Est.
Insider RiskLong read

Insider Risk Considerations in Mergers and Acquisitions

M&A deals create predictable insider risk windows that standard security tools consistently miss.

Reporter · · 13 min read
Cover illustration for “Insider Risk Considerations in Mergers and Acquisitions”
Insider Risk · September 21, 2026 · 13 min read · 2,935 words

M&A deal volume is climbing fast, and it drags a phase-specific insider risk problem behind it that most security programs are not built to catch. U.S. Deal volume is on pace to hit roughly $2.3 trillion in 2025, up 49% from the year before, according to the Harvard Law School Forum on Corporate Governance's write-up of Wachtell Lipton's year-end review. Barclays Investment Bank put global M&A volume above $5 trillion for 2025 and expects the pace to hold through 2026. Every one of those deals opens the same predictable window: workforce anxiety, expanding identity perimeters, rushed system integration, and sensitive data pooled into shared rooms before anyone has agreed on who is allowed to see it.

Most security teams treat this as a hypothetical. Most security teams treat this as a hypothetical, but it is not: this piece breaks down where insider risk concentrates across the M&A lifecycle, why tools built for stable organizations miss it every time, and what a phase-specific control framework actually looks... This piece breaks down where insider risk concentrates across the M&A lifecycle, why tools built for stable organizations miss it every time, and what a phase-specific control framework actually looks like.

What Makes M&A Structurally Different From Ordinary Insider Risk Conditions

Most insider risk programs assume a fairly steady picture of the company: a known workforce, established access patterns, systems that barely change month to month. M&A breaks nearly every one of those assumptions, and it breaks them all at once, not one at a time.

INSA's Insider Threat Subcommittee laid out the shape of the problem in a report, describing three distinct forms insider risk takes during M&A. The first is outright malicious behavior: employees who feel threatened, passed over, or cheated by the deal, and who decide to punish the organization or take something valuable with them into a new role. The second is negligence born of stress. A 2022 Harvard Business Review article cited in the INSA report found that employees under stress are considerably more likely to skip cybersecurity protocols they would normally follow, and a merger is, for most of the workforce, a stress event by definition. The third is sabotage aimed at the deal itself: fraud, ethics violations, or deliberate leaks meant to derail the transaction before it closes.

Here is what most organizations get wrong: they document all three categories and still never build insider risk practices into the M&A process itself. It gets bolted on as a compliance checkbox instead of run as an operational discipline with its own timeline, tied to the deal's actual calendar rather than the annual security review cycle. ReliaQuest's research found cybercriminal forums where threat actors deliberately hunt for companies mid-deal, betting that a security team buried in integration logistics will not notice an intrusion for longer than usual. Dwell time stretches out during M&A, and attackers know it.

The three INSA categories, malicious, negligent, and sabotage, do not distribute evenly across a deal's timeline. Each concentrates in a different phase, for different structural reasons, and that mapping is the point of what follows.

The pre-announcement phase: high secrecy, undetected accumulation, and the insider who knows first

INSA notes that before a deal goes public, knowledge of it stays inside a small circle limited to the C-suite, the board, and outside advisors like investment banks and outside counsel. Those advisors have little reason to leak; their business depends on discretion. The real asymmetry is that a handful of insiders now hold deal-critical information while the company's security controls are still calibrated for a world where that information did not exist.

Three risk patterns cluster in this window. Executives and senior staff doing valuation work or reviewing target company details often carry broad system access granted long before the deal was even a consideration, and nobody has gone back to check whether that access still makes sense. Third-party advisors moving through data rooms get exposure to financials, IP portfolios, and strategic plans, by definition the most sensitive material the company owns. And employees who simply notice something is off (unusual executive travel, a locked conference room, a rumor from someone's cousin at the bank) sometimes start collecting data preemptively, hedging against whatever comes next.

The data most exposed here does not usually carry a classification label. Valuation models, IP inventories, strategic roadmaps, customer lists: these define what the deal is actually worth, and a DLP rule built around regulated data types like a sensitive personal identifier or a payment card number will not flag any of it. Behavioral baselines for the small group involved barely exist, because the group is small and its behavior has never been modeled before. The access is authorized. The data movement looks routine on paper.

That is the deeper risk in this phase. Access channels opened quietly before announcement, with no adjustment to controls, tend to persist and widen once the deal goes public and a much larger population inherits them.

The due diligence phase: data rooms, third-party access, and IP pooling as a threat surface

Due diligence forces both companies to open their most sensitive material to outside eyes: financial models, customer contracts, source code, R&D, manufacturing processes, regulatory filings. The access granted is intentionally broad and intentionally short-lived, and that combination happens to be the exact one insider risk programs handle worst. The access is authorized by design, and the compressed timeline discourages anyone from slowing down to vet it properly.

Third parties, consultants, auditors, outside counsel, get into data rooms with limited identity checks and often no behavioral history to compare against. BeyondTrust's research points to identity debt as a related cause: most organizations already carry orphaned service accounts and "zombie" accounts that have sat active without use for 90 days or more. Layering a due diligence process on top of that mess means nobody can say with confidence who actually has access to what.

