Post-Close Technology Integration: The First 100 Days

17 minute read
Intermediate

Turning diligence findings into a funded plan, the day-one network decision, identity sequencing, and what a sponsor owes its LPs after close.

From Findings to a Funded Plan

The translation is mechanical. It is skipped because it is nobody's job: the diligence advisor's engagement ended at close, the deal team moved to the next process, and the operating partner received a document rather than a programme.

Five Rules for the Translation

Every finding becomes one of four things. A day-one action, a 100-day workstream, a year-one budget line, or an accepted risk with a named accepter and a review date. There is no fifth category, and "monitor" is not one of them. A finding that lands in none of the four will be rediscovered by an incident.

Every item has one named owner. An individual, not a function. "IT" owns nothing. "The MSP" owns nothing. A named person with the authority to spend the budget attached to the item owns it.

Every item has an identified funding source before day one. The escrow, the capital budget, platform operating expense, or the seller under a specific indemnity. Items with no funding source do not happen, and the moment to discover that is before close rather than in month four. The most common version of this failure: the report identified 3.2 million dollars of remediation, the deal model carried 800,000 dollars, and nobody reconciled the two before signing. Illustrative figures, extremely common shape.

Every item has a sequence position and explicit dependencies. Roughly half of remediation work is blocked by other remediation work. Asset inventory blocks nearly everything downstream of it. Service account inventory blocks credential rotation. Logging blocks detection. A plan that lists thirty items without dependencies is a wish list.

Every item has an evidence standard for completion, defined at the start. Not "MFA implemented." Rather: "MFA enforced on 100 percent of privileged accounts, evidenced by a conditional access policy export plus a sign-in log review showing zero successful legacy authentication against in-scope accounts." Define it before the work starts and closure becomes a fact rather than an assertion.

Where the Money Comes From

Trace each item to its instrument, because the instrument carries obligations the plan has to respect.

If a finding was priced into the deal through a purchase price adjustment, the money is already in the platform and the plan simply spends it. If it sits in an escrow with release tied to verified remediation, the remediation schedule is now a contractual obligation with a clock attached, and missing the date can cost the escrow. If it is covered by a specific indemnity, someone has to actually make the claim, within the survival period, with the notice mechanics the agreement specifies. Those mechanics are covered in Turning Diligence Findings Into Deal Terms.

If it was none of the above, the platform funds it, and the operating partner should know that number before close rather than discovering it as a variance.

Governance

Chair the programme at the operating partner or portfolio CTO level, not at the level of the target's incumbent IT manager, who is simultaneously being assessed for retention and asked to report on the deficiencies of the estate he built. Weekly for the first thirty days, fortnightly to day 100. Escalate anything that moves a dependency or changes a number.

One discipline matters more than the rest: carry the same finding identifiers from the diligence report into the plan and into the reporting. The investment committee was told about finding 14. The 100-day plan should contain finding 14. The day-30, day-60 and day-100 reports should say what happened to finding 14. That unbroken trace is what makes the plan auditable, and it is what the final section of this article is about.

A First 100 Days Sequence

Phase 0: Signing to Close

Use this period if you have it. Most of it is preparation that costs nothing and saves weeks.

  • Decide the day-one network connection posture and write the decision down, with the reasoning.
  • Build the credential rotation scope: which credentials, held by whom, rotated in what order, with which application testing required.
  • Agree the incident response contact path that applies from minute one after close, and put a retainer in place if the target does not have one.
  • Secure the seller's post-closing cooperation obligations in the agreement: access to personnel, access to historical data and logs, and assistance with third-party consents. These expire, and they expire sooner than you will need them.
  • Obtain the list of every third party with access to the target's environment. Assume it is incomplete.

Phase 1: Day 1 to 14, Control and Visibility

  • Rotate every administrative credential and every long-lived key and secret. This is the single highest-value action in the first 100 days and it is routinely deferred to a later phase where it never happens.
  • Enforce multi-factor authentication on all remote access and all privileged accounts. Phishing-resistant factors for administrators where the estate supports it.
  • Deploy endpoint detection to full coverage and get telemetry flowing somewhere a human reads it, even if no other integration happens this quarter.
  • Establish the asset inventory. You cannot secure, migrate or budget for an estate you have not enumerated, and the inventory is the dependency underneath most of what follows.
  • Disable accounts for everyone who departed at close. Reconcile the directory against payroll.
  • Confirm backups exist, are isolated from the production directory, and can actually be restored. Test one restore end to end. See RPO vs RTO.
  • Do not connect the networks.

