Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

PK Protect: De-Risking Acquired Data in Mergers and Acquisitions

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

The global market today is markedly characterized by consolidation and convergence; after a brief slowdown in 2020, companies are again looking at mergers and acquisitions for business growth. Beyond bringing people, technology, and business processes together, data is every company’s biggest asset and largest liability. The convergence of data requires deliberation and insights, especially in light of the growing number of privacy and security compliance requirements.

The fundamental problem is that the company acquiring the new business is also acquiring all their data assets, and with that, the liability of safeguarding them. Fortunately, PKWARE’s data solutions are purpose-built to de-risk data that is part of M&A and due diligence processes. Download our solution overview to learn more.

An Acquisition Transfers the Liability With the Asset

A company acquiring a business acquires its data assets, and with them the obligation to safeguard every one. Data is the largest asset on the table and, unexamined, the largest liability.

That matters more now than it did a decade ago, because the privacy and security regimes attaching to acquired data have multiplied while due diligence practice has largely not.

Due Diligence Has to Cover the Data Itself

Financial and legal due diligence are routine. Data due diligence rarely is, and it answers a different question: what regulated information is actually in these systems, in what volume, under whose jurisdiction.

Without that picture, any subsequent audit, internal or external, can produce monetary or legal consequences for the acquirer over data it inherited and never examined.

Two Sets of Business Processes, One Standard

When two companies combine, each brings its own way of using data, and those ways were built against different security and privacy standards. Neither set automatically governs the merged organization.

The way data will be used in the new business process has to be decided deliberately, and the sensitivity of the data is what determines the answer. Deferring that decision means the looser of the two standards usually wins by default, because it is the one that blocks nothing.

The Risk Peaks After the Deal Closes

Integration is when people gain access to data they have never had before. Records from different environments and different geographical regions begin flowing into each other, and the access grants are made quickly because the integration plan has a date on it.

Appropriate controls have to be in place before that sharing is enabled rather than after. Once data from a restricted jurisdiction has been copied into a system that never held it, the remediation is considerably harder than the prevention would have been.

Why Breaches Find Merged Environments

Sophisticated attacks exploit badly designed environments and poorly implemented protocols, and a partially integrated estate is exactly that for as long as integration lasts.

Two directory services, two sets of policies, temporary trust relationships and a period in which nobody owns the whole picture. Knowing where the sensitive data sits throughout that window is what keeps the transition from becoming the incident.

What to Establish Before Signing

Four things make the rest manageable. What sensitive data exists in the target’s systems. Which regulations attach to it and in which jurisdictions. What protection is applied today. And what the acquirer’s own standard requires, so the gap between the two is priced rather than discovered.

Each of those four is answerable with a scan rather than an interview, which matters because the people who know the target’s data best are the ones with the least incentive to volunteer what is wrong with it during a sale.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.