Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/6/2015
06:00 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

Could Security Concerns Scuttle M&A And Investment Deals?

Questions of investor notification of Slack breach prior to signing shows how important security posture will be in vetting future deals.

Last week's breach of communication software start-up Slack offered a great example of how information security is not just a big consideration of customers and business partners, but also potential investors and acquiring companies. Increasingly, financial experts believe that the examination of a company's IT security posture should be as much a part of the due diligence process prior to investment or mergers and acquisition activity as an ROI analysis should be.

In the case of Slack, the breach occurred just after the company was rounding up $160 million in investment. According to a report from the Wall Street Journal, "It’s unclear when Slack discovered the breach or if new investors were told of it before they agreed to the deal." Because the funding story was the result of leaked information from confidential sources and the company is pretty closed-mouthed over the deal, it may be hard to ever know if the breach has or will materially impact the closing of Slack's latest funding round. But one thing you can bet on is that as large-scale breaches continue to gain awareness in the board room, M&A and other investment deals may include security contingencies to cover investors' backsides.

"I could foresee a situation in which, number one, a deal might go through, but one of the terms is that certain upgrades and certain measures be taken from a data security perspective between the time of signing and closing," says Scott Vernick, head of the data security and privacy practice at the law firm Fox Rothschild LLP. "And, two, I could see closing contingent upon there being no material adverse changes, just like anything else. I could also see certain holdbacks from the purchase price if the buyer determines that you've got to spend $5 million or $10 million or whatever it is to bring someone up to best practices or a more robust security environment."

As Vernick explains, though security evaluation adds yet another layer of complexity to the already arduous due diligence process, it is something that shouldn't be optional within the vetting process for M&A.

"If I was sitting on a board, now in addition to asking all the questions you would normally ask, like 'What's this going to do for us?' and Where do we see our ROI and how quickly will we realize it?' the next question is 'What liability from a data security persepctive are we taking on?'" he says. "Because the last thing that you want to do is end up doing a merger or acquisition and then becoming responsible for a whole other set of liabilities because you have no real understanding of what the data security is of the target."

This means understanding what kind of data it collects from customers, how it collects it, what other intellectual property assets it has, where it keeps that data, how long it keeps it and who has access to that data. Those should all be part of the baseline questions asked during due diligence, he says.

Also important is ensuring that whoever asks those questions has the technical knowledge to capably ask the right questions and analyze the answers to truly understand the picture of risk they paint. This may be a role that the CISO plays in the acquiring company.

"In a typical deal you have due diligence which is done by a combination of in-house resources,  outside counsel and an investment banker," Vernick says. "Now you're going to have to make sure that one of those three or somebody else that you bring on board  has the technical skill set to ask the right questions." 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google's new See No Evil policy......
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-24368
PUBLISHED: 2021-06-20
The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin WordPress plugin before 7.1.18 did not sanitise or escape its result_id parameter when displaying an existing quiz result page, leading to a reflected Cross-Site Scripting issue. This c...
CVE-2021-31664
PUBLISHED: 2021-06-18
RIOT-OS 2021.01 before commit 44741ff99f7a71df45420635b238b9c22093647a contains a buffer overflow which could allow attackers to obtain sensitive information.
CVE-2021-33185
PUBLISHED: 2021-06-18
SerenityOS contains a buffer overflow in the set_range test in TestBitmap which could allow attackers to obtain sensitive information.
CVE-2021-33186
PUBLISHED: 2021-06-18
SerenityOS in test-crypto.cpp contains a stack buffer overflow which could allow attackers to obtain sensitive information.
CVE-2021-31272
PUBLISHED: 2021-06-18
SerenityOS before commit 3844e8569689dd476064a0759d704bc64fb3ca2c contains a directory traversal vulnerability in tar/unzip that may lead to command execution or privilege escalation.