TL;DR: A global chemical manufacturer found 79 security weaknesses, 27 compromised credentials, and four paths to domain compromise in 35 minutes during merger due diligence, with escalation reaching ransomware exposure across nearly 200,000 sensitive files, according to Horizons.ai. The evidence shows why acquisition planning must validate identity and lateral-movement risk, not just patch status.
NHIMG editorial — based on content published by Horizons.ai: From Patch Tuesday to Pentest Wednesday®: How a Global Chemical Manufacturer De-Risked a $2B Merger
By the numbers:
- Within 35 minutes, four unique paths to domain compromise were proven by exploiting Zerologon and noPAC vulnerabilities.
Questions worth separating out
Q: What breaks when acquired environments keep inherited identity trust paths?
A: When inherited trust paths are left in place, a single compromised credential or vulnerable domain relationship can become a route to enterprise compromise.
Q: Why do compromised credentials matter more than vulnerability counts in M&A security?
A: Vulnerability counts show exposure, but compromised credentials show usable access.
Q: How do security teams know if microsegmentation is actually reducing blast radius?
A: They should test whether a compromised asset can reach adjacent systems, whether denied flows are being logged, and whether containment happens without manual rework.
Practitioner guidance
- Map inherited identity trust before integration Inventory domain trusts, administrative reuse, privileged groups, and endpoint authentication paths before the acquired environment is joined to the parent estate.
- Test segmentation between business zones first Validate that production, corporate IT, remote site, and OT segments remain isolated under realistic attack conditions before expanding test scope.
- Prioritise compromised credential pathways over raw vulnerability counts Use offensive validation to identify which endpoints, accounts, and services can actually be chained into compromise.
What's in the full article
Horizons.ai's full blog covers the operational detail this post intentionally leaves for the source:
- Step-by-step remediation sequencing for the highest-risk weaknesses found during the baseline pentest.
- The follow-up validation approach used to confirm that prior fixes actually closed the compromise paths.
- Operational detail on safe testing in hybrid IT and OT environments without disrupting production networks.
- The rollout pattern across 20 additional sites, including how local teams were empowered to retest.
👉 Read Horizons.ai's analysis of M&A due diligence, domain compromise, and pentest validation →
Domain compromise paths in M&A due diligence: what did teams miss?
Explore further
Acquisition security fails when inherited identity paths are treated as background noise. The article shows that merger due diligence is not just about whether a target is patched, but whether its identity and trust relationships can be traversed into domain compromise. That is a governance failure, because acquisition teams often inherit access graphs before they understand them. Practitioners should treat pre-integration identity mapping as a mandatory control, not a post-close cleanup task.
A few things that frame the scale:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when merger due diligence misses domain compromise paths?
A: Accountability should sit with both the acquiring security function and the integration leadership that approves trust expansion. If due diligence misses reachable domain compromise paths, the failure is in risk acceptance and evidence quality, not just in controls. Frameworks such as NIST CSF and NIST SP 800-53 both expect control validation, traceability, and risk-informed decision-making.
👉 Read our full editorial: Merger due diligence exposed identity-driven attack paths in minutes