The Challenge
The client is a publicly listed company whose board had begun asking questions its security function could not answer with evidence. The pressure was partly governance and partly regulatory: public companies now carry explicit obligations to disclose material cyber incidents promptly and to describe their risk management processes, and both require actually knowing what the posture is.
The company had grown through acquisition, which shaped the problem. Each acquired business brought its own infrastructure, its own identity systems and its own accumulated exposure, and integration had focused on commercial systems rather than security. Nobody held a complete picture of what the combined organization exposed to the internet.
Our Approach
StrikeCyber assessed the combined estate from the outside in, deliberately starting where an attacker would rather than where the documentation suggested.
- External attack surface discovery across every domain, brand and acquired entity, without relying on the company's asset inventory.
- External and internal penetration testing against the systems that discovery showed carried the most risk.
- Identity and Active Directory review across the combined environment, including the trust relationships created during integration.
The engagement was structured to produce two outputs: technical findings for the security team, and a clear, non-technical assessment of material risk for the board and its audit committee.
What We Found
- Substantial unknown external surface. Discovery identified a significant number of internet-facing systems absent from the asset inventory, most belonging to acquired entities, including several running unsupported software.
- Trust relationships as attack paths. Domain trusts established during integration allowed privilege in a smaller acquired environment to translate into privilege across the group.
- Inconsistent identity controls. Multi-factor authentication was enforced in the parent organization and applied unevenly across acquired businesses.
- Credentials exposed in public repositories. Code published by an acquired entity's development team contained working credentials for internal systems.
The Outcome
The company decommissioned the unsupported systems discovery had surfaced and brought the remainder into a single managed inventory, which was the change that most reduced exposure. Domain trusts were restructured so privilege could not traverse the group, and multi-factor authentication was standardized across every acquired environment. The exposed credentials were rotated and repository scanning was introduced.
The board received a written assessment of material risk before and after remediation, giving its audit committee a documented basis for the disclosure questions it had to answer. Security due diligence was added to the acquisition process, so the pattern does not repeat with the next transaction.
Why It Matters
Growth through acquisition is growth of attack surface, and it happens faster than integration. The combined organization is exposed the day the transaction closes, while the security work is scheduled for later. For a listed company, that gap now carries disclosure consequences as well as operational ones, because SEC rules expect both prompt reporting of material incidents and a credible account of how cyber risk is managed. To get a complete picture of what your organization exposes, get in touch.