Aligning roadmaps for acquisitional growth

Companies grow in many ways, and physical security must keep pace. Sometimes growth occurs naturally through the evolution of internal business programs, but other times one company grows by acquiring another one, and it’s often a company that’s very different from the one that’s doing the acquiring. Growth is exciting, but with growth through acquisition, security teams face challenges around integrating two sets of dissimilar systems, processes, org charts and security cultures. These planning tips should help keep you agile and prepared when your security team encounters acquisitional growth.

Converging to an integrated roadmap

When one company acquires another, there’s an inevitable mismatch between security programs and plans. Company A might have mature processes but outdated systems; Company B might have recent tech but few processes for integrating its use. Or the companies might have different deployment and application philosophies. Sometimes the company being acquired has no formal physical security program at all.

The security culture at each company can also clash: one uses phone-based mobile credentials, while the other uses proximity access cards; one is rigorous about securing its IP due to strict regulations, while the other can historically afford to be more casual. These disconnects intensify when the acquired company’s people aren’t motivated to adopt the policies and practices of their acquirer.

Guess what? Very soon, they’ll all need to play together as one organization. And if one or both of the companies has an existing security technology roadmap, they each face inheriting various aspects of the other’s strategy. For all plans to work together and operational continuity to be preserved throughout the change, security leaders must find some way to blend the two companies’ strategies and cultures to yield an integrated plan for common platforms, activities and standards across the newly unified team.

Elevating security visibility

For most of us, corporate mergers and acquisitions (M&A) seem to happen fast — sometimes without warning. The decision to merge with or acquire another company is typically made in corporate boardrooms, beyond the consideration or awareness of individual departments. As senior executives meet to discuss fine print and calculate bottom lines, they don’t always account for the true costs of merging teams, resources and processes at the operations level, including IT, facilities management and security.

During acquisitions, then, security needs to play a role in shaping change, not just executing it. The number one way to accomplish this is to identify the committee in your company that manages M&A-related changes and do what you can to make sure security is on it. With security leaders adding their voice, you’ll face fewer roadblocks and misfires as acquisitions proceed.

As due diligence proceeds in the wake of an acquisition announcement, it’s up to the security team to provide its own accounting and plans, so that budget and support are hopefully available to accommodate the transition. This means jockeying for visibility as decisions get made that impact the efficacy of security operations and the protection of the newly merged physical environments.

Four areas to focus on

Why does visibility matter so much for security during acquisitional due diligence?

First of all, this work matters because cost and scope assumptions regarding security systems and personnel that are made without security leadership present are doomed to be woefully inaccurate. But also, merging security programs often incurs expenses that go way beyond traditional personnel and technology costs: SME travel during due diligence and integration, retraining of personnel, support for new users and so on. The transition team might be aware of some of these costs, but security can be there early on to make a holistic case by showing cost models, gap analyses and other key roadmap elements.

Planning and positioning your new security journey along this blended route is a matter of examining each company’s current security program and finding effective ways to integrate each one with the other — including potentially sunsetting certain program elements by evaluating and selecting the ones that work best in the new organization.

Correlation must happen across four main areas — budget, technology, people and culture. Let’s take a look at some high-level guidance in each area to help you get started. Then, we’ll jump into three key scenarios to see the areas where emphasis is especially needed to achieve smooth results.

Correlation area #1: Budget and business integration

In many ways, roadmapping starts and ends with a budget. If you don’t have funding, you can’t provide security on the level you plan for. If you don’t work with your M&A committee to identify and amplify security considerations in your blended roadmap, you’ll miss the chance to get your share of budget up front. Be prepared with security budget items and ready to defend them. Need to consolidate and integrate massive security solutions at both companies? Find out now, not later, and obtain the funding you need to get it done.

At the same time, educate yourself on the relative security postures of the two companies, and seek to strengthen your overall posture where needed. Incoming business units often push back on requests for funding, and the security team at the acquiring company must be prepared. The best way is to be backed up by the right corporate policies and directives that reinforce security standards and put the burden on the acquiring company to ensure compliance. Lacking this leverage, the security team has very little leverage to get the business units to spend money.

