Skip the navigation

Strengthen Security During Mergers

By Bob Violino
July 14, 2003 12:00 PM ET

Computerworld - Maintaining robust security is at the top of the IT priority list at many companies these days. But those that are in the midst of a merger or acquisition face some unique security challenges -- and opportunities.
U.S.-based multinational companies plan to increase their merger and acquisition activity over the next two years, with 70% expecting to be involved in such deals in that period, according to a recent PricewaterhouseCoopers Barometer Survey of 170 executives.
That will mean lots more work for chief security officers -- before the deal is signed and afterward, when security technologies and policies have to be integrated. The following are some practical tips for ensuring that data, networks and systems remain as secure as possible during the often turbulent times that accompany a merger or acquisition.

  • Perform due diligence on security well before the merger begins. The chief security officer or other senior security manager should be as involved in the process of evaluating potential merger or acquisition targets as finance, human resources and other executives are. Analyze the security policies and technologies at the other company, and determine how vulnerable it is.
    Also, determine whether the company educates employees about security in general and about things such as preventing the spread of viruses. Conduct a penetration test of the target company's network, and interview managers and staffers to gauge the prevailing attitude about security and protecting data and intellectual assets.
    "Spend a lot of time learning about the company and its culture, where it does business, whether security [management] is centralized or decentralized, and how the company values security," says Bobby Gillham, manager of global security at ConocoPhillips in Houston, who headed security for Conoco during its 2002 merger with Phillips Petroleum. "Work closely with the other company's security manager to understand their security organization and its role in the organization."

  • Assess the security practices and vulnerabilities of suppliers and other business partners that work closely with the merger or acquisition target, says Laura Koetzle, an analyst at Forrester Research Inc. Do the trading partners have adequate security in place for e-commerce, online procurement and Web collaboration?

  • Remember that a merger can always fall through because of regulatory restrictions, stockholder disapproval or other reasons. "Companies have to be careful about releasing [security] information to the other organization, because if the merger is halted, there's no way you can get them to 'unknow' those things you've told them," says Koetzle. This is particularly critical if the merger partner is a competitor. "You can disclose the level of security you provide, but don't hand over all the keys to the kingdom in the early stages of a merger."

  • Anticipate "social engineering" and other security threats from disgruntled employees at both of the companies involved. While experts say bad behavior is usually the exception -- most people are more concerned about finding a new job than harming the company if they believe they're going to be laid off -- it makes sense to be ready for anything. As soon as an employee has been notified about a layoff, cut off access to all critical services and applications. The IT staff should be trained and prepared to shut off employees' network access as quickly as necessary.
    "You need to pay particular attention to protecting against people walking out with proprietary information," Gillham says. "Sometimes people take things not to steal, but to show prospective employers the work they've done. You have to limit access to proprietary systems for those people you know are being downsized."

  • During the integration/transition phase, get the two companies' security groups working together as soon as possible. Begin to identify which security technologies should be retained and which should be dropped, based on the security needs of the new organization. "There may be an opportunity to create [a new] security organization that has the best of both companies," says Gillham. "Compare the security expertise of both companies and look for opportunities for synergy in the integration process."

  • Be sure to address how to handle secure communications, particularly if the companies are using different types of e-mail or virtual private networks for remote access. "That can be a hurdle; if the systems are not compatible, people may not be able to communicate with each other," says Nicholas Percoco, associate partner at Ambiron LLC, an information security advisory firm in Chicago. It may be necessary to change security technologies at one company to guarantee secure communications.

  • If the target company turns out to be a security disaster and it's too late to get out of the deal, spend whatever it takes to quickly bring the company up to snuff, through new technology or upgrades of old products. Send in security experts or hire consultants to evaluate security, especially for the most critical systems and networks.

Violino is a freelance writer in Massapequa Park, N.Y. You can contact him at bviolino@optonline.net.

Special Report

Tips From Security Experts
Stories in this report:

Read more about Security in Computerworld's Security Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
All Security White Papers
Security Webcasts
Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
Introduction to VMware vCenter Site Recovery Manager 5
Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
The Top Ten Secrets to Avoiding SAN Performance Problems
Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
Deduplication Without Compromise
Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
Director of Disk Products Discusses DXi6700
Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs