If you carry responsibility for a company, whether as a CEO, an IT manager, or part of the leadership team, two terms are unavoidable: Due Diligence and Due Care. Both sound like legal jargon, but in a real incident they decide whether a breach counts as unavoidable bad luck or as a blameworthy failure. And that difference can mean personal liability.
The trouble is that many explanations blur the two terms or describe them with contradictory memory hooks. This article clears that up. You will learn what Due Care and Due Diligence really mean according to the recognized professional definition (CISSP/(ISC)²), how European and German law demand them (GDPR Article 32, management liability, NIS-2), what the Marriott case actually cost, and you will get a concrete checklist for daily practice.
The short formula first: Due Diligence is knowing, Due Care is doing. Master both and you act with proper care. Neglect either one and you become exposed, technically and legally.
The clean definition: what Due Care and Due Diligence really mean
In cybersecurity the two principles form a matched pair. The most reliable definitions come from the world of the CISSP certification run by the professional body (ISC)², because they are recognized internationally as a reference.
Due Care: actually implementing the reasonable safeguards
Due Care is the act of implementing and maintaining reasonable safeguards in daily operations, in other words the concrete doing. The Official (ISC)² CISSP Study Guide describes it as "using reasonable care to protect the interests of an organization."
In practice this means you deploy security updates, test your backups, restrict administrator rights, train your staff, and respond to incidents. The legal yardstick behind it is the "prudent person rule" (formerly the "prudent man rule"): you act the way a prudent, responsible person would have acted under comparable circumstances. In the United States the equivalent phrase is "reasonable cybersecurity." The Center for Internet Security (CIS) describes it as a deliberately dynamic standard whose reasonableness depends on industry practice, data sensitivity, organization size, available standards, and known threats. There is no single fixed checklist for what counts as "enough." That is exactly why CIS recommends anchoring your program in established, measurable frameworks such as the CIS Critical Security Controls, so that reasonableness becomes documentable.
Due Diligence: continuously verifying that the safeguards are adequate and working
Due Diligence is the control and management function: the ongoing checking, investigating, and steering to ensure that the Due Care measures are actually adequate and truly effective. The Official (ISC)² CISSP Study Guide phrases it as "practicing the activities that maintain the due care effort." This includes audits, risk assessments, vendor reviews, the assessment before a company acquisition (M&A), and the duty to document all of it in a traceable way.
One point that is often missed: Due Diligence relies on explicit, measurable standards (such as ISO 27001, the NIST Cybersecurity Framework, or the BSI IT-Grundschutz), whereas Due Care rests on the more implicit judgment of what is "reasonable." That is why Due Diligence is comparatively easy to prove, while Due Care often has to be defended by argument if it is challenged.
Beware of the circulating memory hooks
Several mnemonics circulate in the literature that seem to contradict one another at first glance. To keep you out of that trap, here is the classification:
- "Do Detect / Do Correct": Some CISSP materials frame Due Diligence as "Do Detect" and Due Care as "Do Correct." That is not wrong, but it is misleading if you read "detect" as a one-off check after an incident. What is meant is the ongoing audit and management function, not a single root cause hunt.
- "Due Diligence as a subcategory of Due Care": A few sources present Due Care as the broader umbrella and Due Diligence merely as a special case for third-party risk. That is a minority view. The majority, and the more robust reading, treat both as equal-rank, complementary principles.
- "Due Diligence as the proof of Due Care": This nuance stresses the duty to document and demonstrate care to stakeholders. It is a useful addition, but it does not replace the main definition.
The safest thing to remember is the robust pairing: Due Diligence is the continuous knowing and controlling, Due Care is the continuous doing.