Phase 2: Day 15 to 45, Assessment and Decisions

  • Compromise assessment, if one was not performed during diligence. See What Is a Compromise Assessment and When Diligence Finds an Active Compromise.
  • Privileged access review producing actual account counts, including service accounts and break-glass accounts.
  • Third-party access inventory built from the systems rather than from interviews, followed by revocation of everything not currently required.
  • Identity architecture decision with a date attached: federate, migrate, or operate separately.
  • Network interconnect design, if connection is required, as an enumerated and segmented design rather than a route.
  • Contract review for change of control, assignment restrictions and renewal dates on the material technology agreements.
  • Runbook validation against the estate as it actually exists today.

Phase 3: Day 46 to 75, Execute the Decided

  • Identity federation or migration begins, starting with the smallest and least privileged population.
  • Segmented interconnect stands up, if required, with per-rule owners and expiry dates.
  • Remediation of externally exposed vulnerabilities, prioritised by exposure rather than by score. See What Is Attack Surface Management.
  • Logging consolidation into whichever platform will be monitored in steady state.
  • A documented recovery test of one revenue-critical system, end to end, in the estate as integrated.

Phase 4: Day 76 to 100, Close Out and Hand Over

  • Walk the pre-close finding list item by item and close each one with evidence against the standard defined in phase 0.
  • Reconcile actual spend against the diligence estimate and report the variance, including where the estimate was wrong and why.
  • Publish the year-one plan for everything that did not fit in 100 days, with owners, budget and dates.
  • Sign a formal risk acceptance for anything remaining unremediated, with a named accepter and a review date.
  • Hand governance to a steady-state cadence with the same finding identifiers still attached.

The Integration Window Is the Risk Window

For a period after close, usually three to nine months, the combined business is less able to detect an intrusion and less able to recover from one than either company was on its own.

That claim sounds strong until you look at the mechanisms, at which point it becomes obvious. Four of them operate simultaneously, and none appears in the model as a risk. In the model, this period is labelled integration and carries a positive number.

Runbooks Reference Systems That Have Moved

An incident runbook is a document that assumes an environment. During integration the environment changes weekly. The runbook says escalate to this person, who took the retention payment and left at month six. It says fail over to this system, which was decommissioned in the consolidation. It says restore from this repository, which now lives in a different tenant under different credentials. It gives a vendor support number for a contract that was terminated as a synergy.

The practical consequence is that the recovery time objective the business believes it has is fiction from the first week of integration until the runbooks are rewritten, and runbook rewriting is invariably the last task on the programme because it produces nothing visible. See What Is Business Continuity Planning.

Dependencies Span Two Estates

A single business process now touches the target's application, the platform's identity provider, a service still provided under a transition agreement, and a third party's interface. Nobody owns the whole path. Nobody has a diagram of it.

When it breaks, the first two hours go to establishing whose problem it is. During an incident those are the two hours that decide the outcome. This is also the specific failure mode that carve-outs carry into integration, which is covered in Carve-Out Technology Separation and TSA Risk.

Institutional Knowledge Leaves

Retention is negotiated for executives, and sometimes for named engineers. It is almost never negotiated for the person who actually knows why the nightly batch job has to run before the reconciliation, or which of the four servers named after Norse gods is the one that matters.

Departures at close and at the ninety-day mark take the undocumented dependency map with them, and the map was the only copy. This is precisely the finding a retention package is designed for, and it only becomes a seller cost if it is raised before signing. Raised after signing, the buyer funds it.

Effective Recovery Capability Gets Worse

This is the mechanism that surprises operating partners, so it is worth stating in detail.

