TL;DR: M&A creates a sharp identity governance problem because buyers inherit devices, applications, accounts, contractors, and policy conflicts before integration is complete, according to 1Password. The real control failure is assuming diligence can be deferred until after the deal closes, when access sprawl and orphaned identities are already in motion.
At a glance
What this is: This is an M&A identity governance analysis showing that access risk emerges during due diligence, not after integration starts.
Why it matters: It matters because IAM, PAM, and NHI programmes have to govern inherited access paths, contractor accounts, and policy conflicts before deal closure, when remediation options are still available.
Context
M&A identity risk is a governance problem that begins as soon as a deal is being discussed. The buyer inherits devices, applications, identities, contractors, and data before any integration work is complete, which means access decisions are being made under uncertainty rather than after a clean handover.
In practical terms, the security question is not whether the acquired company has controls, but whether those controls align with the buyer’s policies, logging, retention, and access model. When they do not, the result is privilege drift, orphaned access, and a longer period of unmanaged trust across both organisations.
The article frames this as an Access-Trust Gap problem across human users, third parties, and device access. That makes it an IAM and NHI governance issue at the same time, especially where contractors, BYOD, and SaaS access are already part of the acquisition footprint.
Key questions
Q: What breaks when M&A access governance is left until after integration starts?
A: Orphaned accounts, overprovisioned roles, contractor access, and conflicting policies become much harder to unwind once shared systems are live. The control failure is not just delayed cleanup. It is allowing access to persist during the period when ownership is least clear and exposure is easiest to inherit.
Q: Why do M&A deals create such a large identity risk before close?
A: Because the buyer inherits people, devices, applications, and third-party relationships before it has aligned control models. That creates a short period where access is active but governance is incomplete, so privilege can outpace the organisation’s ability to validate it.
Q: What are the signs that an acquisition has an access governance problem?
A: Look for incomplete documentation, weak responses to control requests, unresolved policy differences, contractor accounts with unclear ownership, and devices that have not been checked against the buyer’s trust requirements. Those are practical indicators that integration is moving faster than governance.
Q: How should teams handle contractor and BYOD access during M&A?
A: Treat both as inherited trust paths that need immediate ownership, inventory, and access validation. If contractors or personal devices can still reach sensitive systems after the deal closes, the organisation has not yet established effective control over its expanded access surface.
Technical breakdown
Why due diligence has to start before the deal closes
Due diligence is the only window where security can see the acquired environment before inherited access becomes operationally sticky. In M&A, discovery and validation have to run in parallel because documents, audits, and interviews only tell part of the story. Lightweight recon, pentesting, and policy review are used to test whether the organisation’s stated controls match its real access posture. The central mechanism is simple: once systems begin to merge, access paths multiply faster than governance can absorb them.
Practical implication: bring security into negotiations early enough to assess access, policies, and third-party exposure before integration decisions are locked in.
How conflicting policies create access and compliance drift
M&A frequently brings together two sets of compliance expectations, logging rules, data-retention practices, and privacy assumptions. Even if both companies are technically compliant on their own, the combined environment can become inconsistent as soon as shared access and shared data enter the picture. In identity terms, this is not just a policy problem. It is a control inheritance problem, where the stricter or clearer operating model often has to be applied across the merged environment to avoid ambiguity in authorisation and audit evidence.
Practical implication: map policy conflicts early and decide which control model governs shared identities, shared devices, and shared SaaS access.
Why orphaned accounts and overprovisioned roles appear so quickly
Post-deal chaos creates ideal conditions for ghost accounts, orphaned accounts, overprovisioned roles, and third-party contractor access that has not yet been reconciled. The risk is amplified when BYOD and unmanaged endpoints are part of the inherited estate, because access can outlive the device or relationship that enabled it. This is where lifecycle control matters most: provisioning, deprovisioning, and audit logging need to keep pace with organisational change, or access persists by default rather than by design.
Practical implication: verify account ownership, role scope, and offboarding status immediately after close, with special attention to contractors and BYOD access.
Threat narrative
Attacker objective: The attacker objective is to exploit the merger window to gain or retain access to sensitive systems and data before governance catches up.
- Entry occurs through the acquisition process itself, when the buyer inherits access paths, contractor relationships, and unmanaged endpoints before integration is complete.
- Credential and account exposure follows when ghost accounts, orphaned identities, and overprovisioned roles remain active across both environments.
- Escalation happens as conflicting policies and delayed deprovisioning expand the number of people and systems that can reach sensitive data.
- Impact is realised through data exposure, integration delays, privilege abuse, and the operational chaos that follows a poorly governed transition.
Breaches seen in the wild
- Klue OAuth Supply Chain Breach: OAuth tokens compromised in Klue integration breach affecting 700+ organisations via Salesforce data access chain.
- Canvas Instructure Data Breach: ShinyHunters exploits Canvas LMS platform to expose millions of student records via third-party NHI credential abuse.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Access governance in M&A fails when diligence is treated as post-close work. The article is clear that the highest-risk window is before the ink dries, when inherited access paths still look temporary but are already live. That is the point at which security teams can still identify third-party contractors, legacy systems, and policy conflicts before they become operational assumptions. The practitioner lesson is that M&A access governance is a pre-integration discipline, not a cleanup exercise.
