Quest Warns Midmarket Buyers of Inherited Cybersecurity Risks in Acquisitions
News related to:Quest Technology Management · 2 min read
Quest Technology Management, a provider of technology management and cybersecurity services, has issued a warning to midmarket companies considering acquisitions. The company's CEO, Tim Burke, cautions that buyers can inherit significant cybersecurity risks from the target company, including unpatched systems, monitoring blind spots, and poorly configured security tools.
According to Burke, the technology acquired in an acquisition can pose immediate security threats.
Burke highlighted that the technology acquired can include systems that have not been patched, security tools that are no longer monitoring the full environment, and devices that have dropped out of visibility after a configuration change. These issues can become part of the buyer's environment immediately, turning what initially appears to be an integration issue into a pressing security problem.
The CEO emphasized the importance of conducting a thorough cyber diligence review before closing a deal.
Burke stressed that the security condition of the acquired company should be considered alongside financial factors during the due diligence process. "A checklist of security products tells you what a company bought, not what it actually protects. Ask to see the incident history, and confirm whether the monitoring still covers the environment they have today."
For midmarket companies, which often lack the dedicated cybersecurity teams of larger enterprises, the risks are particularly high. Burke advised buyers to obtain a clear picture of the systems and connected devices in the environment, identify known vulnerabilities and missing patches, and ensure that security and monitoring tools are covering everything they are supposed to.
The risk does not diminish once integration begins. As the two companies start connecting their systems, legacy technology that has not been examined in years can become the biggest source of risk.
To mitigate these risks, Burke recommended that buyers resist the urge to connect the networks quickly. Instead, they should get a clear picture of what they are joining, close the worst gaps first, and treat the integration as a planned project rather than an IT afterthought.
In conclusion, Burke stressed the importance of understanding the acquired environment before systems are connected.