The target's backup configuration was built for the target's estate. When workloads migrate, backup coverage does not follow automatically: newly migrated systems routinely sit outside the backup policy for weeks, and nobody notices because backup reporting is organised by job rather than by asset. Restoration procedures, where they were tested at all, were tested against the old topology. Recovery depends on credentials that were rotated in phase 1 without anyone updating the recovery documentation. Immutable or isolated backup copies, if they existed, may now be reachable from a directory that has been joined to a larger one.

Put the honest statement in the plan: for a defined period, the combined entity's tested recovery capability is worse than either standalone company's was. Assign that finding an owner and a date like any other, and close it with a real restoration test rather than a green dashboard.

The Day-One Network Connection Decision

Someone will ask, usually in week one, to connect the target's network to the platform's. It is convenient. It unlocks shared services, shared file access, the ERP programme and the synergy timetable. It is also the single most consequential security decision of the first 100 days, and it is routinely made by a network engineer solving a ticket.

State the mechanism plainly. Connecting the estates extends the platform's attack surface to include every control the target failed to implement. If the target has no multi-factor authentication on remote access, the platform now has an unauthenticated path into its environment by way of the target. If the target's directory carries service accounts with domain administrator rights and passwords last changed in 2021, the platform's directory is now one trust relationship away from those accounts. If the target has been compromised and nobody has checked, the connection is an introduction.

The rule is short: connect after assessment, not before, and connect in a segmented way regardless.

PostureWhat it meansWhen it is right
No connectionEstates operate independently. Shared services delivered through SaaS or not at all.Target unassessed, compromise not ruled out, or the acquisition is small relative to the platform.
Segmented interconnectSpecific enumerated flows between named systems, denied by default, logged, each rule with an owner and an expiry date.Most deals. This is the default answer.
Full connectionRouted, largely unrestricted connectivity between estates.Only after a compromise assessment, credential rotation, MFA enforcement and endpoint detection coverage on the target.

The design principle is unchanged from ordinary architecture but the stakes are higher because the two estates have different histories. See What Is Network Segmentation.

One more item for the threat model, and it is specific to transactions. Acquisitions are announced publicly, with dates and counterparty names. The period immediately following an announcement is a known window for business email compromise and payment redirection fraud against both sides, because finance teams are expecting unfamiliar payment instructions from unfamiliar people. Brief both finance functions before the announcement, not after the first fraudulent invoice.

Identity Integration Sequencing

Identity is where integration either compounds risk or contains it, and the sequence matters more than the destination.

The common sequence is backwards. Establish a trust between the directories in week two so people can reach each other's systems, then clean up privileged accounts later as part of the identity programme. That inverts the risk: the trust is the blast-radius decision, and the cleanup is its precondition. Once the trust exists, every unmanaged privileged account in the smaller estate is a path into the larger one, and the cleanup that was scheduled for later competes with the synergy backlog.

The correct sequence:

  • Inventory privileged accounts in both estates, with actual counts, including service accounts, break-glass accounts and accounts held by third parties. See What Is Privileged Access Management.
  • Rotate and reduce. Remove standing privilege. Tier administrative accounts so that directory administration is separated from server and workstation administration.
  • Enforce strong authentication on every privileged account and every remote access path, phishing-resistant where the estate supports it.
  • Deploy monitoring on both directories before joining them, so that the first sign of misuse is visible rather than retrospective.
  • Then federate or migrate, starting with the smallest and least privileged population and expanding on evidence.
  • Rebuild joiner, mover and leaver processes early. Offboarding is the process that decays fastest during integration, because it depends on an HR function that is reorganising. See What Is Identity Governance and What Is Identity and Access Management.

Two rules that cost nothing. Do not establish a bidirectional trust where a one-way trust does the job. And do not grant the target's administrators rights in the platform's directory as a convenience during migration, because convenience grants are permanent.

Does the Seller's Security Posture Persist Through Close

Yes, and considerably longer than anyone expects. Closing is a legal event. It changes nothing about who can authenticate to what.

Credentials

Every credential the seller's organization knew still works on day one. Shared passwords held in a password manager the seller also uses. Passwords hard-coded in scripts, scheduled tasks and application configuration files. Local administrator passwords set from a build image and identical across hundreds of machines. API keys committed to source control years ago and never revoked. Certificates and their private keys. Encryption keys and recovery keys.

