A cyber resilient approach to acquisitions
Accenture has been described as the world’s most acquisitive firm. In the first quarter of fiscal 2024, Accenture closed 12 acquisitions for a total of $788 million, acquiring, on average, a new company every two weeks. This past fiscal year saw 25 acquisitions. Our company’s ability to invest at scale to fuel our organic growth
This risk stems from cyber criminals who monitor the market and continue to develop new attack targets. Small companies are generally not of interest until a big company announces an acquisition intention. These criminals then strike in an attempt to extort from the acquiring company whose cash stake in the acquisition target has been made public.
These threats had our Information Security organization zeroing in on how do we rapidly change the security posture of smaller companies and keep them secure? We knew it was critical to remediate risks early and to shorten the integration timeline. Yet, this is no small feat given the companies acquired vary immensely in type and variety of IT environments.
Here’s how we did it.
?
Our cyber enablement program
Our Information Security organization industrialized a comprehensive Acquisition Cyber Enablement (ACE) program that proactively strengthens the cyber resilience of a company prior to acquisition, during integration, and into standard operations against inevitable attacks. Led by Jeff McIlrath, the program consists of synchronized coordination of information security and information technology teams working through four stages—prepare, protect, integrate, and stabilize.
Key highlights include:
Prepare: Before Accenture even signs a deal, we expect acquisition targets to comply with 10 critical baseline controls, such as using multifactor authentication
Protect: We then focus on rapid risk reduction
Integrate: We enable the technical integration
领英推荐
Stabilize: We created this phase for newly acquired companies to demonstrate operational effectiveness
?
A welcome approach to secure integration
Accenture has built a reputation among small businesses and their advisers as being a good acquirer. Among the things they value is our rigorous and collaborative cyber enablement.
ACE is an investment Accenture makes in acquiring a company to protect it by assessing the information security risk of an acquisition up front, reducing risk in that organization’s environment, and integrating its IT assets into Accenture’s IT environment with a standardized integration plan that supports migration into Accenture’s Information Security immune system.
Our ACE approach does so at speed and scale in handling the variety and pace of acquisitions. On average, the integration of an acquired company takes a year. With ongoing standardization and continued learning, the timeline to integrate is expected to decrease further.
More than ever, our Information Security organization recognizes how critical a security assessment is before a company is acquired. A prospective company’s information security posture is a key decision point in Accenture’s journey to acquire a company.
Rather than making cyber resilience an afterthought, consider embedding it in your business strategy from the start. Check out our The Cyber-Resilient CEO for five practical steps.
As always, I am happy to talk more with you about proactive cyber enablement and other cybersecurity topics. Let’s share what we know to secure what we must.
?
??CISSP | Cybersecurity Executive | Expertise in Risk Management & Compliance |Guiding Organizations to Secure Excellence!
11 个月Thanks for sharing , I would also be happy ,to be part of the activity
Helping customers Do Cloud Right so they capture all the benefits of Cloud Adoption for their business
11 个月Great stuff. I'll resist posting white papers. : )
CIO / CISO / Board Advisor / Lecturer. Avanade - A joint venture between Microsoft and Accenture.
11 个月Great share Kris and a quick read for folks! Appreciated.
Security Consultant @ Accenture | Investor | Reader
11 个月A very forward-thinking approach (ACE) to cybersecurity in the context of acquisitions. And aligned with Julie's commitment and vision "Cyber resilience = Business resilience". Identifying and addressing security risks early can save a lot of time and trouble down the road I appreciate the emphasis on information security posture as a key decision point in the acquisition process. This sends a strong message about Accenture's commitment to cyber resilience