Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/9/2019
10:00 AM
Joe Payne
Joe Payne
Commentary
Connect Directly
LinkedIn
RSS
E-Mail vvv
100%
0%

Insider Threats: An M&A Dealmaker's Nightmare

Because data has never been more portable, taking it has never been easier. And that's a huge problem during mergers and acquisitions.

When it comes to insider threats, business and security leaders are facing a harsh reality. Last year, there were 50,000 mergers and acquisitions (M&A) transactions worldwide, with a total value of about $4 trillion. The biggest concerns for dealmakers? They were not what you might expect. For more than a quarter of them, it wasn't typical issues related to valuation, integration, or execution; instead, it was insider threat and other cybersecurity issues.

The risk of data loss or data theft increases during M&A. Employees, especially at the sell-side company, will hedge their bets and prepare for the worst. "What does this deal mean for me? Is my job safe?" In times of uncertainty, even the best employees may take actions that are out of character in order to keep data that they believe belongs to them.

Consider a developer with high-demand skills at an artificial intelligence startup that was just acquired by the market leader. As part of the deal, the buy-side company announces a reorg. Hearing about the pending layoffs, a recruiter for the competition begins poaching talent with the promise of a big compensation package. Worried about losing his job, the developer accepts the offer. Before he leaves, he transfers some source code to personal cloud storage, thinking it might be useful in his new role. Now, your intellectual property (IP) has walked out the door.

Investing big in a merger or acquisition only to discover that you've lost valuable data is a dealmaker's nightmare. And because data has never been more portable, taking it has never been easier. Employees can store hundreds of gigabytes on their mobile devices, put 1TB or more of data on removable media, or, like the developer, quickly transfer data to personal cloud storage services.

When you consider Deloitte's estimate that IP can account for as much as 80% of a company's value, it should not be surprising that securing the transition of that data will directly affect the success — or failure — of an M&A deal. To better protect their investment, it's time for buy-side companies to take a more holistic approach to data loss protection from insider threats.

Demise of the Castle Metaphor
Since the dawn of technology, security has been built around a castle metaphor. The idea is that your network and data is inside a castle that you need to fortify and safeguard. If you build a big enough "moat," everything will be fine. This philosophy assumes that cybercriminals and malicious attacks are outside the moat, and that anything and anyone inside the walls of the castle should be inherently trusted.

However, the notion that you can trust everyone "inside" and prevent all of your sensitive or confidential data from being exfiltrated or compromised is flawed thinking. Data loss "prevention" is a ridiculous promise. Losing data is inevitable.

The Broken Promises of Legacy DLP
To guard against insider threat and data loss during M&A, many buy-side companies opt for a traditional data loss prevention (DLP) solution. They install DLP software on the endpoints of the sell-side company and put strict policies in place to ensure sensitive data doesn't leave the castle.

The problem is that these restrictive policies get in the way of employees getting their jobs done. The policies fail to account for new data being created as the companies work together through the M&A process. They also throw off alerts every time a user moves data that has been classified as sensitive. For many employees, however, moving sensitive data is a completely normal and necessary part of their everyday work. The end result for security teams? Rigid classification rules that simply can't keep up and a flurry of false alerts that are nothing more than noise.

Protect Everything and Trust No One
There is a better way to safeguard data and streamline the M&A process. Rather than trying to identify and tag select files as sensitive, organizations should have visibility to all their data and where it lives and moves.

This approach fundamentally shifts the emphasis of a data security program from prevention to protection by focusing on speed of detection and response. It works based on the assumption that all data is important. Sales pipelines, forecasts, competitive campaigns, customer contact information, product road maps, prototype drawings — they're all critical IP. And when you buy a company, you should be entitled to all the parts.

This next-generation approach to DLP also assumes that you trust no one. In other words, next-gen DLP software doesn't care if an employee is a trusted user or not. It works at the data level, tracking and monitoring all data activity and flagging anomalies, while keeping copies of all files for fast retrieval and analysis. In an M&A situation, you want to see the data you're paying for, keep it, and protect it if it is threatened. Data blind spots will only leave your deal open to more risk.

When done right, M&A is a great way to grow a company and gain a competitive edge. Having the right data security strategy and tools in place will keep your process on track, while protecting your investment. You don't want to find yourself in the middle of a data security investigation the next time you're ready to strike a deal.

Related Content:

 

Black Hat USA returns to Las Vegas with hands-on technical Trainings, cutting-edge Briefings, Arsenal open-source tool demonstrations, top-tier security solutions and service providers in the Business Hall. Click for information on the conference and to register.

 

Joe Payne brings to Code42 more than 20 years of leadership and a proven track record with high-growth software companies. He has a broad experience base in delivering software and software-as-a-service (SaaS) solutions to enterprises across numerous industries. As President ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13640
PUBLISHED: 2019-07-17
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
CVE-2019-5222
PUBLISHED: 2019-07-17
There is an information disclosure vulnerability on Secure Input of certain Huawei smartphones in Versions earlier than Tony-AL00B 9.1.0.216(C00E214R2P1). The Secure Input does not properly limit certain system privilege. An attacker tricks the user to install a malicious application and successful ...
CVE-2019-1919
PUBLISHED: 2019-07-17
A vulnerability in the Cisco FindIT Network Management Software virtual machine (VM) images could allow an unauthenticated, local attacker who has access to the VM console to log in to the device with a static account that has root privileges. The vulnerability is due to the presence of an account w...
CVE-2019-1920
PUBLISHED: 2019-07-17
A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a lack of complete error handling conditi...
CVE-2019-1923
PUBLISHED: 2019-07-17
A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device configuration interface. An attacker could exploit this vulnerability by access...