Case file 01 · M&A security integration
Three and a half years stalled.
None of it for technical reasons.
The architecture already existed. One studio had been developing it for years and could not get anyone else to adopt it — which is a completely different problem, and it does not get solved by more architecture.
Subject
A $69B games-industry acquisition. 35 studios, 100,000+ endpoints. One studio had spent roughly three and a half years on a Zero Trust architecture that neither the other studios nor the parent company had agreed to adopt.
The situation
The work was not missing. A single studio had been developing a Zero Trust architecture for about three and a half years and had produced something real. What it did not have was agreement — not from the other studios, and not from the parent company. Underneath that sat an identity organization in the middle of its own turmoil: several directors in quick succession, and directory structures across the studios with nothing tying them together. Zero Trust depends on identity, and identity was the least stable thing in the building.
Why it had not been solved
Because the objections were correct. When a studio said “we do not have the bandwidth to build this,” that was true, and no amount of executive sponsorship makes it less true. When someone asked “who is going to pay for this,” there was no good answer for as long as the question was being asked between peers — every studio had its own budget and none of them had a reason to fund something the others would also benefit from. Add the ordinary politics and pride of getting independent business units to agree on a large change, and a program can stay technically finished and organizationally dead for years.
What I did
Started where I start most engagements: where are we, where do we want to go, how do we get there. Then worked with the original architect to tighten what he had already built, rather than arriving with a replacement — the architecture was not the thing that was broken.
After that it was the objections, taken one at a time, and neither of the two that mattered was answered by persuading anybody. “Who pays” was relocated rather than argued: it went to Activision corporate, the parent entity, which should have owned it all along. Between peer studios that question has no answer; one level up it stops being a question. “We do not have the bandwidth” was accepted and then removed: my architects built it for the studios, so their cost of participation dropped to a switch. All you have to do is turn it on.
Identity ran in parallel rather than first. I used my own IAM background to fill the gaps while that organization was in turmoil, so the Zero Trust work was never waiting on somebody else’s reorganization to finish.
Result
What this means for you
If a program of yours has been stalled for years, the people blocking it are probably right. That is uncomfortable, and it is also the good news: a correct objection can be removed, whereas an argument can only be won or lost. Funding fights between peers usually dissolve one level up. Bandwidth objections usually dissolve when somebody else does the building. Neither requires anyone to be talked into anything, and both are visible from the outside inside of a couple of weeks.
Take the one-pager with you
The same case file as a single-page PDF, sized to forward to the person who actually has to approve the spend. Also gets you the checklist of what diligence typically misses.
One email, the PDF, and the monthly Dispatch. Unsubscribe whenever.