Consolidating IAM After an Acquisition

When one firm acquires another, it acquires the target’s identity and access estate — a second set of users, systems, entitlements and IAM tooling that now has to coexist with, and eventually merge into, the acquirer’s. Consolidating IAM after an acquisition is one of the more security-critical and under-planned parts of integration, because until it is done, the combined organisation has two overlapping access worlds, inconsistent controls, and a set of seams that are exactly where security incidents and audit findings emerge. It is also genuinely hard, which is why it rewards being run as a deliberate programme rather than a background task.

Why post-acquisition IAM is a distinct problem

Merging identity is harder than merging most systems because identity is everywhere and touches everything. The two organisations have different identity platforms, different access models, different naming, different privileged-access practices, and different maturity — and all of it is live, governing access to systems people need to keep working. You cannot simply switch one off. During integration, you have duplicate identities, unclear access across the boundary, inconsistent controls, and often a rush to grant cross-organisation access for collaboration that creates exactly the over-permissioning a later audit will flag. The target’s IAM may also be weaker than the acquirer’s, meaning you have inherited access risk you did not assess in detail during diligence.

The decisions that shape the outcome

  • The target state, decided early. Which platform survives, what the unified access model is, how identity will work in the combined organisation — deciding this early prevents the drift where two estates calcify side by side.
  • Cross-boundary access, granted carefully. The pressure to enable collaboration quickly leads to broad, ungoverned access across the two organisations; scoping this deliberately avoids importing a mess you will spend years cleaning up.
  • The inherited risk, assessed properly. The target’s privileged access, its dormant accounts, its access practices — these are now yours, and they need the scrutiny that diligence may not have given them.
  • The migration, sequenced to keep people working. Consolidating identity cannot break access to the systems the business runs on; the sequence has to balance security with continuity.

Running it as a programme

  • Decide the target state before you start merging. A clear unified identity model and platform decision, made early, is what keeps the consolidation from becoming permanent coexistence.
  • Govern cross-boundary access from day one. Least privilege across the organisational seam, so collaboration does not become uncontrolled access.
  • Assess and remediate inherited access risk. Treat the target’s IAM estate as something to be scrutinised and cleaned, not just absorbed.
  • Sequence for security and continuity together. Plan the migration so access stays working while the controls converge, rather than trading one for the other.

Post-acquisition IAM consolidation is where a lot of integration security risk concentrates, precisely because it is complex, live, and easy to defer behind more visible integration work. The firms that handle it well treat it as a governed programme with a decided target state, careful cross-boundary access, and honest attention to inherited risk — turning two access worlds into one deliberately. The ones that let it drift run for years with overlapping estates, inconsistent controls, and a set of identity seams that an attacker or an auditor will eventually find.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

Who this is for

This reading is for:

  • Acquirers integrating a target’s identity and access estate
  • CISOs handed two IAM platforms to merge
  • Integration leads for whom “who can access what” is now doubled
  • Boards tracking post-deal security and integration risk

Sixteen Pillars runs post-acquisition IAM consolidation as a governed programme – decided target state, careful cross-boundary access, honest attention to inherited risk. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Build and rescue work

Hands-on delivery of this kind is handled by Sixteen Pillars Studio.

Looking at an acquisition, supplier, or major project?

The greatest risks are rarely visible in the executive summary. The Sixteen Pillars framework surfaces the technology risks that diligence usually misses.