The population who has had access to some part of that set includes the seller's former IT staff, the seller's outsourced provider, that provider's subcontractors, and anyone who has ever read the relevant repository. Rotation is not a cleanup task. It is the first control the new owner establishes, and it should be tracked as a deliverable with evidence per credential class.

Administrative Accounts

Named administrative accounts for seller-side staff who supported the business. Accounts belonging to the seller's managed service provider, which frequently retain domain administrator rights and frequently outlive the contract. Vendor support accounts created for a project in 2019. Break-glass accounts whose credentials sit in a safe the buyer does not control.

Ask for the list, then verify it independently. Enumerate from the directory, the cloud tenant and the privileged vault rather than from the interview, because the interview produces the accounts people remember and the directory produces the accounts that exist.

Offboarded Employees

In many mid-market targets offboarding is a manual process that depends on HR notifying IT. During a transaction, HR is occupied with the transaction. Accounts for departed employees persist, sometimes for years.

Reconcile the directory user list against the payroll list. It is a one-day exercise and it reliably produces findings. Pay particular attention to the close-date departures: people who knew for months that they were leaving at close, and who held access until the last day.

Third-Party and Vendor Access That Transfers With the Entity

This is the category that gets missed, because it is invisible from the inside and nobody listed it in the data room.

Every integration, every API key issued to a partner, every VPN account for a supplier, every SaaS tenant carrying guest accounts, every remote support agent a vendor installed and never removed, every OAuth grant and service principal in the cloud tenant. Those relationships transfer with the entity. You bought all of them, including the ones whose counterparty no longer trades.

The canonical illustration of the shape of this risk is Target in 2013. Attackers obtained credentials belonging to Fazio Mechanical Services, a refrigeration and HVAC contractor, and used them to reach an externally facing vendor portal, from which they moved into the environment that processed payment card data. The result was approximately 40 million payment card records and contact information for roughly 70 million customers. The United States Senate Commerce Committee's March 2014 analysis of the intrusion pointed to inadequate separation between the vendor-accessible systems and the payment environment. No acquisition was involved in that case, and the mechanism is the point rather than the transaction: a third party's access is a path into your environment, and at close you inherit every such path that exists. See What Is Third-Party Risk Management and What Is Vendor Risk Management.

Build the inventory from the systems: firewall rules permitting inbound access, VPN account lists, API key registries, OAuth and application consent grants, remote support tooling installed on endpoints, and guest accounts across every SaaS tenant. Then revoke by default and reinstate on business justification, which is a faster and more complete exercise than reviewing each one on its merits.

What the Sponsor Owes Its Limited Partners

This section is about a different kind of exposure, and it applies specifically to the finding that was identified, disclosed, and not fixed.

When diligence surfaces a material issue and the investment committee approves the transaction anyway, that is a legitimate decision. Sponsors accept risk in exchange for return; that is the business. Nobody is owed a perfect estate.

What creates exposure is the gap between the decision and the record of it. If a material technology or cyber finding was identified in diligence, presented to the committee, and remains unremediated eighteen months later when an incident occurs, three questions follow. They are asked by limited partners, by insurers, by plaintiffs' counsel, and occasionally by regulators. What did you know. What did you decide. What did you do about it.

The answers to all three should already exist in writing, dated before the incident. That is an inexpensive discipline and it is almost never in place. Five practical requirements:

  • The investment committee memo records the finding, the quantified exposure and the decision, including an explicit decision to accept where that is the decision. "Noted" is not a decision.
  • The 100-day plan carries the same finding identifiers, so the trace from report to plan is unbroken and can be walked by someone who was not there.
  • Remediation status is reported to the committee at defined intervals using those same identifiers, so closure is recorded rather than assumed.
  • Where a risk is accepted, the acceptance is signed by a named person with the authority to accept it, and carries a review date rather than sitting open indefinitely.
  • Insurance applications and control attestations are answered against the actual post-close state of the acquired entity, not against the platform's controls or the acquired company's marketing material. An attestation that is true of the platform and false of the newly acquired subsidiary is a coverage dispute waiting for the worst possible moment. See What Is a Cyber Insurance Attestation.

