Application Security

7/9/2018
05:30 PM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

6 M&A Security Tips

Companies are realizing that the security posture of an acquired organization should be considered as part of their due diligence process.
Previous
1 of 7
Next

Image Source: Shutterstock via Sylverarts Vectors

Image Source: Shutterstock via Sylverarts Vectors

There’s a growing sense that companies need to take a closer look at security when considering a merger or acquisition.

A global survey of dealmakers by Mandiant, a FireEye company, found that 78% of respondents believe that cybersecurity is not analyzed in great depth or specifically quantified as part of the M&A due diligence process.

"Although most security teams feel strongly that the security posture of an acquired organization should be considered in an acquisition decision, it often does not play a significant role in the deal team's due diligence process," says Charles Carmakal, vice president and CTO of strategic services at Mandiant. "The reality is that security generally only plays a role during the acquisition if there's a significant breach. In that situation, the security team would evaluate if the asset is too toxic and has lost value."

Chad Holmes, chief services and operations officer at Optiv, adds that cybersecurity has risen in importance because many more companies are acquiring digital assets as part of their digital transformation initiatives. He cited a a study from Capgemini Consulting that finds 87% believe that digital transformation gives them a competitive advantage.   

We talked with Carmakal and Holmes to develop this list of M&A security tips. For more information, check out the Mandiant study, "The Benefits of Cybersecurity Diligence in Mergers and Acquisitions."

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
What We Talk About When We Talk About Risk
Jack Jones, Chairman, FAIR Institute,  7/11/2018
Ticketmaster Breach Part of Massive Payment Card Hacking Campaign
Jai Vijayan, Freelance writer,  7/10/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14084
PUBLISHED: 2018-07-16
An issue was discovered in a smart contract implementation for MKCB, an Ethereum token. If the owner sets the value of sellPrice to a large number in setPrices() then the "amount * sellPrice" will cause an integer overflow in sell().
CVE-2018-14085
PUBLISHED: 2018-07-16
An issue was discovered in a smart contract implementation for UserWallet 0x0a7bca9FB7AfF26c6ED8029BB6f0F5D291587c42, an Ethereum token. First, suppose that the owner adds the evil contract address to his sweepers. The evil contract looks like this: contract Exploit { uint public start; function swe...
CVE-2018-14086
PUBLISHED: 2018-07-16
An issue was discovered in a smart contract implementation for SingaporeCoinOrigin (SCO), an Ethereum token. The contract has an integer overflow. If the owner sets the value of sellPrice to a large number in setPrices() then the "amount * sellPrice" will cause an integer overflow in sell(...
CVE-2018-14087
PUBLISHED: 2018-07-16
An issue was discovered in a smart contract implementation for EUC (EUC), an Ethereum token. The contract has an integer overflow. If the owner sets the value of buyPrice to a large number in setPrices() then the "msg.value * buyPrice" will cause an integer overflow in the fallback functio...
CVE-2018-14088
PUBLISHED: 2018-07-16
An issue was discovered in a smart contract implementation for STeX White List (STE(WL)), an Ethereum token. The contract has an integer overflow. If the owner sets the value of amount to a large number then the "amount * 1000000000000000" will cause an integer overflow in withdrawToFounde...