Security and M&A – Randy Watkins, Critical Start
Randy Watkins, Critical Start CTO, discusses cybersecurity during mergers and acquisitions and provides valuable insight into what questions business leaders should be asking regarding cybersecurity, transparency, and companies’ vulnerability during the M&A process.
Transcript
This is Textron TV. I have the great pleasure of being joined by Randy Watkins Randy a CTO with critical start. It'll be talking with you Randy.
Thanks for having me Mitch. Awesome. Great to have you too fellow bass player musician.
We were talking a little bit about that. But let's talk about you. Tell us a little bit about yourself.
Tell us a little bit about critical start. Yeah. So I'm the the CTO at critical start been here for about 10 years actually a little bit over 10 years incredible start is the leading provider and managed detection and response services.
So all the alerts that are generated by the plethora of security tools that are customers are implementing. We ingest those into our platform. We have a 24x7 security Operation Center.
They do the full investigation and response essentially lowering the dwell time of attackers and keeping the environments clean. So so the target MSP just like what you do is that correct the evolution of MSP. I mean msps to me or more geared around providing compliance and we're more geared around providing security.
Okay security operations and response and and all good good stuff. Well, there's tons of things we could talk about in security always something interesting going on. We don't need to talk about LastPass incident or whatever we can jump to where we want to go but I think one things that picked my interested is talking about m&a because I've gone through several myself and sometimes you get to do do diligence technology due diligence on the company you're acquiring or if you're being acquired a lot of times you don't right.
It's high. I'm the security person from such and so and I work for you now or vice versa, right? So I'm sure you go through a lot of that as the receiver of those customers that are now by the way, we've got three new companies coming on board.
Help us right. Where do you start? How do you have that conversation with your Cuts with your customers?
Yeah. I mean I've been On both sides of the table and in various situations and there's always some element of due diligence done now whether or not it's Technical and whether or not technical includes security is anybody's guess traditionally what we're used to seeing is hey, we just acquired this company in their demanding connection between the two domains. They want they want us to join everything together Federate it and start sharing between organizations.
Let's go and in security is you know, security has a hard time saying no to the business when the CEO is saying yes, it happens today. So there's a couple of things that we've done to help our customers and and we fit in various roles traditionally. What happens is the company is acquired.
The business transaction is done before security really gets a peek behind the covers occasionally, we'll have the businesses that are mature enough from a security understanding to do some element of security due diligence before the actual transaction takes place. Rare, but super valuable right and and we can plug in to those those companies that are looking to be acquired to see if there's any malicious activity beforehand. So best case scenario, we get a security due diligence as you know, prior to the transaction as part of the the business due diligence and we go into it knowing okay.
There's some some problem areas or some missing controls, but there's no active breach more often. What happens is the exact opposite the transaction takes place Securities brought to the table. They're told the Federate we get some level of visibility into the environment and we see okay there is an active breach or there has been an active breach and we don't know that it's it's completely mitigated at this point.
So the first step for us is getting visibility into that new entity and and starting to look at you know, is there any suspicious Behavior? Are there any indicators of previous breach, of course, is there any malware is there any callback I mean that stuff's pretty easy to find but it's really going in and doing your own due diligence after the fact and starting to look for artifacts that would be indicative of a compromise or look for lateral movement credential misuse, you know new logins from Legacy or dated accounts and trying to identify if there's anything that kind of warrants additional suspicion investigation response activities, you know kind of post acquisition. No, when you do this, are you doing it as kind of setting up as a new account or a new whatever in your platform and then observing and seeing what's going on looking for those kinds of activities before you start?
Merge it all together or do you just have to sort of do the big bang and make it happen and then watch it. It depends. Sometimes it's trial by fire.
It really depends on the the existing security posture of the acquired organization. So sometimes you come in and it's a very small acquisition. It's 20 people.
They didn't have much security to begin with those ones usually get the security diligence done during the transaction or before the transaction because it's relatively easy. Do you have antivirus? Do you have EDR?
Do you have EBP? Do you have MFA? Do you have a SIM?
Those questions are really easy to get knocked out if the the acquired company has a technology that we support as part of our MDR. We'll plug them right in and we'll start doing the the monitoring regardless if they're integrated into the parent company or not. Um, if they don't have a good security footprint, we recommend our companies have a an acquisition portfolio of technology that they immediately deploy.
