{"id":27416,"date":"2017-01-04T10:15:02","date_gmt":"2017-01-04T02:15:02","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=27416"},"modified":"2017-01-04T10:15:02","modified_gmt":"2017-01-04T02:15:02","slug":"opinion-dont-neglect-security-ma-due-diligence","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/01\/04\/opinion-dont-neglect-security-ma-due-diligence\/","title":{"rendered":"OPINION | Don&#8217;t neglect security in M&#038;A due diligence"},"content":{"rendered":"<div id=\"attachment_27417\" style=\"width: 243px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-27417\" class=\"size-medium wp-image-27417\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1-233x300.jpg\" alt=\"\" width=\"233\" height=\"300\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1-233x300.jpg 233w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1-768x990.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1-794x1024.jpg 794w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/01\/Drew-Del-Matto-1.jpg 920w\" sizes=\"auto, (max-width: 233px) 100vw, 233px\" \/><\/a><p id=\"caption-attachment-27417\" class=\"wp-caption-text\"><strong><em>Drew Del Matto, Chief Financial Officer, Fortinet<\/em><\/strong><\/p><\/div>\n<p><strong>Look at any M&amp;A due diligence checklist and you\u2019ll see the same things: financials, customer information, sales, real estate, intellectual property, contracts\u2014and the list goes on. One thing you may not see is information security, and that can be a crucial mistake.<\/strong><\/p>\n<p>Like any other critical component of running a business, security needs to be right at the top of the list for M&amp;A due diligence. When combining two companies, they often have different and sometimes even incompatible systems and data. That can create opportunities for hackers. If a company is in the news for a merger or acquisition, it\u2019s a fair bet that hackers and data thieves are going to try their hand at breaching its security. A good business decision can turn bad very quickly if security is an afterthought.<\/p>\n<p><a href=\"https:\/\/blog.fortinet.com\/2016\/09\/15\/why-cfos-need-to-be-drivers-of-security-stewardship\">A CFO\u2019s job<\/a>\u00a0is to realize the optimal business case, mitigate the risk, and protect the company\u2019s assets, both tangible and intangible. In addition to data, some of a company\u2019s most critical assets are its reputation and the loyalty of customers. An acquisition can make customers of both companies apprehensive. If that\u2019s followed up by a massive breach of sensitive customer data, the companies\u2019 customers will flee in droves.<\/p>\n<p>To avoid that worst-case scenario, here are some things to keep in mind during the M&amp;A process.<\/p>\n<p><b>Before the Merger<\/b><\/p>\n<p>Companies going through a merger or acquisition need to start their security due diligence early in the deal and ensure that the target\u2019s data and environment are clean. That starts with a full audit of the target\u2019s network. Look not only at their tools and systems, but also at their policies and procedures. Is their security well documented, with logs and reports?<\/p>\n<p>If it is, the buyer\u2019s team will need to go through all that documentation to find any previous cybersecurity incidents. How did the target respond to the incident and how did it remediate the issue to avoid a repeat? If that documentation does not exist, the organization may have much bigger issues that could require a comprehensive review by a qualified third party.<\/p>\n<p>From the time the merger or acquisition becomes public knowledge, through to the time when the two companies are finally combined, both companies\u2019 networks need to be monitored daily for attacks and suspicious activity. Two-thirds of attacks come from within organizations, from either careless or disgruntled employees. Since an M&amp;A process often includes restructuring and layoffs, employees can feel nervous and threatened. Fearful or disgruntled employees with access to the data and systems can be a dangerous combination. It\u2019s imperative that customer data is protected throughout the process and that the value of the merger or acquisition (and other details) is not being leaked.<\/p>\n<p><b>Bring Two Companies Together, Securely<\/b><\/p>\n<p>From a security standpoint, the first thing the IT team must do is combine and align two different network security policies. This can be complicated. There are a lot of decisions to make. Which elements of each policy will be kept? Does the buyer combine the two policies or create an entirely new one? Whatever approach the buyer takes, make sure the decisions result in improved security for the new organization and that they leave no gaps that can be exploited.<\/p>\n<p><b>Consider an Integrated Security Platform<\/b><\/p>\n<p>M&amp;A deals always present opportunities to increase efficiency by combining systems and eliminating redundancies, and the security side is no different. A merger or acquisition is an opportunity to look at both organizations\u2019 network security systems and consider moving to an integrated, common platform. Most organizations have many different security devices, often from many different vendors, and most likely, those devices don\u2019t talk to each other. That makes it very difficult to share information across the network and respond to threats quickly.<\/p>\n<p>Now, imagine combining two sets of these siloed security solutions. Instead of improving the combined company\u2019s security, they are more likely to slow detection and response times dramatically. The ideal solution is an architectural approach that ties together discrete security solutions into an integrated whole.<\/p>\n<p>The buyer may be hesitant to spend\u00a0<i>more<\/i>\u00a0money during an acquisition. That\u2019s understandable. But imagine an integrated system that automates the processing and analysis of threat information from many different sources, quickly identifies network security threats, synchronizes a response, and even automates the identification, isolation, and analysis of suspicious files. All of this, if done manually, is labor-intensive and time-consuming and is prone to missing complex threats.<\/p>\n<p>However, an integrated platform or security fabric can dramatically improve network security; help the buyer avoid costly, damaging breaches; and do so without adding security headcount. In a time when personnel budgets are tight and cybersecurity talent is in short supply, consider how much that is worth.<\/p>\n<p><b>Future-Proofing with Internal Segmentation<\/b><\/p>\n<p>A merger or acquisition is also a good opportunity to consider implementing more future-proof technologies, like\u00a0<a href=\"https:\/\/www.fortinet.com\/solutions\/enterprise-midsize-business\/enterprise-firewall\/internal-segmentation-firewall-isfw.html\">internal segmentation<\/a>\u00a0of the network. With networks becoming increasingly complex and cyberattacks increasingly sophisticated, even the best firewalls can\u2019t stop everything. And during the integration phase of two different networks, this is truer than ever.<\/p>\n<p>Once an attack reaches the internal network, IT may not be able to detect it, let alone stop it. That\u2019s why some data breaches remain undiscovered for months or even years while cybercriminals siphon off critical information. Internal segmentation firewalls are designed to control traffic between network segments, thereby isolating and containing any malicious code that has made its way into the internal network and limiting the damage it can do.<\/p>\n<p><b>Get All Your People On Board<\/b><\/p>\n<p>Even the best security systems and procedures can be thwarted, intentionally and unintentionally, by people. Communicate early and often to employees to ease their concerns about the merger. Then make sure the company implements consistent security policies and best practices, and thoroughly educates employees on them through an awareness program and ongoing training. The more security-savvy the people are, the better they\u2019ll be at supporting security efforts.<\/p>\n<p>The bottom line: neglecting security during a merger or acquisition can have disastrous results. On the other hand, incorporating security considerations from the earliest stages of the process can result in a combined organization that is stronger, more secure, and more efficient than the original two companies ever were. The latter approach also helps realize and drive the intended value of the M&amp;A decision.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Look at any M&amp;A due diligence checklist and you\u2019ll see the same things: financials, customer information, sales, real estate, intellectual property, contracts\u2014and the list goes on. One thing you may not see is information security, and that can be a crucial mistake. Like any other critical component of running a business, security needs to be [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":27417,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[169,286,4576],"class_list":["post-27416","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions","tag-fortinet","tag-it-security","tag-ma"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27416","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=27416"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27416\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/27417"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=27416"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=27416"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=27416"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}