By NHI Mgmt Group Editorial TeamBased on Unosecur: “Six Identity Security Risks in M&A and How to Prevent Them” (June 4, 2026)

TL;DR: Unosecur reports that mergers and acquisitions can double cybersecurity incident risk during integration, while mismatched IAM stacks, provisional access, SoD conflicts, compliance gaps, and inherited breaches expand exposure. Merger governance fails when identity consolidation is treated as back-office work instead of a security prerequisite.


At a glance

What this is: This guide explains six identity security risks that surface during M&A and argues that the attack surface expands fastest when identity integration is delayed or handled informally.

Why it matters: It matters because IAM, PAM, IGA, and compliance teams have to secure two control planes at once, or inherited access, toxic role combinations, and post-deal exposure can persist into the merged business.

👉 Read Unosecur's analysis of M&A identity security risks and governance failure


Context

M&A identity security is the problem of reconciling access, roles, and control ownership across two organisations without creating new exposure. In practice, the hardest part is not combining systems, but proving that every account, entitlement, and exception remains justified while the integration is still moving.

Unosecur frames the issue through six common failure modes: disparate IAM tools, a larger identity attack surface, provisional access, segregation of duties conflicts, compliance drift, and inherited compromises. The central governance gap is predictable, even when the business event is not: identity controls are often treated as an afterthought rather than a prerequisite for closing the deal.

For IAM and security teams, the real question is whether merger governance can keep pace with the speed of access grant, role change, and compliance inheritance. Where that answer is no, attackers gain a temporary window and audit teams inherit the cleanup.


Key questions

Q: What breaks when identity integration is delayed in a merger?

A: When identity integration is delayed, the merged organisation inherits inconsistent authentication, uneven access policy, and manual exception handling. That creates a security gap and slows user productivity because access decisions remain split across two operating models. The practical fix is to establish one authoritative identity layer early so policy harmonisation can happen before broad user onboarding.

Q: Why do mergers and acquisitions increase privileged access risk so quickly?

A: M&A combines different identity models, different infrastructures, and different levels of PAM maturity under a single operating timeline. That creates pressure to enable access fast, often before controls are harmonised. The risk rises when domain trusts, cloud access paths, and service account ownership are not reconciled early, because the combined environment becomes easier to abuse and harder to audit.

Q: Why do segregation of duties controls fail after mergers or reorganisations?

A: They fail because inherited access and approval chains often remain intact after the operating model changes. Two merged environments may have conflicting role definitions, duplicate privileges, and old admin paths that no longer match the new reporting structure. Without a full access rationalisation, SoD becomes a patchwork of exceptions rather than a control.

Q: What should security teams do immediately after an acquired company joins?

A: They should validate inherited access before it becomes part of the normal baseline. That means checking for stale credentials, hidden administrator accounts, unrevoked third-party access, and unverified high-privilege entitlements. The purpose is to find pre-existing compromise conditions before broader integration gives them durability.


Technical breakdown

Why disparate IAM stacks create control gaps

When two companies use different directories, authentication methods, and policy sets, the merged environment does not start as one identity plane. It starts as two partially overlapping control systems with conflicting assumptions about trust, naming, entitlement structure, and approval flow. That mismatch makes it easy for weak joins, duplicate accounts, and inconsistent MFA enforcement to slip through the transition. Identity Security Posture Management helps reveal where the combined estate is not yet governable, but the technical issue is broader: policy equivalence has to be proven before access can be normalised.

Practical implication: reconcile directory, authentication, and entitlement policy before broad user migration begins.

How provisional access widens the identity attack surface

M&A creates a surge in temporary access because business continuity pressure overrides normal verification. Users, contractors, and administrators often receive accounts before the merged organisation has finished validating identity, role, or need-to-know. That is not just a process flaw. It expands the number of live entry points, increases the pool of privileged accounts, and creates a period where least privilege is suspended in practice even if it still exists on paper. Just-in-time access and mandatory MFA reduce this exposure, but only if temporary access is truly time-boxed and reviewed.

Practical implication: treat every provisional account as high risk until verification, scope, and expiry are confirmed.

Why SoD conflicts emerge during role consolidation

Segregation of Duties breaks down in mergers because roles are inherited from two different operating models and then remapped under deadline pressure. A person who was safe in one company can become toxic when their permissions are combined with a new approval or payment path in the other. The risk is not only fraud. It is also accidental control bypass caused by overlapping authority during transition. Access reviews and automated SoD checks are needed because manual oversight cannot keep up with rapid org-chart change and temporary role stacking.

Practical implication: run access certification against combined roles, not legacy role sets from each company.


Threat narrative

Attacker objective: The attacker aims to exploit merger confusion to gain broader identity access, retain footholds, and reach sensitive data or administrative control inside the combined environment.

  1. Entry begins when the acquiring organisation inherits accounts, integrations, and credentials that were already present in the target environment before close. Those identities often arrive without full assurance about who owns them or whether they were ever fully reviewed.
  2. Escalation follows when provisional access and role overlap create privileged paths that were never meant to coexist. The merged business then has more admin accounts, more exceptions, and more opportunities for misuse or compromise.
  3. Impact comes when weak inherited controls, unverified access, or compliance drift let an attacker or insider move from simple account presence to unauthorised data access, fraud, or post-merger breach persistence.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Merger governance breaks first at the identity boundary. M&A programmes often focus on legal close, systems consolidation, and operational continuity before they prove that the combined identity estate is controllable. That sequencing is backwards. When access, roles, and approvals are merged before they are reconciled, the organisation inherits ambiguity as well as infrastructure. The practical conclusion is that identity control validation has to be treated as a deal dependency, not a post-close clean-up task.

