Mergers and Acquisitions – Lenny Zeltser, Axonius
Lenny and Alan discuss the scale of the risk that the companies are inheriting with acquisition and offer advice on what companies going through M&A can do to protect themselves.
Transcript
This is texturing TV. Hey everyone, welcome to another texturing TV interview. My guests for this interview is my friend Lenny's out sir.
He's the ciso at exonius and Lenny. Welcome to Tech strung TV. Hi, it's good to be here.
Yes, it's good to speak with you again. We haven't spoken in a while. First of all.
I hope all is well with you and your world. Lenny not everyone's going to be I I know you in this from the security world for a long time, but not everyone out here does and every and not everyone obviously is going to be familiar with the company. So if you don't mind Lynn, I'm gonna ask you to kick things off with a little bit of maybe your background and that exonius.
Yeah. Sure. Well, I'm a security professional.
I've been a security professional now for more than two decades and over this time. I've enjoyed taking on different roles. So as long as it's related to security, I'm probably into it and so for a long time, I was working as a consultant for some time.
I was building and managing security products and security services. And now I'm leading a security program at exonius and for me, it's very exciting because I started with a company when we were just very very young. And so I am very happy that I get a chance to really formalize a program and then see it mature over time and there's always room for improvement.
Content Evolution as the company grows. So we're a growing tech company that creates solutions that help customers address their asset management needs in the world of cybersecurity. And so I joined exonius and gosh.
Over three years ago because I was excited about the challenge of really finding a way to oversee manage. It related Assets in a way that works for Security Professionals. And so I think about Asset Management a lot, but my focus is our own security program.
And how do we build it in a way that protects our own assets our customers data and how do we earn our customers Trust? Absolutely and very fair and look you've been in security two decades. I think I know you almost that long through lending, so You know, we've been there done that been there along for the ride with you Lenny for before we jump into today's topic.
Just you mentioned the company but website. So for people maybe who want to go check out and they could die a deeper dive. com.
Yeah you Google cybersecurity Asset Management. You can probably find it quite easily. So I'm not gonna hold your feet to the fire because you spell it for us.
com actually good stuff. All right. So Landy what we wanted to talk today is it's kind of a soft white underbelly of m&a.
Right and you know there's so much Mna activity going on well. between the kind of go go easy money of of the covid times and now as we seem to hit this You know read Readjustment if we want to call it that as money Titans up inflation and so forth. MMA is still going strong in the previous arrows because money was plentiful.
It seemed in this era. It seems that money's not so plentiful. But both of them both of those reasons are driving m&a Activity one of the things in a activities, you know, it's all it's all fine and dandy when you you know, signing contracts and exchanging checks.
but at some point That's over. You got to get down to business and some poor SOB, you know in the security team is handed a portfolio and says, okay, you know go make sure they're secure or let's let's merge and integrate. Technologies here and security being part of it.
Tell us a little bit about kind of your take on this. It will companies have been merging business operations acquiring each other since the beginning of time. In fact nowadays, certainly the world of tech a lot of larger more established organizations see a way of acquiring younger companies as a way of well in a way maintaining their Innovative Street as you grow big it's hard and hard to be really cutting edge Innovative.
And that's what Young companies really good at. So that's one of the reasons why typically larger more established entities acquire smaller organizations in the world of tech. And in most cases not all of them.
Security leaders are a part of the due diligence conversations not always different cultures different styles different scenarios. Sometimes these mergers and Acquisitions happen in a very secretive way, but hopefully a security leader is involved. But at least in the initial due diligence at a high level.
Yeah, you're trying to get a sense like how much sure is the company security program. How does it stack up to what our program is like and in this case? Probably the security leader would be asking similar questions that one would nowadays ask of a third party vendor.
Yeah. Tell us you have a third party auditory reviewing your security program. What Frameworks do you follow what have been your recent security achievements or any security risks that we should know about that's initial due diligence.
Then at some point the deal is closed now. It's signed now that your companies are coming together. as a security professional to worry I think we do.
Yeah, we worry we're really good at thinking all the ways about all the ways in which things can go wrong and we think about risks and so initially that's what's on my mind. The two companies are coming together. If I am a part of the acquiring entity, I worry what did we just get in terms of risk?
Does this strengthen or weaken my security program? Could require identity already be reached and now all of a sudden I'm dealing with an unexpected incident. So that's one way in which Security Professionals are thinking about the situation.
What can go wrong. What are the big risks? But what I wanted to point out Alan, is that what I'm Training myself to do is to have another perspective on any transaction and that is how can I as a security professional enable?
Business objectives. The reason why that m&a transaction happened is because the companies had high hopes for doing something good together. They decided that they'll be better together than a part.
What are those business objectives and how can I and my team better support them to enable business? That's a very different mindset and one that I think we should bring to the table together with and more worrying risk focused mindset. I agree with you 100% And and look let me first of all say that.
I I've been involved in more than several m&a deals over the last 25 plus years. and we probably do more pre-closing security due diligence now than we did. Years ago, right we and I think I fortunately or unfortunately I think compliance.
Is a driver of that right? If you're buying recently Amazon, right? I think in the last couple days and announced a large Buy in the medical field a healthcare provider.
I mean, obviously you if you're gonna make a Buy in the healthcare field today, you've got to be worried about HIPAA personally identifiable information. So I would imagine that that is part of that due diligence. But and so and that I Bravo right?
I'm happy with that. It's risen there. But that level of due diligence is is you know, 50,000 feet due diligence on that's right times.
It's not. Okay. Now we're integrating and what system are you using?
