Join our Newsletter — 33% off our NHI Course

Why do unknown assets and subsidiaries increase cybersecurity risk in M&A due diligence?

Unknown assets and subsidiaries increase risk because they expand the attack surface beyond what a manual review usually captures. Forgotten cloud systems, databases, servers, and orphaned assets can remain exposed or unmonitored, while subsidiary environments may carry their own misconfigurations and vulnerabilities. Attackers often target internet-facing systems opportunistically, so incomplete visibility creates immediate and avoidable acquisition risk.

Why hidden assets matter before the deal closes

M&A due diligence is only as strong as the asset inventory behind it. If the target has forgotten cloud accounts, shadow databases, old servers, or acquired-side systems that never made it into the review pack, the buyer is evaluating a smaller environment than the one it will inherit. That gap matters because security risk often sits in the places no one is actively watching.

Unknown assets are dangerous not just because they exist, but because they are usually unmanaged. A system with no clear owner, no patch cadence, and no monitoring can quietly persist in a vulnerable state long after the transaction closes. In practice, that means the diligence team can sign off on a risk picture that excludes the very systems most likely to be exposed.

For a broader view of how unmanaged infrastructure turns into real compromise paths, NHIMG’s The 52 NHI breaches Report shows how exposed credentials, stale access paths, and overlooked systems repeatedly become entry points.

Why subsidiaries raise the complexity of acquisition risk

Subsidiaries increase risk because they add another operating model, another control environment, and often another set of exceptions to normal corporate standards. A parent company may have strong controls, while a subsidiary runs different tooling, different cloud accounts, different review cycles, and different assumptions about who owns what. That divergence makes “one security posture” a misleading shortcut.

The practical problem is that subsidiary risk is often indirect. The parent may inherit the liabilities of systems it never built, relationships it never documented, and third-party dependencies it never approved. If a subsidiary has weaker configuration hygiene, inconsistent identity governance, or slower remediation, those weaknesses can become part of the acquisition on day one.

That is why acquisition teams should treat visibility across entities as a control question, not just an accounting one. The more fragmented the corporate structure, the more likely it is that exposed services, forgotten integrations, or stale secrets will survive the deal process and create avoidable post-close exposure.

What diligence teams should verify before closing

The key question is not whether the target appears secure in aggregate, but whether the review has found all material assets and all material owners. If the answer is uncertain, then the diligence scope is incomplete. Teams should verify external exposure, ownership, patch status, and whether any assets sit outside central monitoring or standard access governance.

  • Confirm the full inventory of cloud accounts, domains, applications, and infrastructure tied to the target and every subsidiary.
  • Identify orphaned assets, abandoned environments, and systems with no clear operational owner.
  • Check whether each subsidiary follows the same change, logging, and access review standards as the parent.
  • Prioritise internet-facing and business-critical systems, since opportunistic attacks usually start there.

The best diligence output is not a clean-sounding summary, but a defensible list of what was found, what remains uncertain, and what must be remediated or isolated before integration.

Risk and Threat Considerations

Unknown assets and subsidiary environments create a larger and less visible attack surface, which is exactly what attackers prefer. The risk is not theoretical: a forgotten system can be internet-facing, unpatched, or still trusted by internal workflows even when no one is actively maintaining it.

Failure mechanism: Attackers exploit the mismatch between the organisation’s assumed inventory and the actual environment, using exposed services, stale credentials, orphaned identities, or weakly governed subsidiary systems as entry points.

Impact: The result can be initial compromise, lateral movement into better-managed environments, data exposure, or post-close disruption that becomes materially more expensive to contain once the acquisition is complete.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.AM — Asset Management Unknown assets and subsidiaries are an asset-inventory problem that changes acquisition risk.
GV.OC — Organizational Context Subsidiaries create governance and ownership ambiguity that affects due diligence scope.
PR.AA — Identity Management, Authentication, and Access Control Inherited systems often retain stale access paths and weak governance during M&A.
Recommendation — Inventory all inherited assets and reconcile subsidiary environments before close. Define ownership and accountability boundaries across the parent and subsidiaries. Review and remove inherited access paths before integrating the target.
CIS Controls v8 1 — Inventory and Control of Enterprise Assets Hidden systems and orphaned assets are directly addressed by enterprise asset inventory control.
5 — Account Management Acquired environments often carry stale accounts and unmanaged access that expand exposure.
12 — Network Infrastructure Management Unknown internet-facing systems increase exposure through unmanaged network services.
Recommendation — Build a complete asset inventory across all acquired entities and reconcile gaps. Audit and disable unnecessary accounts in every acquired environment. Map exposed services and close unmanaged network paths before integration.
NIST SP 800-63 4 — Lifecycle Management Due diligence must identify inherited identities and access lifecycles across entities.
2 — Enrollment and Identity Proofing Acquired subsidiaries may have separate identity assurance processes that affect trust.
Recommendation — Verify lifecycle ownership for inherited accounts and credentials before go-live. Assess whether subsidiary identity proofing meets the buyer's trust requirements.
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Sprawl Unknown assets often hide exposed secrets and unmanaged credentials in acquired environments.
NHI-03 — Excessive Permissions Subsidiaries can retain overprivileged access that broadens acquisition blast radius.
Recommendation — Discover and rotate exposed secrets across all inherited systems before merger completion. Reduce inherited privilege to the minimum required for each acquired environment.

Practitioner Guidance

What to prioritise: Treat discovery as a gating activity, not a documentation exercise. If you cannot explain how every internet-facing asset and every subsidiary environment is owned, monitored, and remediated, the risk should be assumed higher than the summary says.

What to verify: Look for evidence that the target can produce a reconciled asset inventory, show exception handling for subsidiaries, and demonstrate who can actually decommission or rotate access on inherited systems. The absence of that evidence usually means the real exposure is still undiscovered.

Practitioner takeaway: In M&A, the biggest cybersecurity mistake is assuming the diligence view equals the operational reality, because hidden systems and separate subsidiary controls are where inherited risk most often survives.