TL;DR: Mergers and acquisitions create five identity risk inflection points, from pre-acquisition visibility gaps to post-close sprawl, where orphaned accounts, overprovisioned access, and temporary trust can become durable exposure, according to Delinea. The central issue is that deal-speed assumptions outpace identity governance, so access decisions harden before teams can verify them.
At a glance
What this is: This is Delinea's analysis of how identity risk compounds across the M&A lifecycle, from due diligence through integration and long-tail monitoring.
Why it matters: It matters because acquisition programmes often expand access faster than governance can verify it, leaving IAM, PAM, and NHI teams to inherit unvetted privilege and unresolved access paths.
Context
M&A creates a governance problem because access decisions are often made under deadline pressure while the real identity estate is still only partially visible. In practice, that means the combined environment can inherit accounts, entitlements, and trust relationships that were never validated end to end.
The article frames three phases of the acquisition lifecycle: pre-acquisition, during acquisition, and post-acquisition. Each phase introduces a different way for identity risk to persist, which is why one-time due diligence rarely gives security teams a complete picture of exposure.
Key questions
Q: What breaks in M&A security when due diligence checks documents instead of enforced access?
A: Document-only due diligence misses the live entitlement state, so orphaned accounts, overprovisioned access, and policy drift can move into the combined organisation unchecked. That failure is not just incomplete visibility. It means leaders approve inherited identity risk without verifying who can actually do what, where, and why across the target environment.
Q: Why does temporary access become a persistent risk during acquisitions?
A: Temporary access often persists because transitional trust is created faster than ownership, expiry, and offboarding can be enforced. In acquisition settings, business continuity pressures make those exceptions feel normal, and once they are embedded across two organisations, they are hard to unwind without clear governance and accountability.
Q: What are the signs that identity debt is building after a deal closes?
A: Look for duplicated identities, unresolved ownership, conflicting entitlement models, and access decisions that no one can explain across the merged environment. Those signals show that integration has outpaced governance. When that happens, remediation gets more expensive because every new system depends on the unresolved baseline.
Q: How should security teams govern identity risk after M&A close?
A: They should keep monitoring access, trust relationships, and privilege changes long after the deal closes, because integration risk does not end at a milestone. The goal is continuous verification of who still has access, which exceptions remain active, and where new exposure is forming as systems stabilise.
Technical breakdown
Why pre-acquisition identity visibility fails
Pre-acquisition due diligence often checks what is documented rather than what is enforced. That creates blind spots around orphaned accounts, overprovisioned entitlements, and policy drift between stated controls and actual access behaviour. In identity terms, the target may look governed on paper while the live environment still contains residual privileges and unmanaged access paths. This is especially dangerous in M&A because leaders are approving business risk before they can see the access graph clearly. The result is inherited exposure, not just inherited systems.
Practical implication: validate enforced access, not just policy documents, before the deal is signed.
How temporary access becomes durable exposure
The during-acquisition window is structurally unstable because business continuity often depends on temporary cross-organisation trust. The problem is that temporary access arrangements tend to persist once they are created, especially when oversight is split across two identity models. Privileged access can grow faster than governance can consolidate it, so access meant to bridge the transition becomes part of the permanent operating state. In M&A, the control failure is not access itself but the lack of a clear expiry and consolidation path for transitional privilege.
Practical implication: treat every transitional entitlement as time-bounded and subject to explicit offboarding.
What identity debt looks like after close
Post-close identity sprawl happens when teams merge systems faster than they can reconcile identities, permissions, and control ownership. Early integration shortcuts create identity debt, which then compounds as applications, directories, and access workflows are combined. At that point, each unresolved entitlement is harder to unwind because it sits inside a larger, more interdependent environment. The security risk is not a single misconfiguration but the accumulation of small, unchallenged access decisions that become operationally sticky.
Practical implication: sequence integration so identity reconciliation precedes broad access consolidation.
Threat narrative
Attacker objective: The objective is to exploit acquisition-driven identity confusion to gain or preserve access inside the combined environment without immediate detection.
- Entry occurs through incomplete pre-acquisition visibility, where orphaned accounts and overprovisioned access remain undiscovered in the target environment.
- Escalation follows when temporary cross-organisational trust and privileged access are allowed to persist without unified governance.
- Impact is the creation of durable identity exposure that survives close, complicates auditability, and expands the attack surface long after integration milestones are met.
Breaches seen in the wild
- Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Internet Archive breach 2024: An exposed GitLab token opened Internet Archive code and 31 million user records; unrotated Zendesk tokens let the attacker back in weeks later.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity risk in M&A is a governance problem, not a diligence checklist problem. The article shows that leaders often verify documentation instead of enforced access, which means the risk is not just missed accounts but inherited trust that was never truly validated. In NHI and IAM terms, the control gap is the gap between what a programme believes exists and what the live environment actually permits. Practitioners should treat acquisition diligence as continuous identity verification, not a one-time questionnaire exercise.