The regulatory analogue is instructive. In its November 2020 penalty notice fining Marriott 18.4 million pounds over the Starwood breach, the UK Information Commissioner's Office accepted that "in-depth due diligence of a competitor is not possible during a takeover", but held that a controller's obligations are "not time-limited or a 'one-off' requirement", and that it is "no answer to claim that certain due diligence steps were only needed to be taken in the period immediately after acquisition." Marriott was held responsible for the state of the acquired systems, not for the quality of the diligence it performed in 2016. Responsibility attaches after close and it does not expire.

That is the whole argument for treating the first 100 days as a governance exercise rather than an IT project. See What Is Sponsor Cyber Liability and What Is Cyber Due Diligence.

Related Reading

Frequently Asked Questions

How do you turn due diligence findings into a 100-day plan?

Five rules. Every finding becomes one of four things: a day-one action, a 100-day workstream, a year-one budget line, or an accepted risk with a named accepter and a review date. Every item gets one named individual as owner, not a function. Every item gets an identified funding source before day one, whether that is the escrow, capital budget, platform operating expense or a seller indemnity. Every item gets a sequence position with explicit dependencies, because roughly half of remediation work is blocked by other remediation work. And every item gets an evidence standard for completion defined before the work starts.

Why is the integration window the riskiest period after an acquisition?

Four mechanisms operate at once. Runbooks reference systems that have moved, people who have left and vendors whose contracts were terminated as synergies. Dependencies span two estates, so when something breaks the first two hours go to establishing whose problem it is. Institutional knowledge departs with retained staff at close and at ninety days, taking the undocumented dependency map with it. And effective recovery capability degrades: migrated workloads fall outside backup policy, restoration procedures were tested against the old topology, and recovery credentials get rotated without the documentation being updated.

Should you connect an acquired company to the platform network on day one?

No. Connecting the estates extends the platform's attack surface to include every control the target failed to implement. If the target has no MFA on remote access, the platform now has an unauthenticated path into its environment. If the target carries service accounts with domain administrator rights and stale passwords, the platform's directory is one trust relationship away from them. If the target is compromised and nobody checked, the connection is an introduction. Connect after assessment, and use a segmented interconnect with enumerated flows, per-rule owners and expiry dates rather than a route.

What is the right sequence for identity integration after close?

Inventory privileged accounts in both estates with actual counts, including service accounts and break-glass accounts. Rotate and reduce, removing standing privilege and tiering administrative accounts. Enforce strong authentication, phishing-resistant where supported, on every privileged account and remote access path. Deploy monitoring on both directories before joining them. Then federate or migrate, starting with the smallest and least privileged population. The common sequence inverts this by establishing a trust in week two and cleaning up later, which makes the blast-radius decision before its precondition is met.

Does the seller's security posture persist after closing?

Yes, and longer than anyone expects, because closing is a legal event that changes nothing about who can authenticate to what. Every credential the seller's organization knew still works on day one: shared passwords, credentials hard-coded in scripts and configuration files, identical local administrator passwords from a build image, API keys in source control, certificates and their private keys. Named administrative accounts for seller-side staff and the seller's managed service provider frequently survive the contract. Credential rotation is not cleanup; it is the first control the new owner establishes.

What third-party access does a buyer inherit at close?

Every integration, API key issued to a partner, VPN account for a supplier, SaaS tenant guest account, remote support agent installed by a vendor and never removed, and OAuth grant or service principal in the cloud tenant. These transfer with the entity and are almost never listed in the data room. Target in 2013 is the canonical illustration of the shape: attackers used credentials belonging to an HVAC contractor to reach a vendor portal and from there moved toward the payment environment. Build the inventory from systems rather than interviews, then revoke by default and reinstate on justification.

What does a sponsor owe its LPs when a diligence finding is not remediated?

Accepting a known risk is a legitimate decision; sponsors take risk for return. The exposure comes from the gap between the decision and the record of it. If a material finding was identified, presented to the investment committee and remains unremediated when an incident occurs, three questions follow from LPs, insurers, plaintiffs' counsel and sometimes regulators: what did you know, what did you decide, what did you do about it. All three answers should exist in writing and be dated before the incident, with the same finding identifiers running from report to plan to status reporting.

