Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Managing Application Connectivity Securely Through A Merger Or Acquisition
Articles

Managing Application Connectivity Securely Through A Merger Or Acquisition

ISBuzz TeamBy ISBuzz TeamAugust 22, 2016Updated:May 2, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

For many businesses a merger or acquisition is highly charged. There’s often excitement about new beginnings mixed with angst that comes with any major business change – not least when it comes to IT security.

During a merger and acquisition, you have two enterprises each running complex IT infrastructures with hundreds if not thousands of applications. Usually, these applications don’t just simply integrate together– rather, some perform overlapping functions and need to be altered or extended; some need to be used in parallel; while others need to be decommissioned and removed.

This means amending, altering and updating firewall policies to accommodate new connectivity, new applications and new servers and often new firewalls – crucially, without creating IT security risks or outages. In essence, from the IT security perspective, a merger or acquisition is a massively complicated project that, if not planned and implemented properly, can seriously impact business operations for a long time.

Starting the migration process

 And, as with many IT projects, getting underway can seem daunting – particularly when there are very different infrastructures and different teams that need to be bought together to undertake the project. Generally speaking however, there are a couple of key steps that can quickly help you get going.

First, you need a complete inventory of the business applications of both organizations. This can be done with auto-discovery tools that collect data on any item that is connected to the network.  Once the application and its components are “discovered” and you know how they communicate with each other you’ll have a clear and accurate map of all the network connectivity flows.  This is your blueprint for how you will migrate the current environment to the new environment from an application connectivity perspective.  While its one huge task to build the foundation, it will put your security and networking group in a position to transform your business.

Next, you need to complete a vulnerability assessment (VA) across both enterprise networks, and identify the business-critical applications at risk.  The network inventory, which determines all the application connectivity flows, is a good starting point for the VA – giving you the basis to understand the risk associated with each application.  In this next step you need to identify and prioritize the devices you really care about.  For example, you probably are concerned with vulnerabilities on the trading application that contains the most vital customer and corporate risk information from the company that you just acquired, but may not care too much about vulnerabilities on a system that has no sensitive data.

By following these steps you’ll get a clear business-centric view of the entire enterprise environment: you’ll be able to identify and map all the critical business applications, easily link vulnerabilities and cyber risks to specific applications, assess risk and make smart decisions on how to prioritize remediation actions based on business-driven needs.

Verify, standardize, automate

This will give you with an accurate picture of your current IT topology and its business risk, but of course, this is only the first half of the story. Now you need to update the security policy to support changes to business applications.

However, unlike an internal firewall change management project, a merger or acquisition almost certainly involves two companies that have different types of firewalls in place, such as a mix of traditional and next-gen firewalls from firewalls from multiple vendors, as well as cloud-based security controls.

As Gartner underlined, a huge majority of data breaches are caused by firewall misconfigurations, therefore attempting to change firewall policies manually – especially in such a complex environment – is a fool’s errand.

So to ensure that the firewall change management process is handled efficiently and with minimal risk of misconfiguration, automation is essential.  Automated security policy management solutions should provide visibility of the entire firewall estate (traditional, NGFW and cloud-based security controls, Software Defined Networks (SDN), Cisco ACI, etc.) and be able to support all firewalls holistically from a single point of control. Moreover, the solution should be able to assess risk, translate and apply policies across all devices, to close any potential security gaps and minimizes the risk of any misconfigurations occurring.

What about security maturity?

 Another thing to consider is that the two companies may not be at the same stage on the security policy management maturity model – something we’ve written a series of blogs about in the past. The likelihood is that one company may be more mature from a security policy management perspective than the other. Therefore, when two companies become one, it is vital that they get on the same page.

Maintaining security throughout the transition

 A merger or acquisition presents a range of IT challenges but ensuring business applications can continue to run securely throughout the transition is critical.  If you take an application centric approach and utilize automation, you will be in the best position for the merger/migration and will ultimately drive long term success.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}