West Monroe in West Monroe Partners’ New York Partners’ Mergers and Acquisitions Office
Total Page:16
File Type:pdf, Size:1020Kb
TESTING THE DEFENSES CYBERSECURITY DUE DILIGENCE IN M&A Contributors Sean Curran Paul Cotter Director, Security & Infrastructure Senior Architect, Security & Sean Curran is a director in West Infrastructure Monroe Partners’ Security and Paul is an experienced and Infrastructure practice, based in practiced security professional, Chicago. He has more than 20 years with over 15 years of experience of business consulting large-scale in software, infrastructure and infrastructure experience across a organizational security for range of industries and IT domains, including extensive Fortune 100 companies. Paul has performed several work in the areas of data and information security. He functional diligences in the security product space, has experience designing secure environments, helping including Endpoint Protection, Network Intrusion clients adhere to industry and government compliance Detection, Threat Intelligence, and Deep Packet frameworks including PCI DSS, HIPAA and ISO 27000. Inspection products. 312.386.6195 312.846.9974 [email protected] [email protected] Matt Sondag John Stiffler Managing Director, Mergers & Senior Director, Mergers & Acquisitions Acquisitions Matt Sondag is a managing director John Stiffler is a senior director and the leader of West Monroe in West Monroe Partners’ New York Partners’ Mergers and Acquisitions office. A skilled business consultant practice in Chicago. He specializes with a strong technology background, in corporate divestitures and Matt is responsible for expanding and deepening the operates as a client partner, combining strategy, firm’s unique offerings to the private equity market, financial, people, process, and technology disciplines including its merger and acquisition services. Matt to deliver technology-enabled business change. He works with private equity and strategic buyers involved has over 30 years of global business and technology in or preparing for investments and acquisitions. He consulting experience across multiple industries with assists buyers with pre-deal IT and operational due heavy emphasis in manufacturing and distribution, diligence, as well as post-close projects (integration healthcare, high tech and professional services. and carve-out activities). 312.980.9427 312.980.9446 [email protected] [email protected] westmonroepartners.com | 800.828.6708 ContributorsContributors Sean Curran Paul Cotter Director,Sean Curran Security & Infrastructure SeniorPaul Cotter Architect, Security & Director, Security & Infrastructure InfrastructureSenior Architect, Security & Contents Sean Curran is a director in West Infrastructure Sean Curran is a director in West Paul is an experienced and Monroe Partners’ Security and Paul is an experienced and Monroe Partners’ Security and practiced security professional, InfrastructureInfrastructure practice, practice, based based in in practiced security professional, with over 15 years of experience Chicago.Chicago. He He has has more more than than 20 20 years years with over 15 years of experience in software, infrastructure and ofof business business consulting consulting large-scale large-scale in software, infrastructure and Foreword 4 organizational security for infrastructureinfrastructure experience experience across across a a organizational security for Fortune 100 companies. Paul has performed several rangerange of of industries industries and and IT IT domains, domains, including including extensive extensive Fortune 100 companies. Paul has performed several Sounding the alarm 6 functional diligences in the security product space, workwork in inthe the areas areas of of data data and and information information security. security. He He functional diligences in the security product space, including Endpoint Protection, Network Intrusion hashas experience experience designing designing secure secure environments, environments, helping helping including Endpoint Protection, Network Intrusion Assessing the risks 8 Detection, Threat Intelligence, and Deep Packet clientsclients adhere adhere to to industry industry and and government government compliance compliance Detection, Threat Intelligence, and Deep Packet frameworksframeworks including including PCI PCI DSS, DSS, HIPAA HIPAA and and ISO ISO 27000 27000. InspectionInspection producproducts.ts. PE paying up 12 312.386.6195312.386.6195 312.846.9974312.846.9974 [email protected]@westmonroepartners.com [email protected]@westmonroepartners.com Hitting the escape button 13 Good governance 14 MattMatt Sondag Sondag JohnJohn StifflerStiffler Unpleasant discoveries 18 ManagingManaging Director, Director, Mergers Mergers & & SeniorSenior