Due Care vs. Due Diligence side by side
The table below contrasts both principles along the dimensions that matter.
| Dimension | Due Diligence (the knowing) | Due Care (the doing) |
|---|---|---|
| Core question | Are our safeguards adequate and effective? | Are we actually implementing the safeguards? |
| Function | Assess, investigate, steer, evaluate | Implement, operate, maintain |
| Typical activities | Audits, risk assessment, vendor review, M&A review, management review | Patching, backup testing, restricting rights, training, incident handling |
| Timing | Before a decision and continuously as governance | Continuously in day-to-day operations |
| Standard | Explicit, measurable standards (ISO 27001, NIST CSF) | "Prudent person," "reasonable cybersecurity" |
| Provability | Well documentable (reports, assessments) | Must be defended if challenged |
| Owner | Primarily management and governance | Every employee in their own conduct |
Two practical example pairs make the difference tangible:
- Conducting an annual security assessment is Due Diligence. Actually implementing the corrective measures it identifies is Due Care.
- Understanding and evaluating the root cause of a known vulnerability (CVE) is Due Diligence. Deploying the matching patch is Due Care.
Two applications of Due Diligence: the one-off review and the ongoing control
A common misconception is that Due Diligence is only a one-off check before a big decision. In fact it has two faces, and both matter.
Due Diligence before a decision: the M&A and onboarding review
Imagine you are acquiring another company. You want to know whether there are skeletons in the digital closet: outdated systems, open vulnerabilities, unresolved data protection issues. That is classic Due Diligence, a structured, thorough review before you make a decision.
In an IT and security context you check, for example:
- Are sensitive data stored securely and encrypted?
- Is there outdated software or undocumented shadow IT?
- Which third parties have access to systems or data?
- Do security policies exist, and are they actually followed?
Example: A mid-sized company acquires an online shop. The review reveals that the shop system still runs on PHP 5.6, there is no two-factor authentication, and admin accounts were never reset. Without these findings the acquisition could have led straight to a reportable data breach. A structured risk analysis and a security audit are the heart of this kind of Due Diligence. For the methodology behind such an assessment, see our guide to cybersecurity risk analysis.
Ongoing supply chain Due Diligence: the underrated everyday case
For most organizations the second variant is more relevant day to day: the continuous review of your own service providers and suppliers. Every cloud provider, every software supplier, and every external contractor extends your attack surface.
The US agency NIST describes Due Diligence for supply chain risk management in the finalized standard NIST SP 1326 (published in final form on 8 July 2026) as the minimum understanding a customer should have about a supplier. The guide names five assessment factors for a fast initial review:
- Supply Chain Tiers: How many supplier layers sit between you and the actual manufacturer?
- FOCI (Foreign Ownership, Control, or Influence): Is there foreign ownership, control, or influence?
- Provenance: Where do the components and the software come from?
- Resilience: How resistant is the supplier to disruption, and how quickly can it recover after an incident?
- Foundational Cyber Practices: Which basic security practices does the supplier maintain?
Just as important is so-called fourth-party risk, meaning the subcontractors of your own contractors. Anyone accountable for their supply chain should trace that chain as far as possible. Frameworks such as TISAX for the automotive industry or the BSI IT-Grundschutz provide structured assessment frames for exactly this ongoing vendor Due Diligence.
What happens if you neglect one of them?
The two principles interlock. Drop one and you open a gap that will eventually be exploited.
Without Due Diligence: You acquire a company or roll out new software without looking closely. The result is inherited liabilities: outdated systems, undetected vulnerabilities, or data protection risks. When an incident hits, you are exposed, because you should have known.
Without Due Care: You set everything up correctly once, then let it slide. Systems go unpatched, training fades away, an employee clicks a phishing link, and customer data is gone. The accusation is no longer "you did not know," but "you knew and failed to act."
The Marriott/Starwood case, put in factual context
The Marriott/Starwood case is the textbook example of how Due Diligence during an acquisition and Due Care afterwards can both fail.
Marriott acquired the Starwood hotel group in 2016. From as early as July 2014, that is before the acquisition closed, Starwood's reservation system was compromised without anyone noticing. The attack was only discovered in 2018, roughly two years after closing. Across the known incidents between 2014 and 2020, around 344 million people worldwide were affected, most of them (about 339 million records) through the Starwood reservation system. Despite a months-long review of the information security program before the acquisition, the ongoing intrusion went undetected.
