Solusec: Solutions for Cyber Security

Operated by Solusec Ltd
CREST accredited · IASME Certification Body

Inherited estates

You have just bought somebody else\u2019s attack surface

The acquired company had its own systems, its own suppliers and its own shortcuts. Testing after integration tells you what you already own. Testing before tells you what you are buying.

Urgent penetration testing › After an acquisition

Acquisitions create a security problem that is genuinely different from ordinary risk management, because for a period you are responsible for an estate you did not build, do not understand, and may not have a complete inventory of.

The single most valuable thing you can do is test before the networks are joined. Once they are, a compromise on their side is a compromise on yours, and the window in which the two are separable has closed.

Before integration: what to test, in order

1. External perimeter discovery

Start with what the internet can see, because you cannot rely on the inventory you were given. Acquired companies routinely have forgotten public assets: a marketing microsite from a campaign three years ago, a staging environment somebody left exposed, a remote access appliance from a previous IT provider.

Discovery first, then testing. On an estate of any size, discovery reliably finds assets that were not on the list, and those are exactly the ones nobody has patched.

2. Remote access and identity

How do their people get in, and how would an attacker? VPN appliances, remote desktop gateways, and cloud identity are the three routes that turn an inherited weakness into a company-wide incident. Check for multi-factor authentication coverage across all of them, not just the main tenant.

Pay particular attention to accounts belonging to their previous IT supplier, which frequently survive the transition with high privilege and no owner.

3. Anything with the word "legacy" attached

Every acquired estate has a system somebody describes apologetically. That system is usually unsupported, usually reachable from more places than it should be, and usually holds something important. Find out what it is, what it touches, and whether it can be segmented before the networks join.

4. Evidence of prior compromise

This is the question nobody asks and the one that matters most. You are not only inheriting weaknesses, you may be inheriting an active intrusion. A compromise assessment is a different exercise from a penetration test and is worth running in parallel on any acquisition of reasonable size.

If a penetration test turns up signs that somebody got there first, that is an incident and it should stop the test, which is why the rules of engagement need a clause covering it.

After integration: what changes

Once the networks are connected, the question shifts from "what did we buy" to "what can now reach what". An internal test is the right instrument, specifically looking at whether a foothold on the acquired side reaches the systems that matter on yours.

Active Directory is where this usually plays out. Trust relationships created during integration, privileged accounts duplicated across both domains, and group memberships that made sense in isolation and do not in combination.

A realistic sequence

Testing sequence around an acquisition
StageTestWhy then
Due diligence, if access allowsExternal discovery and perimeter testFindings can affect price or warranties. Rarely possible, valuable when it is.
Completion to integrationFull external test plus identity and remote access reviewThe last point at which the two estates are separable.
Integration planningReview of proposed trusts and privileged accessCheaper to design out than to remediate later.
Post-integrationInternal test across the combined estateAnswers the only question that now matters: what does a foothold reach.
Twelve months onReturn to the normal annual cycleThe estates are one estate by then.

The commercial reality

Acquisition timetables do not accommodate three-week lead times, and the window between completion and integration is often days rather than weeks. Two things help.

First, a contained external test of the acquired perimeter can be bought as a fixed fee and started quickly, which covers the highest-value question without a scoping cycle. Second, telling a provider the deadline and the reason at the first conversation lets them tell you honestly whether it works, while you still have time to make other arrangements.

What to do with the findings

Differently from an ordinary test. Findings on an acquired estate frequently belong to somebody who no longer works there, on a system nobody currently owns, supported by a contract that may have lapsed. Assign owners on your side from the start, and treat "we need to find out who owns this" as a finding in its own right.

The inventory problem, and how to get round it quickly

Every acquisition has the same first obstacle: the inventory you were handed is incomplete, and you have no way of knowing by how much. Asking for a better one takes weeks and produces a document written from the same memory as the first.

External discovery sidesteps the problem entirely. Rather than asking what they own, you find what the internet can see attributed to them, which is both faster and more honest.

The starting points are ordinary: registered domain names and their subdomains, IP ranges registered to the company, certificate transparency logs showing every TLS certificate ever issued for their domains, and public code repositories bearing their name. Certificate logs in particular are difficult to hide from, because a certificate issued for an internal-sounding hostname three years ago is still in the public record.

On any estate of reasonable size this reliably finds assets that were not on the list. A staging environment from a project that finished, a remote access appliance from a previous IT supplier, a marketing microsite on somebody's personal hosting account, a development server exposed because a firewall rule was temporary in 2022.

Those forgotten assets are disproportionately likely to be the vulnerable ones, precisely because nobody has been patching something they had forgotten about.

Questions worth asking the acquired IT team early

Before the relationships get complicated, and while people still have institutional memory, four questions return more than any document will.

  1. What keeps you up at night? Someone always knows about the system everyone works around. Ask before they leave.
  2. Who else has access? Previous suppliers, contractors, the founder's brother-in-law who set up the network. Accounts belonging to people who are no longer involved are the most reliable finding in any acquisition.
  3. What have you been asking for budget for? The answers are a ranked list of known problems, already prioritised by the people closest to them.
  4. Has anything happened? Previous incidents, however minor, and however they were handled. Not to apportion blame, but because an incident eighteen months ago that was never properly investigated may not be over.
Can we test before completion?

Only with the target\u2019s written authorisation, which in practice means it forms part of the due diligence process. It is uncommon and genuinely valuable when it happens, because findings can affect price and warranties rather than just the integration plan.

How urgent is this really?

The window between completion and network integration is the point of maximum value and it is often short. If integration is weeks away, an external test of the acquired perimeter is the highest-value thing you can buy. If the networks are already joined, an internal test is.

What if the acquired company already had a recent test?

Read it rather than repeating it, but check three things: the scope, the date and whether the findings were closed and retested. A report showing twenty open findings from eight months ago is a list of things you have just bought.

Should we test for an existing compromise as well?

On any acquisition of reasonable size, yes. It is a different exercise from a penetration test and answers a different question. A penetration test asks whether somebody could get in. A compromise assessment asks whether somebody already has.

Working to a completion date?

Tell us the date and what you have inherited. We will tell you what can be covered in the time, and what cannot, on the first reply.