1Password CISO Dave Lewis on Cybersecurity Pitfalls in Mergers and Acquisitions
Dave Lewis, global advisory CISO for 1Password, dives into the pitfalls that can arise when organizations ignore cybersecurity issues that will inevitably arise following a merger or acquisition.
Transcript
Hey guys, thanks for the throw. We're here with Dave Lewis, who's global advisory CISO for One Password, and we're having a little chat about, well, cybersecurity and mergers and acquisitions because somehow or other we seem to overlook this issue every time there's a deal. Dave, welcome to the Shah.
Thank you very much for having me on. Alright. There's always some sort of incident and I guess as of late, the one that everybody's talking about involves Salesforce applications and a company called SalesLoft, which bought another company which had some issues with their OAuth tokens.
And then the next thing you know, all the bad guys are targeting their stuff. But this is not an uncommon story and we've seen it before. And I guess the question, Dave, is like, how come we don't seem to ever think about the security implications of these m and a deals and what needs to be done?
A lot of times it's really about business decisions and they want to make sure they're doing things as quickly as possible. So unfortunately, security historically would often get pushed off to the side. You know, they're not just business transactions, they're cybersecurity events.
So this is one of those things where the gotchas can and will happen. I've lived through them, I've seen other organizations deal with 'em and, you know, obviously their current news as well. And you know, the role of the CISO in this particular case is to protect the value of the deal and enable the business.
And unfortunately, security historically was seen as that flaming sort of justice and how we could get to the answer of no. When in effect, you know, security is there to make sure that, you know, security is able to operate safely and securely. Do you think the folks who are doing these deals are aware of the potential security issues?
Or is this just something that comes to light after the fact and then they go, wow, I wish we thought of that? Uh, unfortunately it's a lesson that has to be learned by falling on swords. Um, unfortunately too many times this is the case and part of it is, you know, falls squarely on the security practitioners.
We have to be better at managing the narrative, making sure that we are inserting ourselves where is net where it's necessary on the business side of the house. They have to alter their thinking and start realizing that in order to make sure that an acquisition is going to be successful or a merger, whatever it happens to be, that security has to be absolutely factored into the equation. Hmm.
Um, how does the CISO kinda inject themselves into that conversation? I mean, do they even know that these deals are going down? Or should they assume that they are and just start poking around looking for where they might be happening?
Well, the really interesting thing there is that the CISO tends to fall in different parts in different businesses as well as different verticals for that matter. So if you are, you know, rolling up to the CIO, then it's really an interesting paradigm because you, the one you're finding fault with is ostensibly your boss. So it becomes a very difficult and sticky situation with the CISO there.
If the CISO has a seat on the executive leadership team that changes things and it provides that visibility. Uh, even having the CISO report into the CFO that is responsible for risk and you know, the fiduciary responsibilities that come with it, you're going to have, again, better visibility. So it's really about communication at this point, because the fundamental piece of any security program is really about the human element.
When you boil it right down to brass tacks and making sure that you're able to communicate, get your message across, not only as a security practitioner, but the people that are responsible for exercising these deals, they have to find a way to listen and hear that message. So part of that is, you know, learning how to speak the business language, you know, saying that revenue's at risk, there could be brand damage, compliance fines. These are the kind of phrases that the business leaders will understand if you run in there and say, oh, we're gonna have a zero day of in their environment of blah, blah, blah.
Obviously I'm being facetious there, but get, if you approach it from a security perspective, you're going to get a very different response than if you say, oh, our revenue is at risk. It's going to have a very different response. So shaping the message as a security practitioner in a way that's gonna resonate is absolutely, uh, the key piece of the puzzle there.
Mm-hmm. What, um, should people be doing? Is there some sort of like baseline for forensics for an acquisition from a cybersecurity perspective that somebody has created under a set of best practices here that should be observed There?
