Every Merger, Acquisition, or Divestiture Needs to Build Breach Readiness First: Part 1

table of contents

Hi everyone. I just got back from Toronto, where I spent hours in heated debates with CISOs and security leaders from some of the biggest banks. We all agreed on one thing: the next breach is coming, and we need to be ready. But one question kept coming up, and I promised to share my take here. This is part one.

How critical is breach readiness during a merger or acquisition, especially now that AI-powered attackers are being unleashed by human adversaries everywhere?

As one CISO put it, “Should the merging business environment get compromised tomorrow morning, can the attacker move into critical business systems in the other business environment and vice versa?”

There’s no simple yes or no here. This story has layers, some of them uncomfortable.

Mergers Create Value

Mergers and acquisitions are a whirlwind: fast, urgent, and always on the clock.

For years, cybersecurity in M&A was treated as a box to tick. That shortcut has cost companies dearly. Too often, the real problems (hidden breaches, weak security architecture) surface after the deal is announced. Suddenly, buyers are slashing prices or walking away entirely.

Last year, one cyberattack toppled an industrial giant. The story? Russian hackers sweet-talked a helpdesk during a merger, slipped inside, and unleashed ransomware. Game over.

In 2026, this isn’t a distant threat: it’s the new normal. AI is now the target, the weapon, and the force multiplier. Even innocent prompts can trigger a breach. With Claude Mythos and AI-powered attacks on the rise, the old playbook is out. Breach readiness has to come before you connect a single system.

Read More: AI Threat Resilience in the Age of Mythos

Cybersecurity is now a primary driver of deal valuations and a frequent deal-killer.

Mergers and Acquisitions Are Supposed to Create Value

More customers.

More intellectual property.

More geographic reach.

More technology.

More revenue.

But every merger also creates a brand-new attack surface.

When two companies merge, everything gets connected: users, identities, endpoints, apps, clouds, networks, data, suppliers, remote access, security controls, admin rights. All in a rush. That one compromised endpoint you never noticed? Suddenly, it can reach:

  • corporate identity services
  • shared file systems
  • enterprise applications
  • privileged administration systems
  • cloud control planes
  • data repositories
  • backup infrastructure
  • production environments

Miss a hidden breach or a compliance gap, and you’re looking at fines, reputational damage, or even a failed merger. Under tight timelines, due diligence often becomes a checklist of tools and policies. Every vendor claims to solve “the” problem. The result? A cluttered stack, a blown budget, and no clear answer when the board asks, “Are we covered?”

That’s why cybersecurity in mergers can’t just be a compliance box checked during due diligence and then tossed to IT after closing. The real question every leader should be asking is:

“Which critical digital systems at the data center, on the factory floor, on the cloud, and with remote users or suppliers are accessible from all points of ingress or an AI tool already inside?”

New identities, unverified trust, new reachability, and incomplete visibility, and this is an attacker’s dream during a merger. The real risk isn’t just the acquired company’s vulnerabilities. It’s the hidden trust relationships the acquiring company inherits and doesn’t even know about.

An acquired Active Directory account? Now it’s an enterprise identity. That old VPN? Suddenly, it’s a trusted bridge. A compromised service account? That’s a tunnel. Shadow IT? The attacker’s first foothold. Legacy apps? Highways for lateral movement. Cloud identities? Keys to a whole new kingdom. And if AI finds a zero-day, every gate to your crown jewels swings wide open.

Attackers know this.

MITRE ATT&CK describes lateral movement as the process through which adversaries move through an environment, often using legitimate credentials and native operating-system or network tools. The most dangerous are trusted, valid accounts used by employees, partners, and suppliers. Attackers can use legitimate credentials without necessarily deploying obvious malware, making the activity harder to distinguish from normal business behavior.

The strategic goal is simple.

Connect the Businesses. Don’t Connect Their Risks.

This is the unspoken rule in every boardroom that approves a merger. It guides all the due diligence that follows. Seasoned organizations know: what gets assumed during a merger can come back to bite. Traditional cybersecurity asks, “Can we prevent compromise?” But that misses the point: the new attack surface you just inherited.

This is a big shift for leadership. Cyber risk is no longer something you hand off to IT and hope for the best. That’s why zero trust matters in every merger. NIST 800–207 makes it clear: stop trusting the network, start protecting every resource, user, device, app, and service.

This principle changes the ground rules. Leaders must assume every merger brings hidden cyber challenges that need fixing before you connect anything. And remember, what one company calls “cybersecurity” might look very different to another.

The other aspect is AI. Merging entities must realize an uncomfortable truth.

Reachability Is the New Vulnerability

Claude Mythos has already shown that AI tools can spew multiple zero-day vulnerabilities in hours.

In 2026, AI has emerged as a tool, a target, and a powerful force multiplier for cyberattacks. If a system is connected and accessible to AI, attackers will target its vulnerabilities and bring it down. Hugging Face recently discovered, to their surprise, that guardrails in their own AI capabilities prevented them from defending against the AI cyberattack. Eventually, they ran the forensic analysis instead on zai-org/GLM-5.2, an open-weight model to address the issue.

Hugging Face also mentioned in their disclosure, “the practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.” As if on cue, on August 23, 2026, Chris Lehane, OpenAI’s chief global affairs officer, gave this warning to The Guardian, days after his company paused development on its latest model following increasing safety concerns.

Also Read: Enable AI Without Expanding the Blast Radius

Here’s the hard truth: while everyone expects AI to transform business, we should also expect routine AI-driven cyberattacks. And they are already happening as you read this.

Digital leaders are on high alert. Bain calls this a top-tier business risk, not just a tech problem to push down the org chart. The launch of Claude Mythos is a signal, not the threat. AI-powered attacks at scale are already here. Patch management needs to be faster and bigger, but let’s be honest: you can’t build that overnight, especially during a merger.

During a merger, assume this: some zero-days are unpatched, some credentials are already stolen, some assets are invisible, some endpoints don’t meet your baseline, some service accounts are overprivileged, some legacy systems can’t be fixed right away, lateral movement is happening where you can’t see it, and attackers may already be inside the systems you’re about to connect.

The only practical move? Start with microsegmentation that covers data centers, offices, remote users, factories, and cloud. It needs to work with your EDR, firewalls, and SASE. Most importantly, it must be able to disconnect critical business from an active attack, fast, and if possible, automatically. That’s how you deny AI-powered attackers a win.

Access The Forrester Wave™: Microsegmentation Solutions, Q3 2026 | See how microsegmentation solutions are evaluated across deployment, policy, enforcement, visibility, and other critical capabilities.

Every Merger Is Your Dress Rehearsal for the Next Breach You Hope Never Comes

Best practices say due diligence should cover posture, breaches, governance, infrastructure, incident response, third parties, regulations, IP, and financial exposure. But here’s what they miss: what happens when an attacker slips past your first line of defense?

Cyber due diligence has traditionally focused on questions such as:

  1. Has the target suffered a breach?
  2. Does it have an incident-response plan?
  3. Is MFA deployed?
  4. Does it have EDR?
  5. Are critical vulnerabilities patched?
  6. Does it comply with relevant regulations?
  7. Does it maintain cyber insurance?
  8. Does it have AI applications?

These are useful questions.

But none of these answer the question that matters most: What happens when an attacker (human or AI) gets past your controls or pops a zero-day? Too often, security gets called in after the valuation is set. That’s like signing the lease on a burning building and then dialing the fire department.

Read More: The CISO’s Guide to Containment in the Age of AI Attacks

Here’s the reality: M&A cyber due diligence can’t catch everything. Representations and warranties matter. They give you some legal cover when risks pop up later. But contracts don’t stop lateral movement, isolate a compromised endpoint, revoke a stolen credential, or halt ransomware.

And they definitely don’t keep your manufacturing line running.

That’s why cyber due diligence needs a second dimension: deny access to digital systems by design and by default.

In a merger, waiting for perfection is a losing game. Time is everything. The smart move is to build zero trust into the integration from day one, so a compromise doesn’t turn into a full-blown breach. The best control? Remove unpatched systems from the attack path, fast. Make them invisible, like an invisibility cloak. If attackers can’t reach them, they can’t exploit them. And you keep the merger on track.

If you’re planning a merger, acquisition, or divestiture, contact us to discuss how to reduce lateral movement risk before you connect critical systems.