So if you're using a crowd Striker a Microsoft or Sentinel one or a Palo Alto or something on the endpoint have those packages ready to go that way day one, you can deploy your your company's standard for technology and we can very quickly take over monitoring. So there's less of a kind of a Delta between the point time you made the integration to the point in time. We find out there's a breach and we can lower that dwell time of the attacker.
Did you get much push back in those situations or is that pretty well accepted and inquiring companies is okay. Great. Just roll this out.
We'll flip this over kind of get that done up front. Are they pretty accepting of that or do you get a lot of pushback depends on the size and posture of the acquired company and the acquiring company? I mean all a lot of times not always the acquiring company has a stronger security posture and the acquired company recognizes that and accepts it we have had instances though where the acquired company doesn't accept it.
They say no we've operated this way. This is the way things work in this way. We wanted to work and in those scenarios, I mean our guidance to see souls and security directors the ones in charge of doing the integration is hey try to put the brakes on as much as you can try to make a proxy between you and that acquired company, you know, try to manually copy over data or users.
I mean do a longer integration if you can and then we've had the occasional scenario where the acquired company is actually pretty strong security posture and abiding by the acquiring He would actually weaken their security posture. And for those it's like well, let's just get you under monitoring and let's deploy the the aquarium company standard without lessening the posture that you already have deployed by a policy and procedure. So it's always going to be a mixed bag.
It really just depends on that security posture coming from the acquired company and in doing enough of an audit beforehand to understand whether or not you're gonna help or hurt the situation by immediately merging things together. I'm sure every situation is different but and I can get why an acquired company might be more secure than the one that's doing the acquiring. Why do you what do you think that is?
It's because they're smaller. Maybe they're newer. They've sort of their technology stack has been put together more recently and with services and thinking about security.
Is that true or are there other factors why that's true all the above. I mean, the larger acquiring companies are our traditionally older that maybe they're leveraging some Legacy technology or you know that they haven't updated the technology and regardless older companies security is typically bolted on as an afterthought these newer companies that are kind of quote unquote born in the cloud and anything within the last 10 years or so you start to see security being ingrained inside the infrastructure fabric. It's less of an afterthought and more of a foundational aspect.
And those are the ones where I mean if you're acquiring a relatively new company, you should expect some level of security posture cyber security awareness. And see that carried through in the controls policy and procedure. I mean the quickest way to find out if the company has a decent posture is just to ask for their cybersecurity policy.
And if they have one specifically written for cybersecurity, you're probably in good shape if it's part of their acceptable use terms then you may want to dig a little bit deeper. Mm-hmm. And yeah, maybe okay.
That's our policy. Right? Yeah, if you well interesting.
So what kind of get what happens after you hit like the sixth month Mark or the one year mark, you've gone through that initial ingestion phase of okay, you're up and running and we're you know, you're still you're still secure pretty much but what's the next set of things that happens is company start to mature do people start to integrate everything together. They kind of leave it alone for a while, but the dust settle what's typical? Yeah, we'll find out if the environment's breach within the first month.
I am pretty easily. We usually find out in the first week and then the first month is clean up and and Ensure that everything is is status quo after that. It's it turns from technology to products and our policy and procedure.
So, okay. Well now we have this technology implemented we're able to do 24 by 7 monitoring where we escalating alerts to is there to separate security teams to separate help desks by six months. They start merging us all those things.
Yeah exactly. Where do we send what alerts what's the the standard process for an own device? I mean, do we nuke and pave?
Who do we send that to? What's the reimaging process? You know, what's the policy around potentially unwanted programs not just malware but also pups that stuff starts to come into coming to play around that six month Mark by one year.
It's usually operating as one homogenous environment and it's it's a single entity. Usually there's not many Acquisitions kind of regardless of size that take much longer than that. I'm curious if you run into much can't think about Cloud native and containers and microservices and a lot of people are using observability platforms, which are an evolution of logging alerting and adding tracing and bunch of stuff to it.
Is that in terms of your kind of platform and services. Is that something you see as a I can imagine acquiring company might have that kind of newer technology also and the larger company maybe they're getting started on cloud Nate. Maybe they're into it.
But I've been a lot of cases it's you know, not the majority of what they're doing. So that could cause a real Rift of okay, we had to think about these things differently about how we manage the security of those kind of apps true. Yes or no.
