The Hidden Liabilities of Buying an Internet Business
A business with clean revenue and a decent audience looks safe to buy. But internet properties hide their worst problems in plain sight — in the code, in the relationship with readers, in the dependency on one person. We learned this the hard way.
The Code Is a Liability, Not an Asset
When you buy a software business or a web property, you assume the code is an asset you can use and build on. In practice, the code is often a liability that will cost you more to fix or replace than to rewrite from scratch. Small operators often prioritize getting features to market over writing maintainable code. They skip tests, they hardcode configuration, they build custom solutions instead of using standard frameworks. The result is a system that works until you need to change it.
This becomes a real problem the moment you want to modify the business — add a new feature, migrate to new infrastructure, or simply upgrade the underlying technology. You will discover that the codebase has no tests, no documentation, and no clear separation of concerns. The previous operator knew how the system worked because they built it. You do not. You will need to hire developers to read and understand the code before they can touch it, and that costs time and money you did not budget.
The antidote is to audit the code before you buy. Ask the seller for a full git history, a deployment process, and evidence of testing. Ask them to explain the architecture in detail. If they cannot or will not, factor the cost of a rewrite into your offer. Do not assume you can learn the system quickly or that you can hire someone to fix it cheaply. A messy codebase is a drag on every future decision.
Audience Fragility: The Audience Followed the Operator
You bought the business because it has an audience. But in most cases, the audience is loyal to the operator, not the brand. They read the newsletter because they liked the writer's voice. They followed the account because they liked the person behind it. They came back because they trusted the individual who built the thing. When you take over, you inherit the traffic and the email list, but the relationship dies on day one.
This is especially true for media properties, but it applies to SaaS businesses too. If the business is a solo founder's personal brand — a newsletter, a YouTube channel, a blog — assume that 30 to 50 percent of the audience will leave when ownership changes. They may not leave immediately, but they will unsubscribe or stop visiting after a few weeks when they realize the new operator is not the person they followed. The audience is not loyal to the brand; it is loyal to the person.
The only way to mitigate this is to be transparent about the transition and to invest in the brand separately from the operator. If the previous owner can introduce you publicly and explain why they believe you will take the property in a good direction, that helps. If you can maintain or improve the quality of the content or product, that helps too. But you should expect a dip in engagement and traffic in the first few months. Some of that will come back as you prove yourself. Some of it will not.
Key-Person Dependency: The Operator Was the Business
Many small internet businesses are run by one person. That person is the product, the support, the business development, and the operator. When you buy the business, that person is supposed to leave or hand off their work to you. But there is always a hidden dependency — a vendor relationship, a process that only the operator knows, a customer who trusts only the founder. The business does not work the same way without them.
This manifests as customers asking where the founder went, as important processes that are not documented, as relationships that do not transfer. You will call a vendor and discover that the previous operator has a personal relationship with them and a special price that you do not get. You will try to onboard a new customer and realize that the founder used to customize the product for every client, and that is not in the contract. You will discover that there is no playbook for customer support because the founder just answered emails.
The way to handle this is to negotiate a transition period where the previous operator stays available for handoff. Not to run the business, but to answer questions and introduce you to key relationships. Make this explicit in the purchase agreement. Ask them to document their work — the key processes, the vendor relationships, the customer expectations. Pay them to do this. It is expensive, but it is cheaper than learning it the hard way by losing customers.
Deferred Maintenance and Infrastructure Debt
A solo operator maximizes profit by cutting costs. They use cheap hosting, they do not upgrade dependencies, they do not invest in monitoring or backups, they do not hire help. The business runs on a thin margin for years, and the operator is comfortable with that because they understand the risks. You are not comfortable with those risks, and you should not be.
When you take over, you inherit infrastructure that is held together with tape. The server is running old versions of dependencies with known security vulnerabilities. The backups are manual and ad hoc. There is no monitoring, so you will not know if the site goes down until a customer tells you. The email infrastructure is set up haphazardly. Compliance and legal requirements have been ignored because the operator did not think they applied.