Ghost accounts and overprovisioned roles are not side effects of integration. They are the predictable outcome of unresolved lifecycle ownership. Once two companies start sharing data and systems, identities without a clear owner become hard to challenge and even harder to remove. That is especially true for contractors and BYOD access, where the relationship between user, device, and business purpose is often weak. The implication is that lifecycle governance has to be anchored to ownership, not just directory records.
Conflict between compliance models is an identity problem as much as a governance problem. Different logging, retention, and privacy rules change how access should be granted, audited, and revoked. If security does not resolve which model governs merged access, the organisation ends up with inconsistent authorisation evidence and uneven enforcement. Practitioners should treat policy reconciliation as part of access architecture, not a separate legal or audit conversation.
M&A exposes an identity blast radius that extends across human users, third parties, and devices at the same time. The article’s Access-Trust Gap framing is useful because it captures how unmanaged devices, applications, and contractors create overlapping trust paths long before formal integration completes. That makes this one of the clearest cases for cross-domain identity governance, where IAM, NHI, and endpoint trust have to be assessed together. The practitioner conclusion is that M&A security fails at the intersections, not in isolated control domains.
From our research library:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
- Read next: Identity Security Programme Guide
What this signals
Access governance becomes a deal-critical control the moment two organisations begin to overlap. M&A turns identity from a steady-state programme into a transition-state programme, where inherited accounts, contractor relationships, and device trust all need immediate validation. Teams that wait for full integration will usually discover that the riskiest access was the access nobody had time to inventory.
Third-party access is often the fastest route to unmanaged trust in an acquisition. The buyer may inherit vendors, contractors, and BYOD endpoints that were acceptable in the target’s environment but do not fit the buyer’s control model. According to NHI Mgmt Group research, 92% of organisations expose NHIs to third parties, raising concerns about supply chain security. In M&A, that exposure is no longer abstract because it can arrive with the deal.
Access-Trust Gap: the merged environment inherits trust faster than governance can absorb it. The useful mental model here is that access can be technically functional long before it is operationally governed. Practitioners should expect the first risk spike to show up in identity ownership, device assurance, and contractor access reconciliation, not in the integration plan itself.
For practitioners
- Start security review at negotiation entry Pull security into Corp Dev workflows as soon as acquisition discussions begin so access, policy, and third-party risk can be assessed before signing.
- Run discovery and validation in parallel Use documentation review, interviews, lightweight recon, and targeted pentesting together so paper controls and real exposure are checked at the same time.
- Reconcile policy conflicts before shared access expands Compare logging, retention, and privacy rules across both organisations and decide which model governs shared identities and shared data.
- Inventory inherited third parties and contractors immediately Identify all contractor accounts, vendor relationships, and BYOD access paths so unmanaged external access does not survive the transaction.
- Verify provisioning, deprovisioning, and ownership after close Confirm who owns each inherited account, what role it has, and whether deprovisioning has already been completed for departed users or unused access.
Key takeaways
- M&A creates identity exposure before systems are merged because the buyer inherits access, contractors, devices, and policy conflicts in advance of full integration.
- The biggest governance failure is assuming security can wait until after close, when orphaned accounts and overprovisioned roles are already active.
- Teams that want to reduce deal risk need early security involvement, fast access inventory, and immediate reconciliation of ownership, trust, and control models.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 — Vulnerable Third-Party NHI | The article centres on inherited contractors and external access during acquisition. |
| NHI-01 — Improper Offboarding | Orphaned accounts and delayed deprovisioning are explicit risks in the post-deal window. | |
| NHI-05 — Overprivileged NHI | The article highlights overprovisioned roles as a common acquisition-era exposure. | |
| Recommendation — Inventory and validate third-party NHI access before integration expands the attack surface. Remove stale accounts and confirm ownership before inherited access becomes entrenched. Review inherited entitlements and cut excess privilege to the minimum required role. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | Merged environments need a clear entitlement model across both organisations. |
| Recommendation — Re-baseline authorisations so shared access matches the buyer's control model. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on account inventory, ownership, and lifecycle control during M&A. |
| Recommendation — Reconcile account ownership and disable unnecessary access as part of the acquisition plan. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | Inherited accounts and exposed contractor access create paths for credential abuse and spread. |
| Recommendation — Map acquisition-era access exposure to credential access and lateral movement detection. | ||
Key terms
- Access-trust gap: The gap between having a policy and actually enforcing it when access is requested. It appears when compliance, HR, or training data sits in separate systems from the access decision, allowing users to reach resources even though a required condition has not been met.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Lifecycle Ownership: Lifecycle ownership is the assignment of responsibility for creating, changing, reviewing, and retiring an identity or its access. For customer and non-human identities, weak lifecycle ownership usually shows up as orphaned access, inconsistent policy enforcement, and unclear accountability during change.
- Delegated Trust Path: A route into an environment created by an already-approved relationship such as OAuth, service account delegation, or API connectivity. These paths are attractive to attackers because they often inherit trust from the original configuration and can bypass direct user interaction.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org