Buddies, associates? One happy family?
A traditional dish called zongzi is served during China’s Dragon Boat Festival, which falls in June. It is a rice…
Divina credited the firm’s achievements to its members, thanking them for their ‘hard work, dedication, teamwork, and…
‘Sec. Vince Dizon, please explain how this finding of your own team should not be flagged as a ghost project in Taguig.’
Technical due diligence is a given in almost every acquisition or investment involving technology companies. The diligence checklist can be daunting for acquirers and targets alike, but as a new study published by (ISC)2 confirms, auditing for cyber security is and should be at the top of the checklist. In fact, the (ISC)2 survey of 250 US-based M&A professionals showed that 100 percent of the executives and M&A advisors surveyed agreed that cyber security audits have become standard practice.
Why companies conduct cyber security audits
To understand why companies are auditing for cyber security, we must first understand the risk. In the same study, (ISC)2 found that security breaches that come to light during the due diligence process can derail a transaction; almost half (49 percent) of participants said they had seen it happen. Further, 52 percent of respondents viewed an audit revealing weak security practices as a liability. The same number said a post-acquisition security breach in an acquired company has affected the share value of publicly traded organizations.
It’s clear a cyber security breach can significantly affect shareholder value. During integration, it’s critical to expose, and plan to deal with, any potential weakness at a target company.
Urgent need for open source audits in M&A
There are many angles to consider when auditing for cyber security in an M&A transaction. For example, consider the high-profile Equifax breach.
The breach occurred when an unpatched open source vulnerability compromised the personal data of millions of people. Equifax paid the price in both brand damage and shareholder value. But as we’ve learned in the aftermath, not everyone learns from the mistakes of others.
In the year following the Equifax breach, Fortune published a piece under the headline “Thousands of Companies Are Still Downloading the Vulnerability That Wrecked Equifax.”
Synopsys’ annual Open Source Security and Risk Analysis report is based on the anonymized data from thousands of open source audits we perform for M&A due diligence. The 2019 report found that 60 percent of the codebases we audited during 2018 contained at least one open source vulnerability. Further, 43 percent of the codebases contained vulnerabilities over 10 years old.
As we learned from Equifax, unpatched software vulnerabilities are one of the biggest cyberthreats organizations face, and unpatched open source components in software add to security risk.
Certain characteristics of open source make vulnerabilities in popular components attractive to attackers.