The difference between a finding and a blocker

A finding describes a gap. A blocker describes a gap severe enough that proceeding creates risk the acquirer would not knowingly accept. The distinction matters because integration teams work from a plan, and a plan that treats all findings equally either delays everything or delays nothing.

The ten below recur constantly in lower-middle-market transactions. Each one is a reason to pause the connection decision, not necessarily the deal.

The ten

  1. Evidence of a prior compromise that was never investigated. An unexplained incident, a ransom note nobody escalated, or a reimaged server with no root-cause analysis. Connecting an environment with an unresolved intrusion history extends the intrusion.
  2. No multi-factor authentication on administrative or remote access. The most exploited gap in the market, and the one most often described in a questionnaire as "in progress."
  3. Privileged accounts with unknown ownership. Shared administrator credentials, service accounts nobody can explain, or access still active for departed staff or former providers.
  4. Endpoint protection coverage well below asset count. Licenses purchased is not agents deployed. The delta is where an attacker lives.
  5. Backups that have never been tested. A backup that has not been restored is a hypothesis, not a control, and it is the difference between an incident and a catastrophe.
  6. Internet-facing systems running unsupported software. End-of-life operating systems or applications exposed to the internet cannot be patched, only replaced or removed.
  7. Regulated data in undocumented locations. Patient, defense, financial, or payment data outside the systems management believes hold it. The buyer inherits the obligation immediately at close.
  8. Contractual security commitments the target does not meet. Customer contracts promising controls that do not exist create breach exposure the moment ownership changes.
  9. Unmanaged third-party or vendor connectivity. Persistent tunnels into the target's network from parties nobody has inventoried, which become tunnels into the acquirer's network after integration.
  10. No logging or monitoring of any kind. Without it, nobody can answer whether something is happening now, which makes every other control unverifiable.

Pausing without stalling the deal

Delaying integration is not the same as delaying the transaction. In most cases the correct sequence is to close on schedule, operate the acquired company at arm's length for a defined period, and run a baseline deployment that clears the blockers before connection. The business keeps moving; the risk does not move with it.

What makes that possible is finding these issues during diligence, while there is still time to plan, price, and staff the response. Discovered after close, the same ten findings become an emergency.

Every blocker needs three things

A blocker without a cost, a timeline, and a named owner is an argument, not a plan. The purpose of deal-grade diligence is to attach all three to every material finding, so the investment committee can decide rather than debate.

Working a transaction where this applies?

PrimeTech provides fixed-fee technology and cyber diligence, Day-1 security baseline deployment, and post-merger integration for private equity firms and corporate acquirers.

Discuss an Active Deal →  More Insights