Does it work with the system. I'm at that I use which system should we use going forward should we use? Especially some companies they do m&a rather regularly, right?
You can't have 12 differences or can you? Right. How do you normalize that?
Well, certainly coming into the situation as a security leader. It begins with understanding the situation. Yeah, and as you suggested we need to understand.
What technologies are being used in the new company? How do they compare to what we're using right now? But before we've even go there to be able to write the right to ask the right questions about the Technologies first.
Let's understand what our first of all they compliance and legal obligations that we now need to follow if our company has never dealt with Healthcare and all of a sudden required and organization that is in the business of healthcare. You know, what the security team will need to work very closely with legal probably to understand. So what do we need to do now that perhaps we weren't doing before what are the new perhaps unexpected requirements of the security program.
Then we need to understand even before we talk Tech. What are the business objectives for the organization and alluded to this earlier? Why are we coming together?
Is it because let's say now. We have a brand new product line and that helps us gain access to particular vertical Market or is it that we're acquiring this company because want to get access to a new geography where we didn't have physical presence, right? There's so many reasons why these m&a transactions happen.
We need to understand this because technology that will ultimately talk about drives these business objectives. So why are we doing this? For example, if the company's goal is product diversification and it will expect to maintain different non-integrated product lines.
That means that probably they acquired entity will want to keep some of its technology. Because it's expected to operate let's say independently in contrast. If the goal is let's say many companies are required because of us.
We call it Aqua hire right? We're just acquiring the company not because of their customers not because of their Tech. We just want the people in that case.
Probably you want to migrate to the acquiring entities text that right away. So you understand the context from a legal regulatory perspective you understand the business objectives. And then you as a security and Technology leader can think about what do we do about the tech?
And to answer this question first of all get the lay of the land. What are the key Technologies being used by the acquired company? What are the it assets that they have?
What is the their use of cloud infrastructure how Reliant are they on SAS applications? Do they have things on Prem off-brand? What are the employee desktops and laptops look like right you start Gathering these background details.
That's your foundation or then making decisions regarding what technology to keep how to migrate and when to merge if at all the security and it operations a great, you know Lenny back in the com days, right? I helped a good I sold my company to another company. It was a roll-up and we I helped that company go public we did about 30 Acquisitions and 36 months a lot.
Almost one a month. And the rule of thumb we followed there was when we bought a company. acquired a company we didn't do anything.
with the technology or oftentimes even the people For six months or so, right? You don't go in day one and start saying use this don't use that, you know and making wholesale changes. It's kind of let him do what they want.
But in the world if security you really you if something is a Miss something's not up to standards. You can't afford to wait six months. Right.
And and so how do you you know, when when when is it too early, right? You know, when when is it too early to go in after the acquisition? It's okay.
We got to start we got to start doing this now. Hey, yeah, no you bring up a good point that there's a sense of urgency about some security activities that maybe is not there when it comes to other aspects of the acquisition for example, in many cases. And the reasons why you tend to leave the acquired company alone initially is because look, It beyond what some paper and on the contracts, it's people right there their groups of people that somehow now need to work together when previously they didn't do that and that means you're dealing with the messy things like culture and Communications and expectations and you don't want people Employees leaving in Mass.
You you want you don't want them losing productivity, but when it comes to security the big question is Did I just acquire a company that is so poorly managed or perhaps is so weak security wise that when they have an incident now, they're acquired entity exposes the acquiring entity to unexpected risk brand tarnishing or regulatory fines or other Financial repercussions of a data breach. So that's why I agree that initially. Very quickly.
You need to get an understanding of what did we get? What is the set of infrastructure components that they acquired entity brings to the table? Where does the data reside how is it used?
How does it flow? And where might we have the weak points that could be compromised or maybe already compromised once you understand this then you oftentimes embark on a project to see. Are they already compromised?
Yeah, you perhaps do some threat hunting you understand if there's already an incident happening and maybe you don't know yet because that you need to address right away. So there's a security professional you need to balance the need to understand the lay of the land and your risk right away because if there's a reach need to deal with it right away, but also you need to think longer term. These are people with whom you'll be working together.
There's some business objectives that require collaboration and therefore you need to understand right? How do we work together? For example, how do we not alienate the ATM security team of the acquired entity because you know, what if they don't like something in this market they can probably find a job elsewhere quite quickly.
So how do you make sure that they feel valued and if you're starting to poke your nose into their business, let's you let's purposely frame it in a way that sounds on Pleasant because that's how they might see it. You come into their organization, you're questioning their decisions. You're implying that they are perhaps Not good at their job.
If you're saying I want to know if you've already been compromised. So there's a human aspect to these interactions and I think for this to be successful you need to interact with them by explaining. Yes.
This is why we're doing this right now and it's urgent. But let's do it in a way that allows us to be more successful together because they security team of the acquired entity. It needs to be happy with where they're going in the longer term just as much as the security team of the acquiring entity.
Absolutely. Look, I think we can follow a lot of this under. Don't forget this human beings involved here, right?
It's not just some. Corporate entity dealing with some corporate entity and a bunch of different technologies that were like, you know. folding cards mixing cards up this there's people here and and this feelings and there's you know, this human the humanity of it in the human aspect of it is something I think we need to to really look at buddy.
These interviews are 15 minutes. We're already over 15 minutes. But you know, I want to thank you for for you know, helping us shine a spotlight here.
We have to jump onto our next interview. com, but don't ask me to spell it. com folks.
This is Alex trevora Tech Strunk TV will talk soon.