Provisional access is an access-governance exception that becomes a security model if it lasts too long. During mergers, temporary access is often justified by urgency, but urgency does not change the control objective. If the merged organisation cannot bound those exceptions, least privilege becomes aspirational rather than operational. Practitioners should read that as a sign that IAM Ops, PAM, and access certification are not supporting functions in M&A. They are the mechanism that decides whether the deal widens risk or contains it.

SoD conflict is the hidden control failure most merger plans under-estimate. A role combination that is acceptable in one entity can become toxic once entitlements are combined across the new organisation. That makes merger governance a segregation problem as much as an identity problem. The implication is that access reviews must evaluate the post-merger operating model, not the pre-merger org charts, or conflict will be created by the integration itself.

Inherited breach risk proves that identity due diligence is a security control, not just diligence theatre. The Starwood example shows how a compromised environment can outlive the transaction that absorbed it. That failure mode is not simply poor hygiene. It is a governance assumption that the acquired estate is safe enough to onboard before it is fully inspected. Practitioners should conclude that pre-close and immediate post-close identity assessment must be capable of finding hidden access, stale credentials, and lingering admin paths before business integration normalises them.

Identity blast radius is the right concept for merger risk. The combined company does not just add users. It adds privileged accounts, exceptions, integrations, and inherited trust relationships that enlarge the space an attacker can exploit. That changes the security question from how many systems are being consolidated to how much damage one compromised identity can now cause. Teams should use that lens to prioritise which identities, not just which systems, are allowed to cross the merger boundary.

What this signals

Identity consolidation has to be designed as a control exercise, not an IT migration. M&A programmes that treat identity as a downstream implementation detail usually discover that access logic, privilege structure, and compliance obligations do not align on their own. The merged organisation needs a single view of accounts, roles, and exceptions before business integration can safely scale.

Post-close access reviews should target the merged operating model. Legacy review cycles built around the pre-deal organisation will miss toxic combinations created by the integration itself. That is why merger governance needs to assess where privilege now intersects, not where it used to sit in each company.


For practitioners

  • Map both identity estates before integration Inventory directories, privileged accounts, service accounts, and authentication methods on both sides before broad migration starts. The goal is to identify duplicate trust paths, orphaned identities, and policy mismatches that could survive the merger.
  • Time-box every provisional access grant Require named owners, expiry dates, and review checkpoints for all temporary accounts, VPN access, and emergency roles used during the deal. Access that is justified by urgency should still be revocable, traceable, and tied to a business need.
  • Run post-merger SoD analysis on combined roles Evaluate duty conflicts after entitlements are merged, not before. A role that looks harmless in one company may create a toxic combination once purchase, approval, and payment paths are unified.
  • Validate inherited credentials and admin paths immediately after close Search for stale passwords, missing MFA, hidden administrator accounts, and unrevoked third-party access in the acquired environment before broader access normalisation occurs. The objective is to find compromise conditions before they become part of the merged baseline.

Key takeaways

  • M&A expands identity risk because two access models, two role structures, and two governance regimes have to be reconciled under time pressure.
  • The most dangerous failure modes are provisional access, SoD conflicts, and inherited compromise, because they create a larger attack surface before the merged entity has stable control.
  • Security teams should treat identity reconciliation, privileged access review, and inherited credential validation as deal-critical work rather than post-close remediation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKTA0006; TA0008 — Credential Access; Lateral MovementM&A identity gaps create conditions for credential abuse and movement across the merged environment.
Recommendation — Map merger exposure to TA0006 and TA0008, then prioritise inherited credentials and broad access paths.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centres on reconciling entitlements and access rights across two organisations.
Recommendation — Apply PR.AA-05 to reconcile entitlements before merging user populations or privileged roles.
CIS Controls v8CIS-5 — Account ManagementAccount sprawl, stale access, and inherited identities are the core operational risks in the article.
Recommendation — Use CIS-5 to inventory, validate, and retire accounts inherited through the transaction.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeProvisional access and over-privileged users are direct least-privilege failures in merger integration.
Recommendation — Enforce AC-6 so temporary access and role consolidation do not outgrow business need.
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingM&A often leaves behind accounts and third-party access that should have been removed or revalidated.
Recommendation — Audit offboarding gaps and revoke inherited NHI access that is no longer required.

Key terms

  • Identity Security Posture Management: Identity security posture management is the continuous assessment of identity configuration, privilege, and exposure across an environment. It focuses on drift, overprivilege, and control gaps so teams can see where IAM, PAM, and NHI governance are failing before those gaps become incidents.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Identity Attack Surface: Identity attack surface is the total set of accounts, tokens, login endpoints, trust paths, and supporting systems that can be probed for access. For password spraying, the risk grows with every externally reachable authentication path and every dormant or weakly protected identity.
  • Provisional access: Temporary access granted to keep business operations moving during a transition such as a merger or acquisition. It becomes risky when expiry, ownership, or review is missing, because temporary rights can silently become standing privilege.

What's in the full article

Unosecur's full blog covers the operational detail this post intentionally leaves for the source:

  • The six-risk breakdown with practical examples from merger and acquisition environments
  • Specific mitigation patterns for ISPM, IAM Ops, PAM, and ITDR in post-deal integration
  • The FAQ guidance on access reviews, SoD, and inherited breach validation
  • The consulting perspective on how to sequence identity security before and after close

👉 The full Unosecur post covers the six M&A identity risks and mitigation themes in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org