Director,Director, Mergers & AcquisitionsAcquisitions AcquisitionsAcquisitions Conclusion 20 MattMatt Sondag Sondag is is a amanaging managing director director JohnJohn StifflerStiffler is a senior director andand thethe leaderleader of West Monroe Appendix: Respondent profiles 21 inin West West Monroe Monroe Partners’ Partners’ New New York York Partners’Partners’ MergersMergers and Acquisitions office.office. A Askilled skilled business business consultant consultant practicepractice inin Chicago. He specializes withwith a astrong strong technology technology background, background, inin corporatecorporate divestituresdivestitures andand MattMatt is isresponsible responsible for for expanding expanding and and deepening deepening the the operatesoperates asas aa clientclient partner,partner, combining strategy, firm’sfirm’s unique unique offerings offerings to to the the private private equity equity market,market, financial,financial, people,people, process,process, andand technology disciplines includingincluding its its merger merger and and acquisition acquisition services. services. Matt Matt toto deliver deliver technology-enabledtechnology-enabled business change. HeHe worksworks with with private private equity equity and and strategic strategic buyers buyers involved involved hashas over over 3030 yearsyears ofof globalglobal business and technology in inor or preparing preparing for for investments investments and and acquisitions. acquisitions. He He consultingconsulting experienceexperience acrossacross multiple industries withwith heavy emphasis in manufacturing and distribution, assistsassists buyers buyers with with pre-deal pre-deal IT IT and and operational operational due due heavy emphasis in manufacturing and distribution, diligence,diligence, as as well well as as post-close post-close projects projects (integration (integration healthcare,healthcare, highhigh techtech andand professionalprofessional services. 312.980.9427 andand carve-out carve-out activities). activities). 312.980.9427 [email protected] 312.980.9446312.980.9446 [email protected] [email protected]@westmonroepartners.com westmonroepartners.comwestmonroepartners.com || 800.828.6708800.828.6708 Testing the defenses: Cybersecurity due diligence in M&A 3 Foreword Big data and IT are becoming ever more critical to the modern “When a data breach corporate world. As their importance rises, data security has become vital for ensuring business continuity and protecting lands on the front page a company’s most prized assets – its customer information and intellectual property. of CNN.com or The Wall Street Journal, The costs of failing to keep data secure are increasing rapidly. In 2015, the average cost of a data breach reached US$3.79m, companies start to a 7.6% increase over 2014, according to a survey commissioned pay closer attention by IBM. Overall, the total cost of cybercrime to the global economy as estimated by software-maker McAfee can reach to the issue. In the last up to US$575bn per year. 18 to 24 months, we In the realm of M&A, concerns about cybersecurity are becoming have really started to a critical issue when companies target acquisitions. A company’s cybersecurity infrastructure – or lack thereof – can affect the deal see the importance of price, and at times determine whether a potential acquirer goes cybersecurity resonate through with a deal at all. with our clients.” Data security has long been an issue for M&A activity in certain sectors, such as retail and technology. In recent years, however, Matt Sondag, Managing Director, it has become relevant across industries. Take healthcare: in West Monroe 2015, major insurer Anthem suffered a breach of an estimated 80 million customer records after hackers broke into its network, part of a string of breaches at medical firms. In the telecom industry, British firm TalkTalk saw the data of 157,000 customers exposed, and the company predicted the incident would cost it over US$50m. In order to protect themselves from security lapses, acquirers are turning to vigorous due diligence to examine the IT infrastructure of deal targets. Diligence procedures are quickly expanding and improving – but many companies continue to identify shortcomings in the process. Our report surveyed top-level corporate executives and private equity partners about their companies’ practices in order to better understand the state of cybersecurity diligence for M&A. The results provide a window into the trends that shape the diligence process, as well as insights into the ways it can be improved. We hope the report proves useful to you as you navigate the increasingly complex dealmaking landscape. 4 Key findings include: Cybersecurity diligence is no longer Good governance trumps