Temporary access in M&A creates a standing-privilege trap. During-acquisition trust is frequently justified as transitional, yet transitional access has a habit of becoming default access when no one owns the sunset. That is the same structural problem identity teams see with long-lived privilege in other environments: what begins as business continuity becomes persistent exposure. The practitioner lesson is that deal speed does not reduce governance obligations; it compresses the time available to enforce them.
Identity debt is the right concept for post-close sprawl. The article describes how early integration shortcuts harden into structural weakness as dependencies grow, and that is exactly how unresolved identity decisions become expensive to reverse. Identity debt: access, policy, and ownership decisions made under transition pressure that later constrain remediation and raise blast radius. For practitioners, the implication is to measure integration by the reduction of unresolved access, not by the speed of consolidation.
Continuous monitoring is the only defensible end state for acquisition risk. M&A changes the identity attack surface long after close, so the programme cannot stop at a single assessment or an integration milestone. The field should stop treating acquisition security as a project with a finish line and start treating it as an operating condition with ongoing evidence requirements. That shifts M&A from a moment of change to a permanent governance posture.
Acquisition pressure exposes a broader assumption flaw in access governance. Identity programmes often assume that access changes can be safely made first and verified later. M&A breaks that assumption because access is expanding before controls are merged, and the combined organisation may never return to a clean baseline without deliberate intervention. The implication is that governance models must account for transition states, not just steady-state environments.
What this signals
Identity governance in M&A needs to move from point-in-time review to continuous verification. Once trust spans two organisations, the question is no longer whether access was approved at one stage of the deal, but whether it still matches the live environment after integration changes. Acquisition teams that rely on static sign-off are effectively betting that no one has expanded privilege faster than the control plane can catch up.
Identity debt is the hidden cost of moving too fast. Every unresolved entitlement, duplicated directory record, and unowned exception increases the amount of work required to stabilise the combined estate. The fastest way to reduce acquisition risk is to avoid turning temporary access into a permanent operating assumption.
Acquisition programmes should treat post-close monitoring as part of the deal, not a follow-on task. The combined environment keeps changing after close, which means the identity attack surface keeps changing too. Security teams that keep reviewing privilege drift, orphaned accounts, and cross-domain trust are better positioned to preserve deal value without inheriting avoidable exposure.
For practitioners
- Validate enforced access before sign-off Compare documented entitlements with live access, orphaned accounts, and actual policy enforcement in the target environment before deal completion.
- Define expiry for transitional trust Make every temporary cross-organisational entitlement time-bounded, owned, and subject to a documented removal trigger.
- Sequence identity reconciliation ahead of consolidation Resolve directory overlaps, entitlement collisions, and ownership gaps before merging access models or shared workflows.
- Track identity debt as an integration metric Measure unresolved accounts, duplicated permissions, and unassigned access ownership throughout early integration.
- Maintain post-close behavioural monitoring Continue reviewing privilege expansion, dormant accounts, and new trust relationships after integration milestones are declared complete.
Key takeaways
- M&A creates identity risk because access is often expanded before governance is fully reconciled across the combined environment.
- The article's core warning is that temporary trust, orphaned accounts, and unresolved entitlements can become durable exposure if teams move too quickly.
- Security teams should verify enforced access, define expiry for transitional privilege, and keep monitoring identity behaviour after close.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | M&A risk includes orphaned access that outlives employment or vendor relationships. |
| NHI-05 — Overprivileged NHI | The article repeatedly cites overprovisioned entitlements and temporary trust turning permanent. | |
| Recommendation — Revoke inherited accounts and remove access paths before they become permanent liabilities. Review acquired entitlements for least-privilege violations and shrink excess scope before consolidation. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The core issue is unmanaged permissions across merged environments. |
| Recommendation — Inventory and validate access permissions across both organisations before broad integration. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account sprawl and unresolved ownership are central to the post-close risk described. |
| Recommendation — Centralise account ownership and remove stale or duplicated accounts during integration. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | The article flags violations of least-privilege principles through excess access during M&A. |
| Recommendation — Apply least-privilege reviews to every inherited entitlement before the combined estate stabilises. | ||
Key terms
- Identity Debt: Identity debt is the accumulation of unowned, over-permissioned, or poorly governed non-human identities that security teams cannot cleanly inventory or retire. It usually grows when experimentation outruns access governance, leaving service accounts and tokens active long after their original purpose has passed.
- Transitional Trust: Transitional trust is temporary cross-organisational access granted to keep work moving during a deal or migration. It becomes a security problem when no expiry, ownership, or review path exists, allowing emergency access to harden into persistent privilege.
- Enforced Access: Enforced access is the set of permissions that actually works in the live environment, not just what is written in policy or documentation. Security teams use it to separate assumed control from real control during due diligence, integration, and post-close monitoring.
- Identity Sprawl: Identity sprawl is the uncontrolled growth of identities, entitlements, and credentials across an environment. For NHIs, it usually appears when automation creates accounts faster than governance teams can inventory, review, and remove them. The result is hidden access, weak accountability, and a wider attack surface.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org