When it comes to the financial fallout, precision matters, because there were two separate proceedings in different jurisdictions that must not be merged into a single figure:
- ICO fine (United Kingdom), 30 October 2020: The UK data protection authority ICO imposed a fine of 18.4 million British pounds for GDPR violations, reduced from an originally announced 99.2 million pounds.
- FTC and state AGs settlement (United States), October 2024: Marriott settled with a coalition of 49 US states and the District of Columbia for a payment of 52 million US dollars, plus extensive obligations (a risk-based security program and data deletion requirements). The settlement with the federal FTC consisted primarily of obligations rather than a separate monetary penalty.
These two amounts stem from different authorities, countries, and years. Together they show how expensive neglected care becomes, but they must not be added into one "damage figure." On top of that, cases like this always carry a hard-to-quantify but very real reputational cost.
The legal framework in Germany and Europe
In the German-speaking region, Due Care and Due Diligence do not have their own statutory labels, but the obligations behind them are firmly anchored in law. One caveat up front: this is a professional classification, not legal advice for an individual case.
GDPR Article 32: Due Care and Due Diligence in one provision
Article 32 GDPR ("Security of processing") is the central European rule for appropriate IT security. It obliges controllers and processors to implement "appropriate technical and organisational measures" (TOMs) that ensure a level of security appropriate to the risk. As its yardstick, the article explicitly names the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, and the likelihood and severity of the risk.
What is striking is that Article 32 combines both principles in a single provision:
- The Due Care elements sit in the concrete measures: pseudonymization and encryption, the ability to ensure ongoing confidentiality, integrity, availability, and resilience, and the ability to restore access to data quickly after an incident.
- The Due Diligence element sits in the final point of paragraph 1: "a process for regularly testing, assessing and evaluating the effectiveness" of the measures. That is, word for word, the ongoing control function.
In addition, paragraph 3 allows approved codes of conduct or certifications to serve as evidence. Together with the accountability principle in Article 5(2) GDPR, this creates a duty of proof that matches the Due Diligence idea exactly: you must be able to demonstrate that you assessed and acted with care. For a structured way to build the required measures, see our guide to an IT security concept.
Management liability: German company law
Breaches of these duties of care can become personal. Under German law, managing directors of a limited company must apply "the diligence of a prudent businessman" (Section 43 GmbHG), and stock corporation law imposes a comparable duty on board members (Section 93 AktG). If they breach that duty, they are liable to the company for the resulting damage, potentially with their private assets. For accuracy: Section 43 GmbHG does not mention IT security literally; applying it to cybersecurity failures is the prevailing interpretation of the general duty of care, not the letter of the law.
The decisive factor is the burden of proof. To clear themselves of an accusation, management must actively demonstrate that they established a working security management system, ran regular updates, and put preventive measures such as backups and firewalls in place. Without complete documentation, that exoneration becomes difficult. This is precisely where Due Diligence as a documented control function pays off twice over.
NIS-2: cybersecurity becomes a board matter
The European NIS-2 Directive tightens the situation further for many companies. It explicitly puts management bodies on the hook to approve risk management measures, oversee their implementation, and undergo training themselves. Cybersecurity thereby becomes a leadership task with personal responsibility. For the financial sector, DORA (the Digital Operational Resilience Act) points in the same direction, and what NIS-2 requires in detail is a compliance topic in its own right. The Cyber Resilience Act belongs to the same cluster of obligations.
D&O and cyber insurance as a backstop
Because personal liability is real, leaders often protect themselves with D&O insurance (Directors and Officers), complemented by cyber insurance for the company. Neither is a free pass, however: insurers can reduce or refuse payouts if basic duties of care were demonstrably breached. Here too the rule holds: without documented Due Care and Due Diligence, the coverage becomes worthless.
Checklist: Due Diligence and Due Care in practice
The two lists below condense the essentials into a form you can tick off.