How long should the first 100 days plan actually run?

The 100 days is a governance cadence, not a completion date. Phase one, days one to fourteen, establishes control and visibility: credential rotation, MFA, endpoint coverage, asset inventory, departed-account cleanup and a tested restore. Phase two, days fifteen to forty-five, is assessment and decisions. Phase three, days forty-six to seventy-five, executes what was decided. Phase four, days seventy-six to one hundred, closes findings with evidence, reconciles spend against the diligence estimate, publishes the year-one plan and records signed risk acceptances for whatever remains open.

T-Mobile After Sprint: Four Incidents and a Remedy That Names Segmentation

T-Mobile closed its merger with Sprint on 1 April 2020, combining two national mobile networks and the systems behind them.

Between 2021 and 2023 the company disclosed a sequence of security incidents. Four of them were covered by the Federal Communications Commission investigations that followed: a 2021 intrusion in which an attacker reached internal systems and obtained personal data relating to tens of millions of current, former and prospective customers; a 2022 incident associated with the Lapsus$ group; a January 2023 incident in which an application programming interface was abused to obtain data on approximately 37 million accounts; and a further 2023 incident involving a sales application.

In July 2022 T-Mobile agreed to settle consumer litigation over the 2021 breach for 350 million dollars, together with a commitment to spend a further 150 million dollars on data security and related technology. The 2021 breach was reported to have affected approximately 76.6 million United States residents.

In September 2024 the FCC announced a 31.5 million dollar settlement: 15.75 million dollars as a civil penalty paid to the Treasury, and 15.75 million dollars as a binding commitment to invest in cybersecurity over two years.

State the limit of the inference plainly, because it matters. The public record does not establish that the Sprint merger caused any of these incidents, and claiming that it did would be wrong. T-Mobile is a very large carrier with a correspondingly large attack surface and a history that predates the merger.

The transferable point is in the remedy rather than the penalty, and it is worth reading closely by anyone about to integrate an acquired estate. The commitments the FCC required included adopting a modern zero trust architecture with network segmentation, deploying phishing-resistant multi-factor authentication across internal systems, data minimisation, inventory and disposal, detection and tracking of critical network assets, independent third-party security assessments, and regular reporting from the chief information security officer to the board on cyber posture and business risk.

Read that list against a typical first-100-days plan. Network segmentation. Asset inventory. Strong authentication on internal systems. Data minimisation. Board-level visibility. Every item is a first-100-days item, every item is cheap relative to a settlement, and every item is routinely deferred during integration because none of them produces a synergy and none of them appears in the model.

The sequence a regulator eventually compels is available to a sponsor at close, voluntarily, at a fraction of the cost. The difference is that at close it is a choice, and in a consent decree it is a schedule.

31.5 million dollars

That is what T-Mobile agreed to pay the FCC in September 2024 over four security incidents disclosed between 2021 and 2023. Half was a civil penalty and half was a binding commitment to spend on security. Read the remedy rather than the penalty: the consent decree required zero trust architecture with network segmentation, phishing-resistant multi-factor authentication, asset inventory and board-level reporting. Every one of those is a first-100-days item that gets deferred because it produces no synergy and appears in no model.

How Cloudskope Can Help

Cloudskope writes diligence findings so they can be executed, and then helps operating teams execute them. Each finding carries an owner type, a dependency chain, a cost with a stated method, a funding source, and an evidence standard for closure, which means the 100-day plan is assembled from the report rather than reconstructed from scratch in month one. We run the day-one work directly where it helps: credential rotation scope and sequencing, privileged access review with real counts, third-party access inventory built from systems rather than interviews, and the network connection decision with a segmented interconnect design. Our M&A Cyber and IT Technical Due Diligence practice is built to hand over a plan, not a diagnosis.

Before the estates are joined, the question that decides whether the integration extends the platform's attack surface or contains it is whether the acquired environment is already compromised. Cloudskope SARTUS answers that question on a transaction or first-30-days timeline, with evidence preserved and written for counsel and an investment committee. Connecting an unassessed estate to a platform network is a decision that cannot be reversed by disconnecting it later.