INSA flags a version of this problem that is easy to overlook: on the target company's side, ordinary employees frequently have no idea a sale is even being discussed while the acquirer's team is combing through their organization's most sensitive assets. The target's own security team cannot monitor an exposure it does not know is happening.

Putting both organizations' most valuable data into one shared environment, before any integration controls exist to govern it, makes that pooled environment the highest-value, least-protected moment of the entire deal. A consultant with legitimate data room access could download materials for competitive intelligence purposes, and with no established behavioral baseline for that individual, nothing about the download looks wrong. An Infosys white paper found that 52% of respondents uncovered a major, previously undisclosed cybersecurity risk only after the deal closed, a strong signal that whatever was incubating during due diligence went undetected the entire time.

The announcement window: how uncertainty drives the pre-departure exfiltration spike

Diagram: The Exfiltration Spike: When Employees Act. Visualizes: Visualize the dramatic concentration of insider data exfiltration risk around the departure window, using three concrete statistics from the article.

Once a deal becomes public, organizations face a real bind: investors and employees expect transparency, but restructuring and layoff plans usually have to stay confidential until decisions are final. That gap, between what employees fear and what they are actually told, is a recognized driver of exfiltration behavior in this window.

The numbers back it up. Cyberhaven's research found a 720% surge in data exfiltration activity in the 24 hours before a layoff compared to baseline, with suspicious activity sometimes starting as much as six months earlier. Separately, insiderisk.io's data identifies pre-departure exfiltration as the most common critical insider-risk pattern seen today: employees are roughly 69% more likely to take data in the window before they resign than at any other point in their tenure.

The channels involved are not exotic. Cyberhaven's research found personal cloud storage accounts for 22.7% of insider exfiltration incidents, removable media for 15.6%, and generative AI tools for 13.1%. Add bulk downloads from shared drives, documents emailed to a personal address under the cover story of a "safe copy," and the occasional print job, and the picture is one of ordinary tools used in an ordinary way, just at an unusual volume or an unusual hour.

That is exactly the difficulty of detecting the behavior. The access is authorized, the channel is familiar, and the behavior looks statistically normal for that employee even when the timing or volume is not. The announcement window also compresses several distinct populations into the same stretch of time: people who are genuinely leaving, people still waiting to find out if they have a job, and people who decide to hedge no matter what happens to them. No single behavioral profile built around role or department catches all three.

The Rippling v. Deel case from March 2025 shows how far this can go using nothing but sanctioned tools. According to Fasoo's reporting, exfiltration of customer lists, pricing details, and competitive intelligence went undetected for four months, carried out through Slack, Salesforce, and Google Drive, tools every employee at the company had legitimate reason to use every day.

The integration phase: identity debt, inherited infrastructure, and the attacker's bridge

Integration merges two separate identity perimeters, two sets of access controls, and two data environments, usually under heavy pressure to hit a "Day 1 connectivity" deadline that has nothing to do with security readiness. This Day 1 bridge is a route dormant malware can travel across into the acquiring organization before anyone has finished vetting the target's systems. Private equity deals carry an added wrinkle: portfolio companies often run siloed IT environments, so each one can be sitting on its own unmonitored vulnerabilities that nobody outside that specific company has ever looked at.

Identity debt compounds fast in this phase. Both organizations bring their own orphaned service accounts, leftover contractor credentials, and zombie accounts into the merger, and combining two messy identity environments without auditing either one first roughly doubles the dormant access surface overnight. The sharpest version of this risk is the hidden trust relationships the acquirer inherits without knowing they exist.

PwC data cited in Cybri's research found that 80% of global dealmakers uncovered cybersecurity issues in at least a quarter of their M&A targets over the past two years, and Infosys's 52% figure on post-closing discoveries fits the same pattern: the issues were there all along, just invisible until the systems were finally combined.

ReliaQuest's 2024 incident data gives this some texture. In July 2024, an employee at an industrial-sector company created an email forwarding rule to an external domain shortly after an acquisition closed, a move that triggered exfiltration detection only because someone happened to be watching for it. In August 2024, a healthcare organization found unauthorized access and data exfiltration coming from a legacy server inherited from a recently acquired company; the server had never been fitted with standard SentinelOne agents or logging, so the activity went unnoticed for a stretch before anyone caught it. Cybri's research describes a similar case where a buyer's security team, after close, found dozens of unmanaged cloud accounts in active use by developers at the acquired firm, none running MFA or logging, forcing an urgent remediation effort that set back the product integration timeline.

Cultural friction piles on top of the technical mess. Employees from the acquired company, still working under different norms, tools, and policies, will behave in ways that look anomalous to the acquirer's monitoring systems even when nothing malicious is happening. That noise makes the signal that actually matters harder to spot, not easier.

How External Threat Actors Exploit the M&A Window From Inside

Threat actors deliberately exploit the distraction caused by M&A activity. Research into cybercriminal forums has found threat actors explicitly discussing targeting companies mid-deal, on the assumption that a security team's attention is elsewhere and dwell time will stretch out as a result.

