For operating partners
The deal closed.
Now inherit the security debt.
M&A security integration is the post-close work of merging two security estates: unifying identity, consolidating cloud, resolving who the acquired security function reports to, and reporting progress in a form an investment committee can act on. It is priced here at $50,000–$250,000 fixed per deal, sized by scope.
The three things diligence usually misses
Diligence is built to check controls against a framework, and it does that well. The items that actually determine your integration timeline are structural rather than control-shaped, so they tend to fall outside the scope of the report you already paid for.
Identity sprawl
Two identity systems that were each fine in isolation become an attack surface the moment you connect them. Every merger creates a period where trust relationships exist that nobody designed, and that period lasts exactly as long as it takes someone to own the problem.
Shadow cloud
The acquired company's cloud footprint is almost always larger than its documentation. Accounts stood up for a project that ended, environments a departed contractor owned, subscriptions billed to a card rather than a contract. These are not exotic and they are not in the data room.
The reporting line nobody negotiated
Where the acquired security lead sits after close is usually decided by accident, and it quietly determines whether anything gets done for the next two quarters. It is worth ten minutes of deliberate thought at close and it almost never gets them.
Why integrations stall, and what actually restarts them
Stalled integrations are rarely technical. In the largest one I worked on, a Zero Trust architecture had been in progress for roughly three and a half years and had not landed — not because the design was wrong, but because two objections had no answer at the level they were being asked.
“Who is going to pay for this?” is unanswerable between peer business units, each with its own budget and no reason to fund something the others benefit from. It stops being a question one level up, at the parent entity that should have owned it from the start.
“We do not have the bandwidth” is usually true, and no amount of executive sponsorship makes it less true. It disappears when somebody else does the building and the business unit's cost of participation drops to a switch.
Neither of those is persuasion. Both are structural, and both are visible from outside inside a couple of weeks. The full case file has the detail.
What the engagement produces
- Identity and network unification, mapped and sequenced across both organizations, with the collisions found before they are load-bearing.
- Multi-cloud consolidation, including the accounts nobody listed.
- An honest read on the org chart — where security reports and whether that survives integration.
- Executive reporting in a form a board and an investment committee can act on.
- A sequenced blueprint with blocking items named while they are still schedule items rather than surprises.
Common questions
When should security integration start?
At or immediately after close. Before signing you want a diligence read, which is a different and much shorter engagement. After close the clock is running on integration and every week of ambiguity about who owns security is a week the acquired company's team spends waiting.
What does M&A security integration cost?
$50,000–$250,000, fixed, per deal. The range is driven by size and scope: number of entities in the transaction, identity systems and cloud tenants to unify, combined headcount, how compressed the timeline is, and how many jurisdictions are involved.
Diligence already covered security. Why is there more?
Diligence checks controls on paper, and it is good at that. It rarely checks identity sprawl, shadow cloud, or where the acquired security function actually reports — and those three decide your integration timeline more than any control gap does.
What if the integration has already stalled?
That is a common engagement and often an easier one, because the failure is usually visible from outside within about two weeks. Stalls are rarely technical. They are usually a funding question being asked between parties who cannot answer it, or a capability being demanded from a team that genuinely does not have the bandwidth.
Have a deal in motion? Thirty minutes is usually enough to tell whether the integration has a structural problem or a scheduling one.
Book the 30-minute diagnostic M&A Security Integration →