. That description became the basis for the buyer's initial risk assessment and, implicitly, for how much diligence attention the incident received afterward.

The problem surfaced when the buyer's technical team requested the underlying incident response documentation as a matter of routine completeness, expecting to close the file. What came back from Ying's own systems, an internal incident log her IT contractor had kept at the time, described a longer window of unauthorized access, a broader set of affected records than Ying had disclosed, and a response that had been slower and less structured than her account suggested. Ying had not lied deliberately. Her memory of a stressful event two years old had simply smoothed itself into a cleaner story than her own records supported, and now the gap between the two was sitting in front of a buyer's legal team.

The risk we had to size

The immediate risk was obvious: a material discrepancy between what a seller represents during diligence and what the seller's own documents show can be treated by a buyer as a red flag serious enough to walk away from a deal, or at minimum to demand a steep discount and an indemnity structure that would follow Ying long after closing. Buyers do not need to prove bad faith to react badly to this kind of gap; an inconsistency alone raises the question of what else might not match, and that question can poison an otherwise sound deal.

There was also a distinct regulatory layer underneath the commercial one. Federal privacy legislation requires an organization that suffers a breach creating a real risk of significant harm to notify the affected individuals and to report the breach to the federal Privacy Commissioner, and to notify other organizations that may be able to reduce the harm. A record of every breach must be kept regardless of whether it meets that threshold. Which version was accurate mattered to that compliance question too, not just to the buyer's diligence.

We had to size two separate things before we could respond to the buyer. First, what had actually happened during the original incident, stripped of both Ying's smoothed-over account and the buyer's worst assumptions. Second, whether the gap between the two accounts was a matter of imprecise memory, which is common and manageable, or something closer to a genuine concealment, which would be a very different problem requiring a very different response.

Working from the incident log itself, along with the IT contractor's contemporaneous notes and correspondence with the affected clients at the time, we reconstructed a fuller picture. The unauthorized access had in fact lasted longer than Ying recalled, closer to several days than the hours she had described, and had touched a broader set of client files. But the contractor's notes also showed the company had notified every affected client individually at the time, retained a specialist to confirm no data had actually been exfiltrated, and implemented new access controls afterward, none of which Ying had mentioned because she had folded the whole episode into a single sentence rather than walking through what the response actually involved.

That distinction mattered enormously. A seller who understated the scope of an incident but had, in fact, handled it responsibly at the time, with proper notification and remediation, was in a fundamentally different position than one who had covered up a serious lapse. Our job was to establish the first version credibly, with documentation the buyer could verify independently, before the discrepancy hardened into the buyer's assumption that Ying could not be trusted on anything else in the file.

What we did

  1. Pulled every contemporaneous record of the original incident, including the IT contractor's log, client notification emails, and the specialist's post-incident report, before responding to the buyer at all, because we needed a version of events built entirely from documents rather than from Ying's recollection, which had already proven unreliable on the specifics of what happened and how long it took to contain. Ngozi's advice to trust the record over the memory of it, relayed to us through Feng, became the operating principle for the entire reconstruction.
  2. Built a day-by-day timeline from those documents alone, cross-checking the contractor's log against the client notification emails to confirm the dates lined up, so that when we eventually presented the corrected account to the buyer, every claim in it traced back to a document the buyer's own technical team could independently verify rather than to Ying's word alone, which was the whole point of building it this way in the first place.
  3. Met with Ying and Feng separately from the buyer negotiations to walk through the reconstructed timeline in detail and confirm there was nothing further in the record that had not yet surfaced, since a second discrepancy discovered later, after the first had already been corrected, would have been far more damaging to Ying's credibility than getting the full picture out in one pass. Ngozi joined that meeting by phone and pressed hardest on whether every backup and old invoice had actually been searched.
  4. Proactively disclosed the corrected account to the buyer's counsel before they raised the discrepancy themselves, framing it in writing as a correction to an imprecise earlier description rather than waiting to be confronted with the contractor's log, which materially changed how the buyer's deal team received the news and kept the whole conversation collaborative rather than adversarial from the very outset of that exchange.
  5. Provided the underlying documentation directly, rather than a narrative summary written by us, so the buyer's technical team could verify independently that the company had in fact notified affected clients and remediated the access controls at the time, which supported the case that this was an honest disclosure gap rather than a deliberate cover-up of a more serious failure.
  6. Negotiated a specific incident response representation into the purchase agreement describing the corrected timeline precisely, scope, duration and remediation steps included, so the buyer's reliance going forward was on an accurate account rather than the original understated one, closing off any later argument that the representation itself had been false or incomplete in some further respect the buyer had not yet found.
  7. Built a closing condition around a limited follow-up technical review, giving the buyer's security team a defined two-week window to independently verify that the access controls implemented after the original incident remained in place and effective, satisfying their need for real, independent assurance without reopening the entire diligence process from the very beginning of the file all over again.
  8. Adjusted the indemnity structure to include a specific, capped provision addressing the originally undisclosed scope of the incident, giving the buyer a defined remedy if the corrected account still proved incomplete in some way not yet discovered, while keeping Ying's overall exposure bounded rather than open-ended against a past event that was already priced into the deal by the time closing arrived.