Wielding emotional intelligence to keep productivity on track

Acquisitions are a time of heightened emotions, and morale can be sharply affected, particularly at the company being acquired. Simultaneously, the security program integrations that acquisitions entail often expose new, temporary security vulnerabilities.

The most success with positive morale and productivity occurs when both companies are intentional about understanding each other’s position. The acquiring company succeeds with diplomacy, helping the new teammates understand the WHY of certain changes rather than just steamrolling in to implement them. Including this “why” perspective will help prioritize integration activities with minimal disruption in a sometimes-fragile transition.

Meanwhile, the acquired company succeeds by finding power in its more modest position, showing up in good faith, knowing its questions will be heard and answered.

Correlation area #2: Technology and infrastructure

The nuts and bolts of merging security at two companies often come down to how you’ll overlay the tech components — primarily your access control and video surveillance platforms, but also the other systems, platforms, applications, network appliances and other technologies that support security at your sites. It also helps to have the annual costs of operating your security program ready to share, as you might discover opportunities for savings as you go along, such as lowering operating costs by eliminating redundant server resources and application licenses.

Ultimately, your goal is to retrofit and standardize systems across two — or sometimes more — environments. In the course of doing this, you’re likely to uncover gaps and mismatched elements that will take time and money to fix. In some cases, the whole platform at your company or the one you’re acquiring might be so close to end-of-life that the acquisition is actually a chance to wipe the slate clean and start over. Make sure your M&A committee understands the importance and nuances of your concerns and has visibility and clarity on your proposed approach.

Correlation area #3: People and roles

Role redundancy is usually what people fear most when they hear their company is undergoing M&A. The axe can fall pretty hard in some acquisitions, depending on how similar the roles and procedures are in each environment. Security is no exception. As soon as you can, you’ll want to carefully document teams, roles, duties and job descriptions at both companies to check for overlaps and gaps.

But don’t make assumptions too fast. You won’t know exactly how many people are needed until you’re crystal clear on the direction your new roadmap is taking. In some cases, so-called redundant personnel can be retrained, reassigned or even promoted based on revisions you make to integrate operations.

Use your voice on the M&A committee to make your personnel expectations clear. No matter the outcome, you’ll benefit from having a clear sense of each company’s security team and how their methods of providing security services compare.

Correlation area #4: Culture

Security culture is a vital consideration for acclimating newly merged companies to one another. The characteristics of a company’s culture drive the way it does business, and when one company acquires another, those cultures have the potential to clash.

Some large companies have been so stung by this reality they’ve made cultural association a deciding factor over others in whether to acquire a company or to alternatively continue growing some other way.

At companies that acquire or are acquired, these culture clashes can impact a physical security program in various ways. Users at smaller companies acquired by larger ones sometimes feel like “Big Brother” is watching them, whereas they formerly operated with less electronic oversight. If the security team at an acquired company has less sophisticated platforms and processes, they can feel overwhelmed by the need to upgrade both and adjust their approach. Change management is essential for addressing these issues and providing a unified security culture at the resulting merged company that everyone feels a part of.

Navigating security culture differences

Acquired companies often feel bombarded with integration requirements, including many that don’t match up with the security culture they’re accustomed to.

To help ease these differences, enable the business, and reduce the stress of change, both companies’ integration teams should ensure security leadership from both sides is engaged, not just the acquiring company, while helping the security team itself adjust to the increased risks it often faces as part of becoming a larger brand or differently focused operation.

Preparing for the scenarios ahead

Budget, technology, people and culture provide the foundation for aligning security programs during acquisitional growth. However, the way these areas are addressed will depend on where the organization is in the acquisition process. A company preparing for possible growth will face different priorities than one responding to an acquisition already underway or managing acquisitions as an ongoing part of its business.