There's all sorts of different best practices. Like one of the ideas is having, you know, security protocols by phase, like doing due diligence of going through and looking at the threat posture and security posture of the organization, how they measure up for compliance, what sort of business, uh, business, sorry, what kind of vendor risks do they have? So for example, if you are connected to a vendor that has a history of security issues, you know, that could really affect the blast radius of how you're doing your calculus, uh, then you have to look at it from the integration perspective of lining to access controls, consolidating your vendors, making sure that you don't have multiple vendors that do the same thing.
I've, I've lived through an organization where we had seven different vendors that were delivering ostensibly the exact same product, and that was because it had been a project driven environment and at no point did anybody sit down and say, oh, do we already have this in place? And the other piece there is to unify the policies between the acquirer and the acquiree to make sure that everything is lining up properly. And then looking at it from the post deal perspective of, you know, ongoing monitoring audits, remediation where necessary, and making sure you're cataloging any inherited weaknesses and adding that to your risk register so you're making sure that you're tracking it from cradle to grave.
'cause when the auditors come and they will come, they will be asking for those sort of questions. So you wanna make sure that you can demonstrate that you have not only identify it, but you have a plan to remediate. Should we just assume that the cybersecurity is gonna be flawed in any acquisition because, uh, 90% of them either involve a smaller company that probably didn't have the resources to do it right in the first place, or a larger company that's been in distress and maybe probably isn't spending enough on cybersecurity to be it, As long as you have human touching keyboards, you're gonna have a risk of something being missed.
Um, and, and that's inevitable. But you can do a very good job of reducing that risk by going through and looking at it like doing a risk assessment of looking at where the gaps are, um, as well as, you know, having a security integration playbook ready before the deal starts. So first, get yourself in front of the, the business leaders to make sure that they are taking into account security has to be there and making sure that you show up as a secure security leader with a plan, how you're gonna deal with it, how you're gonna per deal with, uh, interim controls and all that sort of thing to make sure that you are showing up prepared.
Mm-hmm. Do you think that the bad guys out there are tracking these types of deals? 'cause for them it's just like basically a, a red light signal that says, yeah, there's probably weaknesses here to be exploited.
I can guarantee that. Because again, back to the human element, anytime you have a deal happening, you have people on either side of the equation are saying, am I gonna still have a job? And the attackers know this and they will prey upon this.
If we look back to, uh, the pandemic as a great example there, all sorts of emails started going out about, oh, if you don't complete this questionnaire, you're gonna lose your healthcare coverage and things like that. And that was really a horrible approach, but it was extremely effective from the attacker's perspective because people genuinely concerned they didn't know how things were gonna unfold. I know I didn't.
Um, so when the, when a, an event like this comes up where there's a merger, uh, that, you know, leaks out into the news, you have the chaos element that is introduced and the law of unintended, unintended consequences where not each side of the house knows who is on what company. And so it prov, you know, really does give an opportunity for an attacker to even fashion. Like if you're at Widget Co, you could, you know, widget co with an extra letter in there, all of a sudden that email address looks like the same thing, even though it's a different thing entirely.
And this is where the problems really can unfold because, uh, you know, the attackers will prey on this sort of chaos to be able to, you know, steal data effect, change, uh, cause havoc if they want. Right. And to your point, they may just impersonate people at the other company 'cause I don't know who they are, and if somebody shows up and says that they're from the finance team of the company that's acquiring me, I'm kind of likely just to trust that.
Right? Yep. Mm-hmm.
Um, will AI kind of exacerbate this? And I, and, and it seems like on the plus side, I maybe should be able to use AI to discover what my issues are faster, but the bad guys are also gonna be using AI to also discover what my issues are faster. So is is the window of time when I get to actually review that security kind of narrowing to zero?
It is really getting tweaked down to a fine point. And, you know, the attackers have been using, uh, artificial intelligence and LLMs now for quite some time. If you look at Worm GPT and fraud, GPT, there are already tools that have been around for at least a year.
