The pattern

A company with a hundred employees and healthy margins is acquired. IT is one stretched generalist, or an outsourced managed service provider whose contract covers helpdesk and uptime. Security is whatever the provider's default configuration happened to include. Nobody in the building owns it.

The diligence questionnaire comes back looking clean, because the person completing it answered honestly about a domain they were never responsible for. A clean questionnaire from an organization with no security function is not evidence of good security. It is evidence that nobody knows.

Why this is not a reason to walk away

Companies in this position are often excellent businesses. The absence of a security program reflects size and history, not mismanagement, and the cost to establish a reasonable baseline is usually modest relative to deal value. The mistake is not buying them. The mistake is buying them while assuming a capability that does not exist.

Concretely, that assumption shows up as an integration plan that expects the target's IT to execute tasks nobody there can execute, a timeline built on that expectation, and a Day 1 that arrives with nobody assigned.

What to do instead

Price the gap during diligence. Establish the remediation cost as a line item, decide whether it belongs in the model or the purchase price, and plan for outside hands to do the work in the first weeks after close.

Then treat Day 1 as a deployment rather than a handoff. The acquisition security baseline is a defined minimum control set, aligned to the CIS Critical Security Controls' essential cyber hygiene, established and evidenced before enterprise trust is granted:

  • Asset and identity discovery
  • MFA and privileged-access baseline
  • Endpoint and EDR coverage validation
  • Vulnerability scanning and critical remediation
  • Backup, logging and escalation validation
  • External exposure and remote-access review
  • Data protection and regulatory triage
  • Documented exceptions and a 100-day plan

Working with the acquired team, not around them

The people at the target are usually relieved rather than threatened when experienced help arrives, provided the framing is right. They have known about these gaps for years and lacked budget and authority to close them. Deployments that treat them as partners move faster and leave behind an organization that can operate the controls after the consultants leave.

That handoff is the actual finish line. A baseline nobody can maintain decays within months.

Working a transaction where this applies?

PrimeTech provides fixed-fee technology and cyber diligence, Day-1 security baseline deployment, and post-merger integration for private equity firms and corporate acquirers.

Discuss an Active Deal →  More Insights