Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations evaluate after acquiring a company…
Governance, Ownership & Risk

What should organisations evaluate after acquiring a company with an unknown security posture?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

After an acquisition, organisations should evaluate the target’s current security posture before assuming controls are adequate. That means reviewing encryption practices, incident detection, compliance evidence, and whether critical assets were ever assessed during due diligence. Security gaps missed during integration can become inherited liabilities, so the buyer needs a clear view of risk before closing and immediately after.

What to evaluate first after an acquisition

The first task is not to assume the acquired environment inherits your controls, but to establish what is actually true today. Treat the target as a separate security estate until you have evidence for encryption coverage, logging and alerting, account inventory, privileged access, patch status, and the current state of critical systems that may never have been assessed during due diligence. Buyer confidence should come from verification, not integration assumptions.

That review should include the assets that matter most to business continuity and compromise impact: core data stores, externally exposed systems, identity infrastructure, remote access paths, and any crown-jewel applications that could create immediate exposure if they are weakly protected. If the deal process focused only on financial diligence, security diligence often needs to catch up fast after close.

For posture review at scale, a structured baseline helps. NHIMG’s Identity Security Posture Management (ISPM) Guide is useful here because it frames how to assess identity posture, standing access, and drift in a way that supports post-acquisition triage.

Which inherited security gaps matter most in practice?

The highest-value findings are the ones that can create immediate blast radius or hide active exposure. Common examples include long-lived credentials, overprivileged administrative access, weak or missing MFA, stale service accounts, unmonitored third-party connections, and encryption that exists on paper but is not consistently enforced. A merger can also leave duplicate tools and conflicting policies in place, which makes it easier to miss control gaps until they are exploited or cause an outage.

Evidence quality matters as much as the control itself. Compliance attestations, audit logs, asset inventories, incident records, and recent vulnerability remediation history tell you whether the posture is real or merely represented in policy. If the acquired company cannot show how it detects, investigates, and responds to security events, then you are not evaluating a mature control environment yet, you are evaluating an unproven one.

The review should also account for cloud and vendor dependencies, especially where inherited environments rely on shared tenants, third-party administrators, or opaque integrations. NHIMG’s AI Security Platform Buyer’s Guide is a useful example of how to compare security capabilities and vendor claims against concrete evaluation criteria, which is the same discipline buyers need when they inherit unfamiliar tooling.

How should buyers turn the assessment into action?

The practical goal is to separate what can be trusted now from what must be contained, rotated, or revalidated. Start by classifying the acquired environment into three buckets: controls that are demonstrably effective, controls that exist but need validation, and areas where the buyer should assume compromise potential until evidence is produced. That triage determines whether you can integrate quickly or need to impose temporary segmentation, access restrictions, or credential resets first.

Where inherited systems expose regulated data or critical transactions, the buyer should map the security review to the relevant control domains and confirm that security ownership is explicit after close. This is especially important when the acquired business has multiple cloud accounts, outsourced operations, or independent admin teams, because post-deal ambiguity is one of the fastest ways for risk to persist unnoticed.

For cloud-heavy acquisitions, the CSA Cloud Controls Matrix is a strong reference point for structuring the review across IAM, data security, audit, and governance domains. When the buyer needs a broader control catalogue for inherited environments, NIST SP 800-53 Rev 5 Security and Privacy Controls helps translate what you find into concrete control expectations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity & Access ManagementPost-acquisition reviews must validate inherited identity and access controls.
Recommendation — Review IAM ownership, privileged access, and account lifecycle before integrating the target.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAcquired environments often hide stale or excessive accounts and access paths.
Recommendation — Inventory and validate all accounts, then remove or recertify access that lacks evidence.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyM&A security posture evaluation is a risk-management decision before and after close.
ID.AM-02 — Hardware and software assets are inventoriedUnknown posture requires confirming what assets exist before trusting controls.
Recommendation — Define acquisition risk thresholds and require evidence-based signoff before full integration. Build and reconcile an asset inventory for the acquired estate before expanding trust.
ISO/IEC 27001:2022A.5.9 — Inventory of information and other associated assetsAcquisition review depends on knowing what assets and systems were inherited.
Recommendation — Reconcile the target asset inventory and close gaps before merging control domains.

Practitioner Guidance

What to prioritise: Prioritise controls that can create immediate breach impact or operational disruption, especially privileged access, external exposure, logging, and encryption of sensitive data. If any of those are undocumented, treat the environment as high uncertainty until validated.

What to verify: Verify evidence, not statements. Ask for current inventories, recent access reviews, incident and vulnerability records, and proof that critical assets were actually in scope for due diligence and post-close assessment.

Decision rule: If the acquired company cannot prove a control is operating, assume it is incomplete for integration purposes and contain the relevant asset or access path first, then remediate.

Practitioner takeaway: The safest acquisition assumption is that unknown security posture means unknown blast radius, so integration should follow verification and containment, not the other way around.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org