Flashpoint's 2025 data puts a number on how active insider recruitment has become: 91,321 instances of insider recruiting, advertising, and related discussion tracked across the year, averaging roughly 1,162 posts a month, with Telegram remaining one of the most active channels for this kind of activity. Telecommunications was among the most prominently targeted industries in that data.

The logic driving this is straightforward and cold: recruiting one willing or pressured insider to walk past a multimillion-dollar security stack costs an attacker less, and takes less time, than building a technical exploit to go around it. M&A hands that logic a ready-made population: employees who are financially anxious, aware of exactly which data is valuable, and in some cases resentful about how the deal is unfolding for them personally. That is precisely the profile external recruiters look for.

Two cases show how far this goes when it works. In the Coinbase incident from May 2025, attackers bribed customer support agents to exfiltrate data on 69,461 users, then demanded a $20 million ransom. Coinbase refused to pay and instead offered its own $20 million reward for information leading to the attackers. Separately, Reporting on the Medusa ransomware group describes an approach to a BBC employee in 2025, offering 15% of any ransom payment in exchange for network access, a direct illustration of organized groups applying financial pressure to individual employees rather than relying on technical intrusion alone.

For an acquirer, the target's employees come along with the deal, including anyone who may already have been approached, pressured, or compromised before the acquisition ever closed. No org chart shows that history.

Why standard controls fail across every M&A phase

Looking across all three phases shows the same failure mode repeating with different details each time. Access is authorized. The channel is familiar. Behavior is statistically normal for the individual involved, even when it is not normal for the moment. Identity environments are too incomplete to build an accurate baseline from.

Rule-based DLP hits a specific wall here. The data that matters most in M&A, valuation models, IP inventories, strategic roadmaps, is valuable because of what it means to the business, not because it matches a known format. A system built to catch classified data formats does not catch data whose sensitivity is entirely contextual.

Behavioral baselines carry their own version of the problem. They assume a stable organization to measure against, and M&A destroys that stability on every dimension at once: roles change, access changes, systems change, and the culture itself shifts underneath everyone. Defining "normal" becomes close to impossible exactly when it matters most.

The identity perimeter compounds all of it. Real detection depends on visibility into accounts that were never fully inventoried to begin with, on both sides of the deal, and BeyondTrust's point about hidden trust relationships lands hardest here: the real exposure is the access the acquirer does not even know it inherited. Meanwhile alert volume spikes across every monitoring surface during integration. The Ponemon and DTEX report found the average organization logged 25 insider-related incidents in 2025, up from 23 the year before, with an average containment window of 67 days. In a normal year, that is a resourcing problem. In an M&A year, every one of those 67 days carries direct implications for deal value.

Treating insider risk in M&A as a retrospective checklist item means nobody builds monitoring around the deal's actual timeline, and the exposure sits there until someone finds it after close. What the moment calls for instead is a way of watching that reads content, destination, identity, role, and behavior together, tracked across the full arc of the deal.

A phase-by-phase framework for insider risk controls in M&A

Pre-announcement calls for narrow but deliberate monitoring: watch the small population that already knows the deal is coming, before external advisors even get brought in. Crown-jewel data, valuation models, IP inventories, strategic roadmaps, needs to be treated as maximally sensitive regardless of whether it carries a formal label, so detection has to run on content and context rather than a classification tag nobody applied. Access pattern shifts among executives and senior staff, especially anything that looks like early positioning ahead of a deal nobody is supposed to know about yet, deserve a second look rather than a shrug.

Due diligence needs controls built around the data room itself: time-bound access tied to specific individuals, logging granular enough to catch a bulk download from a third-party advisor, and enough scrutiny on external participants that "legitimate access" does not quietly turn into "unmonitored access." The target company's security team needs a way to flag unusual activity even when most of the workforce has no idea a sale is underway.

Because volume and timing matter more here than whether the channel itself is sanctioned, departure-adjacent behavior needs to be tracked as its own category, separate from ordinary policy violations. Personal cloud uploads, bulk drive downloads, and generative AI tool use all deserve tighter scrutiny during this specific stretch, since the incentive to misuse them just changed even though the tools did not.

Integration needs an identity audit that treats both organizations' orphaned accounts, contractor credentials, and zombie accounts as one combined risk surface, not two separate cleanup projects to get to eventually. Legacy systems inherited from the acquired company need logging and endpoint coverage before they are trusted. And cultural friction between the two workforces has to be factored into monitoring design from the outset, so unfamiliar-but-benign behavior does not drown out the signal that actually deserves attention.

None of this is exotic. It comes down to matching controls to the specific conditions of each phase instead of running one steady-state insider risk model against a process that changes shape every few weeks. At current deal volumes, that mismatch is the default state most security teams are working under, and it is a solvable one, not an inherent cost of doing the deal.

Sources

  1. insaonline.org
  2. Mergers and Acquisitions — Reviewing 2025 and Looking Ahead to 2026
  3. The profile of M&A in 2026 | Barclays Investment Bank
  4. reliaquest.com
  5. flashpoint.io
  6. swif.ai
  7. en.fasoo.ai
  8. The Hidden Cybersecurity Risks of M&A
Filed underInsider Risk

More in Insider Risk