{"id":36372,"date":"2019-09-06T10:41:36","date_gmt":"2019-09-06T02:41:36","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36372"},"modified":"2019-09-06T10:47:01","modified_gmt":"2019-09-06T02:47:01","slug":"your-application-security-testing-tool-just-got-acquired-now-what","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/09\/06\/your-application-security-testing-tool-just-got-acquired-now-what\/","title":{"rendered":"Your application security testing tool just got acquired. Now what?"},"content":{"rendered":"<p><strong><em>By Asma Zubair, Product Manager at Synopsys Software Integrity Group<\/em><\/strong><\/p>\n<p>You spend a large sum on your application security testing tool. You roll out an application security testing program across your organisation. Then one fine day, you learn that the vendor or the tool you\u2019ve been using has been acquired. Now what?<\/p>\n<p>Mergers and acquisitions bring a lot of uncertainty for customers. Personnel may change; terms of service may change. That shiny new feature that your vendor promised to implement in the next release may be in jeopardy. Not only that, but the product itself may be end-of-lifed!<\/p>\n<p>If you\u2019re running an application security program for a government agency, things may get even more complicated after a cyber security acquisition. What if your tool gets acquired by a company offshore? After all, we\u2019re talking about potentially giving a foreign-located vendor access to vulnerabilities in your applications. Do you trust the vendor and their personnel to perform security testing on applications that handle sensitive or classified information?<\/p>\n<p><b>What to do after a cyber security acquisition<\/b><\/p>\n<p>If you find yourself in a sticky situation related to a cyber security merger or acquisition, follow these simple steps:<\/p>\n<p><b> \u2022 Review your contract. <\/b>Have your legal team look at the contract to understand your options, including the ability to revisit the contract in an M&amp;A situation.<\/p>\n<p><b> \u2022 Understand the drivers.<\/b> Do some research to understand the drivers behind the acquisition. Sometimes companies acquire tools to shut them down and gain market share (e.g., Slack\u2019s acquisition of HipChat). In such cases, you need to prepare for change.<\/p>\n<p><b> \u2022 Know your standards and regulations.<\/b> Some sectors, like government, have strict regulations for working with companies in particular countries. For example, Indian company HCL\u2019s acquisition of AppScan may raise concerns for U.S. intelligence communities who share information only with select countries and may take issue with sensitive data being housed by companies outside that group.<\/p>\n<p><b> \u2022 Assess the impact. <\/b>Every merger or acquisition brings some changes. Assess the impact on your business. Were you waiting on any major product updates? Could product consolidations affect your existing integrations? Are you no longer able to fulfill certain regulation or compliance needs owing to the merger or acquisition of your vendor?<\/p>\n<p><b> \u2022 Evaluate your options and make a decision. <\/b>If you anticipate significant changes as a result of the merger or acquisition, this is your opportunity to move on to something better.<\/p>\n<p><b>An acquisition can be an opportunity<\/b><\/p>\n<p>If your AppSec tool or vendor has been acquired, you\u2019re faced with an important decision. You may have to find a new vendor so you can obey regulations or meet your customers\u2019 requirements. Or you may want to find a new tool to meet your own needs. Either way, a cyber security acquisition can be a golden opportunity for you to find better options.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Asma Zubair, Product Manager at Synopsys Software Integrity Group You spend a large sum on your application security testing tool. You roll out an application security testing program across your organisation. Then one fine day, you learn that the vendor or the tool you\u2019ve been using has been acquired. Now what? Mergers and acquisitions [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":34618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26,25],"tags":[6151,951,6863],"class_list":["post-36372","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions","category-software","tag-high-tech","tag-mergers-and-acquisitions","tag-synopsys-software-integrity-group"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36372","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36372"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36372\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/34618"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36372"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36372"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36372"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}