Um, it's not outta the realm of possibility to say that they're gonna be using some sort of AI tool to be able to breach systems. And then if you flip it on it head and look at it from not only managing credentials for an organization, but looking at it, the agentic AI aspect of things where you have agents and environments from the acquirer and the inquiry that they need credentials, they need to be able to manage access within their environments to APIs, to accounts, whatever it happens to be. How are you managing those credentials?
Making sure that, you know, they are not leaking out of the environment, they're not being compromised. Because unfortunately a lot of times these, uh, agent ai, um, accounts have more permissions than the individual human might. So those could be a real potential for problems there.
Mm-hmm. Ultimately, there's also regulations involved in a lot of these m and a activities. So are the auditors getting smarter about what to look for as well?
And maybe it's not just so much about the fact that I'm gonna get attacked as much as I just might get fined. Well, yeah. So the AI piece now, it really is the equivalent of running with scissors, um, because it may seem like a really neat idea because you like to flirt with danger until you find that little bump in the rug and next thing you know, you got a problem.
Um, and when the, and the auditors know this, they're gonna come looking and the AI aspect of things, it's just a different hammer within your tool set. So you have a red hammer, green hammer, blue hammer. This particular hammer is just an another tool.
And we really have this bad habit of anthropomorphizing. We think of it as being far more elevated than it is, but when it boils right down to it, it is just yet another, uh, technology and it'll be obviated by something else that comes down the road in a couple years. But yes, it is getting faster.
The auditors are getting wise to this. They're understanding that a lot of times we're getting ahead of our skis with the implementations of various AI projects and security is being left by the wayside. So we have to make sure that we're getting better at that.
And, you know, really fundamentally getting our arms around the security perspective so that the auditors don't do it on our behalf. And it goes from being a simple project to a rather massive remediation project. CISOs of course, have multiple challenges as it is, is there maybe somebody on an m and a team who should be the security specialist, then maybe that's brought in by a third party or somebody who kind of does this over and over again because well, CISOs aren't doing acquisitions every day of the week either, so it's not maybe core to their function.
Well, yeah, so you like, whether it's an acquisition, true merger, a divestiture spinoff, um, there are all sorts of different ways this this can be presented. If you had the budget available and the time to be able to bring in an external security person, by all means do it. But realistically, it ends up being a matrix type of approach within an organization where the security person internal to the organization of the acquirer in this, uh, acquire acquirer, yeah, sorry.
Acquiring aspect, uh, can be brought into the conversation. So these, um, security professionals, this may not be their core competency, but there'll be very good as security. The, the idea here is just to approach it as a rather a sev one type of approach.
Because m and a activity usually is very strictly time boxed. There's rather significant implications to things going wrong, and sometimes it's okay to say no. Um, I, I have been through, uh, m and a activity in the past where we literally just walked away from the table.
This was at a previous organization and it was just, there was too much risk involved. And there's other times where we've seen organizations where going through m and a activity and something was unearthed during the process that caused the deal to drop by hundreds of millions of dollars. So making sure that security is in at the beginning is, uh, absolutely non-negotiable.
That has to be part of the equation. 'cause otherwise you could be introducing undue risk into the organization that could have material impact, uh, from a stock perspective as an example, um, credibility within the industry. There's all sorts of different ways that we can approach that.
Hmm. So last question, but what's that one thing you see folks doing as it relates to m and a and security that just makes you shake your head and say, folks, we should be a little bit smarter than that? Oh, it's a twofold thing.
Not managing the accounts, uh, correctly, because I've been through activity in the past where we inherited all sorts of super user accounts that belonged to people that were no longer the organization and had not been there in years. That was a rather significant piece. And the other piece of that, which is the flip side that is often integrated is it's okay, we accepted the risk.
That is not a good answer because usually what that means is a piece of paper was signed off by someone who had no authority to accept the risk shoved into a back of a drawer and off they go. Hey folks, you heard in here when those m and a deals come around, make sure you take a good long look before you leap. Hey Dave, thanks for being on the show.
Thanks for having me. All right. And back to you guys in the studio.