Every acquisition is different, but the challenges facing physical security teams are often the same. As discussed in Aligning roadmaps for acquisitional growth, successful integration depends on aligning budget, technology, people and culture while ensuring security has a seat at the table throughout the acquisition process. The priorities, however, will vary depending on where your organization is in its acquisition journey.
Whether you’re preparing for future growth, actively integrating a newly acquired company or managing acquisitions as an ongoing part of your business strategy, security leaders must adapt their planning to the situation at hand. The following three scenarios outline practical considerations and planning tips to help guide your approach.
Three scenarios
Let’s game out three common scenarios regarding physical security at acquiring companies. Do any of these match a scenario your business is facing? If so, read on to find out some advice for each one.
1. FUTURE-PROOF: We plan to acquire. What can we do now?
If you think M&A changes might be on your company’s horizon, but no target company has yet been named, proactive thinking is your key to warding off messy future challenges. Beyond ensuring security is part of the M&A committee at your company, here are some other best practices for being prepared.
Start where you are
It’s never too soon to get started. Clarify risk profiles so they can be compared sensibly to those of any company you’re acquiring. Sketch out rough plans for various M&A models: What are the special considerations if we acquire a small company versus a larger one? What’s our plan if the rumors that we’re acquiring Company X are true? Having this work done and in your back pocket gives you and your team peace of mind and a head start whenever an acquisition is announced.
Plan ahead, especially budget-wise
Do your best to pre-allocate funds for likely integration activities, including systems migrations, retraining, change management and travel. Standardize core platforms and reduce or simplify as much as possible so that when the time comes, your technology is well positioned to either meld with or supersede that of the company you’re acquiring. Use your M&A models to start attaching preliminary pricing to the various systems integration scenarios you might encounter. Identify any compliance expectations pertaining to the integration time frame.
Modularize program elements
Picture a future moment when you’re faced with integrating operations across two disparate security teams, and then rewind the tape to where you are now. What’s the best possible structure for your security programs for ease of transition? Adjust your processes and team structures accordingly, and use an updated organizational chart to create role-mapping templates for each job position. Having apples-to-apples comparisons will help streamline your integration efforts.
2. UNDERWAY: Whoa! We’re acquiring. What’s the plan?
If your company has identified a target company it plans to acquire, be ready to participate in a security capacity as soon as possible. Apply the future-proofing tips from the first scenario, and in addition, take first steps toward making sense of mismatched systems and processes to ensure a smooth transition.
Keep steady communication
Stick close to the M&A committee, speak up often and be ready with physical security risk data, questions and specific needs. You’ll often face a number of important decisions, both as a team and as a company, and these decisions generally can’t be made by consensus due to the fast pace at which most acquisitions proceed. The sooner you can get buy-in for what you need, the faster you can make decisions that positively impact security outcomes.
Identify SMEs
Before the journey to a blended security team and roadmap gets underway, think about who will be the crucial players in this transition — system administrators, investigators and other physical security specialists — and build checklists of the acquisition-related tasks they’ll be expected to perform. This includes people in your company as well as in the one you’re acquiring, as soon as you can find out who they are.
Audit your current environment
If you haven’t recently produced a full inventory of your security assets, now is the time to get started. Build a catalog of your current-state architecture, including physical locations, vintages and versions, health and availability, and performance. Have this data ready to overlay with the acquired company’s environment details so integration strategies can proceed from accurate accounting.
3. PERPETUAL: We’re always acquiring. What can we do better?
At some large companies, acquisitional change is an ongoing reality, and perpetual acquisition leads to continually migrating physical security systems. Depending on the maturity and visibility of your security program, you can strengthen your participation in this process by seeking ways to help the value of your unique contribution stand out.
Adapt as you roll along
With ongoing acquisition cycles, you’re committed to running your security program in a constant state of flux, operating a diversity of technologies. This makes it unlikely—often unrealistic—to ever achieve true standardization across your enterprise. Instead, tailor your systems administration, monitoring and maintenance approaches to fit the reality of ever-shifting ground. Consider enhancing your program to include a dedicated M&A function where people and resources are tasked with managing constant change.
Maintain a reliable security backbone
Even as you make constant changes to security programs from acquisition to acquisition, an operable infrastructure must remain intact. Make it an ongoing priority to harmonize incident and emergency response plans every step of the way, with clear responsibilities, reporting structures and escalation paths so operations don’t break down during transition.
Double down on visibility
Security teams gain traction, efficiency and credibility during acquisitions when they are part of the core team managing acquisitional change. Make sure your security leaders are part of this team, able to add security input to vital budget and scheduling decisions, and consulted throughout the acquisition process, from early pre-announcement to post-M&A change management.
Develop security messaging
Every time your company acquires another, it’s important that everyone clearly understands what your team does and the value it brings. This is an opportunity to demonstrate thought leadership and lead conversations around physical security. Have clear, concise messaging that defines your mission, so time isn’t lost to misunderstandings as decisions are made. The more prepared and consistent you are as a security team, the further your input will travel.
Commit to timelines
Part of demonstrating security leadership during an acquisition is sharing clear, realistic timeframes for integration. Others on the M&A committee aren’t always familiar with the nuances of physical security or aware of the unique risks, opportunities and dependencies involved. As you communicate these considerations, provide realistic expectations for how long the security system and cultural integration will take.
Conclusion
Whether your organization is preparing for its first acquisition or integrating new companies as a regular part of doing business, physical security has an important role to play in the success of every transaction. Organizations that involve security early, establish clear priorities and build flexible roadmaps are better positioned to reduce risk, maintain operational continuity and create a stronger, more unified security program.
While every acquisition presents unique challenges, a thoughtful approach to planning, communication and integration can help security teams navigate change with confidence and support the long-term success of the organization.