The outcome

The buyer's team, after reviewing the documentation and completing the follow-up technical review, accepted the corrected account and proceeded to closing on the original timeline, with the specific representation and capped indemnity provision in place. The deal did not reprice on the broader points already negotiated, though the negotiation of the incident-specific indemnity took roughly three additional weeks that a clean disclosure from the outset would not have required, weeks that added real pressure to an already tight closing schedule.

What made the difference was less the legal drafting itself than the sequence in which things happened: getting the full, document-backed account in front of the buyer before they found it themselves reframed the entire conversation from a credibility problem into an administrative correction. A buyer who catches a seller in a contradiction during its own review reacts very differently than one who receives a voluntary correction accompanied by the underlying documents, even when the underlying facts are identical in both scenarios. Ying's willingness to let the documents speak for themselves, once Feng had pushed her to look at them properly rather than repeat her memory of events, was what kept the deal on track through what could easily have become a deal-ending dispute.

The indemnity provision negotiated around the incident remained in place after closing, giving the buyer a defined, capped remedy rather than an open-ended one, and no claim has been made under it. Ying closed the sale and has since told the story to other founders going through diligence as a caution about relying on memory for anything that touches a security incident, no matter how confident that memory feels at the time it is being described.

Feng's instinct to check her account against what he remembered from when the incident actually happened, rather than accept the smoothed-over version she had settled into telling, is the reason the discrepancy surfaced on their own terms rather than the buyer's, and Ying credits that instinct with saving a deal that a less careful review would have put at real risk. Ngozi never looked at the purchase agreement or spoke with the buyer's counsel, yet her insistence on trusting the record over the memory of it is the reason the whole file was rebuilt from documents rather than recollection.

What you can learn from this

  • When diligence turns up a discrepancy between a seller's account and the seller's own records, disclosing the correction proactively is almost always better than waiting for the buyer to find it.
  • Memory of a stressful past event tends to smooth into a cleaner story than the contemporaneous records support; check recollections against documentation before repeating them to a counterparty.
  • A seller who understated an incident but responded to it properly at the time is in a very different position than one who concealed a real failure; establishing which one applies changes the entire negotiation.
  • An inconsistency alone, even without bad faith, can lead a buyer to question everything else in a diligence file; the cost of a credibility gap is rarely limited to the specific issue that caused it.
  • A capped, incident-specific indemnity can resolve a disclosure gap without reopening the whole deal, giving the buyer a defined remedy while keeping the seller's exposure bounded.
This case study is entirely fictional. It does not describe any real client, file, or matter handled by Treadstone Law, and it is not a real file with details changed. All names, people, properties, businesses, dollar amounts, dates, and events are invented, and any resemblance to a real person, business, or situation is coincidental. Fictional scenarios like this one illustrate the kinds of legal issues people in Ontario commonly face and how a lawyer can help. They are general information, not legal advice — no two matters unfold the same way, and nothing here predicts the outcome of any real case. Reading a case study does not create a lawyer-client relationship. If you are facing something similar, speak with a lawyer about your specific circumstances.

This is a mergers & acquisitions problem we handle

Start a file online — flat, published fees, reviewed by a licensed lawyer before a dollar is owed.

ContactStart a File →