Due Diligence questions before a decision or vendor selection
- [ ] Has a structured risk analysis been carried out for the systems and data involved?
- [ ] Are the software in use and its version levels documented (software bill of materials)?
- [ ] Is it known which third and fourth parties have access to systems or data?
- [ ] Can the provider evidence its security practice with certifications or audit reports (for example ISO 27001, TISAX)?
- [ ] Is there a current record of processing and security measures (Articles 30 and 32 GDPR)?
- [ ] Have the provenance, ownership structure, and resilience of the supplier been checked?
- [ ] Is the review itself documented so that it is provable if challenged?
Due Care routines in daily operations
- [ ] Security updates and patches are deployed promptly and traceably.
- [ ] Backups are created regularly and their restoration is tested.
- [ ] Administrator rights and access follow the least-privilege principle.
- [ ] Employees are trained regularly (awareness, phishing).
- [ ] Systems are monitored continuously and incidents are handled to a plan (see MDR, MSSP, EDR, XDR, and NDR).
- [ ] A maintained IT security concept with clear ownership exists.
- [ ] All measures are documented so that the care remains provable.
FAQ
What is the difference between due diligence and due care?
The short formula is: due diligence is knowing, due care is doing. Due diligence is the ongoing control and management function, that is the checking, investigating, and steering to ensure that your safeguards are adequate and effective (audits, risk assessments, vendor reviews). Due care is the actual implementing and maintaining of those safeguards in daily operations, such as patching, testing backups, restricting rights, and training staff. Both are equal-rank, complementary principles.
What does due care mean in cybersecurity?
Due care is the act of implementing and maintaining reasonable safeguards in daily operations, in other words the concrete doing. The yardstick behind it is the "prudent person rule": you act the way a prudent, responsible person would have acted under comparable circumstances. In the United States the equivalent phrase is "reasonable cybersecurity," a deliberately dynamic standard that depends on industry practice, data sensitivity, organization size, and known threats. There is no single fixed checklist for what counts as "enough."
Is due diligence the same as duty of care?
Not exactly. Duty of care is the legal framework, while due diligence and due care are the professional principles that give that duty concrete shape in cybersecurity. In German and European law they carry no statutory labels of their own, but they sit inside rules such as GDPR Article 32 (the regular review of measures as the due diligence element) and management liability under Section 43 GmbHG and Section 93 AktG, which require "the diligence of a prudent businessman."
What are the legal consequences of failing due care?
Failing due care can become expensive and personal. When an incident hits, the accusation is no longer "you did not know," but "you knew and failed to act." Authorities can impose fines, as the UK ICO did in the Marriott case for GDPR violations. In addition, management can be personally liable under Section 43 GmbHG or Section 93 AktG, potentially with their private assets, if they cannot demonstrate a working security management system. D&O and cyber insurers can also reduce or refuse payouts when basic duties of care were breached.
What is included in a due diligence assessment?
A due diligence assessment includes a structured risk analysis of the systems and data involved, documentation of the software in use and its version levels, clarity on which third and fourth parties have access, evidence of security practice through certifications or audit reports (such as ISO 27001 or TISAX), and a check of the provenance, ownership structure, and resilience of the supplier. Crucially, the assessment itself must be documented so that it is provable if challenged.
Conclusion
Due Diligence and Due Care are not interchangeable synonyms but two equal-rank, complementary principles. Due Diligence is the ongoing knowing and controlling of whether your safeguards are adequate and effective. Due Care is the actual implementing and maintaining of those safeguards in daily operations. One without the other is worthless: assess but never act, and you only know where the fire is. Act but never assess, and you are working blind.
The Marriott case and the German legal landscape teach the same lesson from two angles: care must not only be lived but also proven. GDPR Article 32, management liability, and NIS-2 all demand exactly that, an interplay of implemented measures and documented control. Whoever consistently interlocks both principles and backs them with a clear checklist lowers not just the technical risk but also the personal liability risk. And that is precisely why it pays to truly understand the difference.