Solving Your Complex Core Business Risks In An Innovative, Pragmatic, Cost-Effective Way

Merger and Acquisition Due Diligence - Solution Approach:

The Business Issue:

While the security posture of an acquisition target is unlikely to influence management’s decision to acquire the firm, an acquisition creates both opportunities and risks for the acquiring company.  Several common issues that must be considered include:

bullet

Risk: How to securely and quickly interconnect/integrate the two firms while still protecting the combined information assets and business processes?  By connecting the two firms, the acquirer potentially expands its network perimeter to that its acquisition. 

bullet

Risk: Employees or affiliates of the acquired firm become internal users increasing their ability to potentially harm SSC assets,  particularly if they are disgruntled about the acquisition and are privileged IT users.

bullet

Opportunity: Identify and help retain talented security staff and best practices within the acquired firm.

KoreLogic’s Approach:

Various clients have retained KoreLogic to provide M&A security due diligence services including Post-Acquisition Assessments (PSA).   The following are representative examples of this support:

bullet

Conducted a PSA for a Fortune 500 financial services firm which had acquired another financial services firm for +$4B.  KoreLogic performed external and internal penetration testing of the acquisition and their hosting providers.

bullet

Conducted a PSA for a large financial services firm which had acquired a strategic consulting firm.  We are performed external pen testing, internal pen testing, Active Directory integration review, security operational practices review and VoIP testing.   

Other services include:

bullet

Pre-acquisition audit--to gauge risk and the expense to correct flaws (allows acquiring company to factor this into the purchase price and to estimate post-acquisition resources to take corrective action).

bullet

Application security assessments of key software products or business-critical applications of the acquired firm (to gauge risk and the expense to correct flaws).

bullet

Forensics - when there is concern about disgruntled employees, concern about theft of intellectual property, etc,

bullet

Post-acquisition threat monitoring - monitor for suspicious user activity when there is concern about disgruntled employees and/or the acquired firm's security posture is weak. 

bullet

Interconnection architecture review - review of the client-developed interconnection plan to acquisition (e.g.,  access points to public networks, business partners, vendors; how access is controlled, threat monitoring capabilities)