I mean typically the the companies that have those really cloud-native micro service to Applications. They have some level of security baked into it because there's enough security products out there that kind of fold into the mix relatively easy to have to right. Yeah.
I mean if you're running a devop shop, you probably have a deaf secops practice. So usually it's you see the the acquiring company kind of back away from it like oh it looks like you have that thing handled really they have no idea how to handle itself and then if that's if there's that much of a maturity Gap, we usually see the virtualization leaders of the acquired company step into some sort of Leadership role at the acquiring company to start modernizing their applications and bake in some of that same devsecops practice and policy. We've actually seen a few Acquisitions solely for that purpose.
It was almost like an accuhire to to modernize the applications and bring them up to not just infrastructure best practice, but also security best practice and as long as your MDR mssp can integrate with some of those platforms or can bring in those alerts and Telemetry from a sin you're in pretty good standing. Interesting. How about API security?
That's kind of a Hot Topic, you know within within security and within app security. Is that something you run into folks are focusing on that? Unfortunately not.
I think if you look at the Gartner hype cycle, I mean we're probably at the peak of it for API security so and and on the downtrend So eventually we'll start to curve back up and then level off and and I think that's probably the next six to 12 months. API Security will become a more of an ingrained kind of aspect of overall Security application Security in general has always been some place where security has lagged just because of the I guess the lineage of most Security Professionals coming from an infrastructure and networking side not so much a development side, but now you do start to get those security-minded developers that are making the shift to True devsecops API Security application security Beyond a traditional sast and asked type deployment. It seems to where we've come in from is that's usually handled by the dev group the app Group handling app security and it's not necessarily an infrastructure.
Well, you have kind of platform engine Steering rate is a new role relatively speaking that starts to merge into that SRE. Is that something you see much of people doing, you know site reliability engineering. On their staff.
Is that a growing Trend? Yeah, it's it's growing but only in very very large organizations that can afford to have that that niche of a program or that tailored of expertise around and can really focus on that and honestly a lot of the customers that we're dealing with are still working on foundational controls. I mean, we're happy to get MFA deployed with conditional access set up.
We're happy to have EDR coverage on 95 plus percent of assets. We're happy to have authentication and email logs going into a Sim which we can monitor. There's there's room for growth and in more foundational areas than looking at some of the more advanced practices including API Security application security.
So in some of the more mature organizations, we see some of that but they're generally doing a lot of their own monitoring or they have their own stocks set up. It seems like on the lessons of m&a is that's where things get exposed the good and the bad, right? It kind of comes out in the wash here.
It's and you've got to go back and okay, we're not all on MFA. We're not all whatever right? So let's get that set up get it done.
Right, of course the drifts from there before the next acquisition or whatever, but that seems like it is a good time to take care of those things that you should have taken care before maybe really needed to if you've been preached or something any kind of parting thoughts were just about the end of our time here in terms of Lessons Learned or other things. You might share with folks about consider this if you're looking at or going through an acquisition Yeah, having a good procedure that's agreed upon by the executive leadership team at the organization. If you're going to be hot and heavy in Acquisitions as always good that way, you know, there's no surprise from the CEO that says get this done.
You can point to the policies and say Hey you signed off on this policy. We're following this and and then also I mean to your last Point looking at something that assesses posture at a very high level just to make sure there's some level of cohesity and and structure to the security program. There's a lot of new companies coming out exonius cefco six Sense come to mind that are looking at posture from a very basic level of do you have AV install?
Do you have patching installed are these assets and active directory and and are they being properly monitored and covered from a cybersecurity perspective having that in place certainly does speed up the process of making sure there's proper coverage across the Acquired and the acquiring organization and that there isn't too much drift. So it always comes down to you know an Preparation is worth a pound of cure. So making sure that you have that we call it an m&a kit an m&a go kit ready to go.
So hey, I have these installers ready to rock. I have a heavy forward that's ready to go. You know, I have this iot security that's ready to get dropped in place having that ready to go really using security to enable business as opposed to hinder business typically wins out in the long run and and results in much better, you know m&a and kind of speeds out that process.
It sounds like an excellent recommendation to me. Well Randy great to have you join us today working folks find out more about critical start. Yeah.
com. Great. Thanks for being with us Randy.
Randy Watkins CTO with critical start. I will come back again soon. Thanks, Mitch you bet.