What's Your Strategy When the Company Announces a Merger?
Mergers, Acquisitions and Divestitures require special handling
when bringing together two distinct organizations or separating a business from
the remaining IT infrastructure. The
technical environment can be rife with unsecure access points, un-patched
servers, excessive access controls, and incorrectly configured firewall settings
to name just a few. Information on
the acquired company technical environment may be non-existent or incomplete and
depending on the nature of the merger and it may be difficult to work with
people during the transition.
The idea of bringing together two organizations under one
leadership requires understanding the risks.
This risk analysis requires multiple tasks to uncover any underlying
vulnerabilities in the architecture.
So where do you start to untangle the colliding technical environments?
-
Vulnerability Scanning / Risk Assessments
-
Managed Security Services (Firewall / Intrusion Prevention)
-
Content Management
-
Remote Access / Business Connections
One of the most important tasks to be completed is a Security Audit
or Risk Assessment that includes at a minimum a comprehensive vulnerability scan
of the internal network, as well as the external scan from the Internet.
Ideally, these scans should be assessed by seasoned security
professionals, which can provide a true risk assessment and prioritize the
remediation necessary to secure the environment.
While many organizations are already transitioning their firewall
and intrusion prevention systems to 24/7 managed services, it is far more
critical that network traffic is monitored when connecting your production
network with an unknown network of another organization.
Rouge systems, Trojans, Spyware/Malware, viruses and disgruntled
employees can cause huge impacts to your own systems availability and compromise
your previously secure data.
Another major area to consider is that of Content Management.
Data leakage, insufficient controls on Internet access, email content and
inbound/outbound attachment need to be closely monitored and controlled to help
reduce the risk of introducing new threats to your own internal network and
production systems.
Finally, Remote Access and Business Partner Data Connections are
some of the more commonly overlooked areas that can also cause major issues.
Your own strict internal standards for authentication, encryption, and
controls on access may not be shared by the other organization.
In fact, in many cases you may find that their outside vendors,
contractors, developers, or business partners have unnecessary access and/or
excessive permissions within the network.
BAI Security can assist IT managers with the security and support
services needed for any business restructuring event quickly and accurately.
BAI Security has been providing solutions for customer mergers for over
eight years. We look forward to
assisting you with your IT Security Plan. For more information and
solutions to these issues contact
BAI Security today!
|