Safeguard
Industry Analysis

Diligence Tells You What You Bought. Integration Is Where the Risk Arrives.

Most acquisition security effort happens before close and produces a report. Your exposure actually changes in the ninety days afterwards, when the pressure is to connect everything quickly and the security questions are marked answered.

James
Principal Security Architect
6 min read

Diligence tells you what you are buying. Integration is where the risk actually arrives, and it arrives on the day someone connects the two networks so that the new team can get to work.

Most acquisition security effort is spent before the deal closes, producing a report. The period that determines your actual exposure is the ninety days afterwards, when the pressure is to make everything work quickly and the security questions have already been marked as answered.

This post is that ninety days. For whoever inherits an acquired company's systems.

What you actually acquired

Beyond the product and the team, you took on everything attached to them, and most of it was not in the diligence report:

  • Their internet-facing assets, including the ones nobody remembers. Their domains, their forgotten subdomains, their old marketing sites.
  • Their vendor relationships, which become your subprocessors, with contracts you did not negotiate and terms you have not read.
  • Their identity estate: accounts for former employees, contractors, and the founders' personal tooling that became company tooling.
  • Their technical debt as a security position: unsupported operating system versions, a database nobody can upgrade, a framework two major versions behind.
  • Their data, with whatever consent and retention history it carries. If a user's data was collected under terms that do not cover your use, that travels with the data.
  • Their incidents, including ones nobody disclosed because nobody noticed.

The last one is worth dwelling on. You are inheriting an unknown history. A compromise that happened before the deal is now your compromise, and the discovery usually happens after the networks are joined.

The sequencing that matters

The pressure on day one is to connect identity, so people can log in to each other's systems. Resist doing that first. It is the change that most increases blast radius and it is the hardest to reverse.

A workable order:

First, inventory without connecting. Domains, cloud accounts, repositories, SaaS applications, internet-facing services, and who has administrative access to each. You cannot make decisions about a system you cannot name, and this step needs no trust relationship at all.

Second, close the obvious doors. Former employee accounts, shared credentials, anything internet-facing that should not be, and any administrative access held by people who left during the deal. Deal periods produce departures, and offboarding is the first thing to slip when a company is being sold.

Third, look for evidence of prior compromise before joining the networks. Authentication logs, unfamiliar administrative accounts, unexplained egress, and the certificate transparency record for their domains. If something is already there, you want to find it while the two environments are still separate.

Fourth, connect narrowly. Specific applications, specific groups, rather than a trust relationship between directories. Federation between identity providers is convenient and it means a compromise on their side is a compromise on yours.

Fifth, integrate properly, over months, with the same controls you apply to your own estate.

The instinct is to do step four on day one and the rest eventually. The cost of that ordering is that if anything is wrong on their side, it is now wrong on yours, and you found out afterwards.

Things that reliably need attention

Their laptops. Unmanaged or managed by a system you are retiring. Until they are enrolled in your management, they are unmanaged devices with access to your systems.

Their production access model. Small companies frequently give every engineer production access, because at eight people that is reasonable. At your size it may not be, and changing it is a cultural conversation as much as a technical one.

Their secrets. In a password manager you are not migrating, in environment files, in a wiki. Assume they need rotating, because you cannot establish who has seen them.

Their CI credentials, which are usually the most privileged things in the estate and the least reviewed.

Their customer data location. If they stored EU data somewhere your commitments do not permit, you now have that obligation and that problem.

Do not break the team

The part that is easy to get wrong for non-technical reasons.

An acquired engineering team has just lost autonomy, and the first thing the acquirer's security function does is often to arrive with a list of everything wrong. That is accurate and it is a poor opening, and it makes every subsequent request harder.

What works better: explain which constraints are non-negotiable and why, ask them what worries them about their own systems, and fix two things they have been asking for. Acquired teams usually know exactly where the problems are and have been unable to get time to address them. That knowledge is the most valuable thing you acquired and it evaporates if the relationship starts adversarially.

Write down what you accepted

Some things will not be fixed in ninety days. An unsupported database, a compliance gap, a customer contract with terms you would not have signed.

Record each one as an explicit acceptance with an owner and a date, the same as any other risk acceptance. The failure mode otherwise is that the integration finishes, the project closes, and the known issues become permanent and unowned because the list lived in a project plan that was archived.

The concession

Every recommendation here slows integration, and integration speed is usually part of the deal thesis. The synergies that justified the price often depend on teams working together quickly, and a security function that adds three months to that is answering to a different objective than the business.

So be explicit about the trade rather than absolute. Connecting narrowly on day one and properly over a quarter costs little. Insisting on a full remediation before any connection costs real money and will be overruled. Pick the two or three things where the blast radius genuinely justifies delay, usually directory federation and production access, and move fast on the rest.

The implication

Diligence is an assessment. Integration is a change to your own attack surface, made under time pressure, with incomplete information about what you are attaching.

Treat the ninety days after close as the security project, not the weeks before signing. That is when the exposure actually changes.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.