This costs money to fix. You will need to upgrade the infrastructure, hire someone to manage it, add monitoring and backups, and ensure compliance with laws and regulations in your jurisdiction. Budget for this before you buy. Ask a technical advisor to audit the infrastructure and give you a realistic estimate of the cost to bring it up to professional standards. Add that cost to your acquisition offer.
Compliance and Legal Liability
Small operators often ignore legal and compliance requirements because the cost of learning them is high and the risk feels remote. They do not have a privacy policy, or they copied one from another site. They do not know the regulations for their industry or their jurisdiction. They do not have a proper terms of service. They are not thinking about what happens if someone sues them or if the government audits them.
When you buy the business, you inherit this liability. If there is a privacy violation, you are responsible. If there is a copyright infringement in the content or the product, you own it. If the business should have had a license and did not, you are liable. If the business collected data without proper consent, you are liable. This is not just a theoretical risk; it is a real cost that can be expensive to remediate.
Before you buy, hire a lawyer to audit the business for compliance issues. Ask them to review the terms of service, privacy policy, and content for legal liability. Ask them about licensing and regulatory requirements for the industry. This costs money upfront, but it is much cheaper than discovering a liability after the purchase and having to fix it or carry the risk yourself. Make sure the seller indemnifies you for any pre-existing violations.
The Revenue That Disappears
A business with revenue that looks stable on paper can lose that revenue very quickly after you take over. This happens for a few reasons. Some revenue comes from the operator's personal relationships or reputation — clients who work with the operator because they trust them. Some revenue is fragile because it depends on a specific strategy or tactic that only the previous operator knows how to execute well. Some revenue is one-time or irregular, not recurring, so the baseline is lower than you think.
If you buy a services business, expect that you will lose some clients because they do not have a relationship with you. If you buy a content business with sponsorships, expect that some sponsors will not renew because they were working with the founder personally. If you buy a SaaS business with a high churn rate, expect that the churn will stay high or get worse if the product experience changes. Revenue that looks solid in an income statement can evaporate when the operator leaves.
The way to protect yourself is to carefully audit the revenue before you buy. Ask which revenue is recurring and which is one-time. Ask which customers or sponsors are dependent on the operator. Ask about churn rates and customer acquisition costs. Give yourself a longer runway to prove yourself than you think you need. Do not assume that the revenue will stay the same. Assume that you will lose some of it, and that it will take time to rebuild trust and win it back.
What to Do: The Acquisition Checklist
- Hire a technical advisor to audit the codebase, infrastructure, and deployment process. Budget for the cost of fixing what you find.
- Hire a lawyer to audit the business for compliance issues, liability, and licensing requirements. Get an indemnification clause in the purchase agreement.
- Map the audience and understand how much of it is dependent on the operator. Factor a 30-50 percent drop in engagement into your projections.
- Identify key-person dependencies: vendor relationships, customer relationships, and processes. Negotiate a transition period where the operator is available to hand off.
- Ask the operator to document their work in detail. Pay them to do this. It is expensive, but it is cheaper than learning by trial and error.
- Audit the revenue by source and customer. Understand which revenue is recurring, which is one-time, and which is dependent on the operator.
- Reduce your offer by the cost of fixing everything you find. Do not assume you can absorb the problems cheaply.
Common questions
what are the biggest hidden costs when buying an internet business
Technical debt (the code is a liability, not an asset), audience fragility (readers are often loyal to the operator, not the brand), key-person dependency (the previous owner was the business), and deferred maintenance (infrastructure, compliance, and tooling have been neglected to maximize short-term profit).
how do you spot technical debt before you buy
Ask to audit the codebase, host infrastructure, and deployment process. A business that cannot show you its own systems or claims they are too complex to explain is a red flag. Run a live migration test if possible.
can you fix audience fragility after buying a media property
Sometimes, but it takes time and risk. If the audience followed the operator's name or voice, not the brand, you must rebuild trust by proving you will not abandon the property or degrade its quality. A sharp drop in traffic or engagement is normal in the first 3 to 6 months.
Every property in the Don Gastón portfolio is independently live — built, deployed, and operated by one person.
See what's live in the portfolio