Your Competitor’s Spyglass: Data Risks During a Divestiture

Data protection and security protocols have become more robust in the last two decades. This has been driven both by increasing incidents of data breaches – statutorily acts such as the EU General Data Protection Regulation (GDPR), the Gramm-Leach- Bliley Act, Health Information Technology for Economic and Clinical Health (HITEVH) Act, Health Insurance Portability and Accountability Act (HIPAA), and the Fair and Accurate Credit Transactions Act – and by the Payment Card Industry Security Standard, to name just a few drivers. In general, most entities have implemented strong safeguards to ensure that issues such as inadvertently sharing identifying information with third parties and the existence of sensitive data (credit/procurement card numbers, tax IDs, social security numbers, vendor/customer bank account numbers, etc.) for their current and active data are addressed.

Though these measures have become more commonplace, the threat of cybercrime and data breaches is unfortunately still on the rise. Cybesecurity Ventures, a cybercrime magazine, estimates that cybercrime will cost approximately $10.5 trillion per year on average by 2025, up from $6 trillion in 2021. IBM estimates the average cost of a data breach for a company is $4.24 million per incident. This figure covers detection, containment, revenue loss and equipment damage, but there are also unspecified irreversible losses to the company’s reputation and goodwill. Even more worrisome during merger, acquisition, or divestiture activity is loss of intellectual property, the impact of operational disruption, and the costs of regulatory compliance. The below figure from Deloitte illustrates typical points in the M&A lifecycle that are dependent on data transfer, putting the involved companies at increased risk of cybersecurity threats:

 

These threats are more likely to arise when a company has legacy or inactive ERP data. Prior to the enhanced security protocols of the last two decades, it was common practice to put sensitive data into an ERP system’s unsecured fields, such as memo and descriptive fields, or in otherwise re-purposed fields. As a result, much legacy data does not meet privacy and security standards. This risk can be managed without having the expense of a hygienic data purge when the legacy data is buttressed by access controls. The biggest risk is when a third party is given access to or possession of either a portion or clone of an existing ERP instance. This most commonly occurs in divestiture or partial divestiture situations.

In fact, it’s been speculated that undergoing complicated large-scale business changes (like a divestiture, an acquisition or a merger) opens an enterprise up as an easier target for a security breach because of infrastructure changes and limited resource allocation. This is an especially vulnerable time because if a parent company creating a clone for their acquired company still retains the data of a (now sold) child company and suffers a theft or data breach, not only do they have the downfall of their own reputation, but they could be liable for damages to the child for the compromise (or vice versa), compounding the threat if that company in question is flipped again and purchased by another entity. If they have data belonging to the parent company, they are at risk if any of the companies has a breach that involves the parent company’s data. As companies are repeatedly bought and sold, a data breach can be very costly for both the acquirer (parent) and the acquired (child) company. Over time, the original source of the data is not clear, and the breach can have untold impacts and ever-increasing costs. The bottom line is that all parties will bear the burden, monetary expense of remediation, and opportunity cost of a damaged reputation.

There has been an uptick in the handling of divestiture and acquisitions by cloning the instance in question, masking the data and handing it off as part of the sale – but there are inherent risks for both the buyer and the seller when using a clone or masking solution for a divestiture. Companies who are creating a clone for their acquired company still have data belonging to the child company, and therefore, they would not only have the reputation of their own customers, but they will likely have to pay the child company compensation for breach of their data. The reality is that an experienced hacker can undertake an unmasking initiative, access that data by finding related data, or querying at the data base level, and open vulnerabilities for both an internal and external data breach.

With the exceptional dangers involved, it begs the question: why have these processes become commonplace? The seller risks inadvertently sharing trade-secrets or competitive advantage via sensitive information left in the database, and the buyer undertakes the complication of carrying the masked data that it does not own in their system, causing delays and increasing infrastructure costs (i.e. a larger footprint, additional license fees, added expense to manually segregate the data for reporting or compliance, etc.).

This risk cannot be understated. A single inadvertent unauthorized disclosure of private customer or vendor information could result in large penalties, sometimes into the millions of dollars. If the clone instance is provided to a competitor in a partial divestiture, added to this risk is the possibility of damage resulting from inadvertent disclosure of the non-divested business’ proprietary strategic information, such as vendor and customer credit lines, discounts, customer and vendor contractual details, etc.

Finally, to magnify these risks, the threat of litigation losses respective of inappropriate data disclosure can dwarf the costs of other risks.

So what is an appropriate risk management strategy to adopt during a divestiture? An entity has three choices: minimize the risk, accept the risk, or ignore the risk.

Minimizing  the Risk:
This strategy involves a variety of steps, including non-disclosure agreements with third-parties, contractual obligation, and other due diligence around the risks. However, the ideal way to minimize the risk is to purge old/legacy non-divestiture related data from the clone instance provided to the divested or acquired entity.

Accepting the Risk:
Accepting the risk can be an effective risk mitigation strategy. However, to accept the risk, entity management must have a relatively accurate estimate of the risky data exposure accompanied by a what- could-go-wrong quantification of the potential risk respective losses.

Barring a means to quantify the risks associated with the divested clone instance’s legacy and non- divested entity related data, entity management is not accepting the risk. Instead, by default, entity management has chosen the riskiest approach – Ignoring the Risk.

Ignoring the Risk:
If an entity’s management cannot be provided with a reasonable estimate of quantified risks associated with the divested clone instance’s legacy and non-divested entity related data, then barring minimizing the risk by purging unrelated and legacy ERP information, management has chosen to ignore the risks. This is the worst possible strategy, because it leaves the entity open to the risk of being deemed negligent, which can significantly exacerbate litigation, business and other risks

In conclusion, during the rapid transition of a divestiture, it is critical to ensure that due attention is given to the risk of legacy, inactive, and unrelated to the divestiture ERP data. The best strategies are to either minimize or accept the risk and avoid the unacceptable act of ignoring the risk.

347 thoughts on “Your Competitor’s Spyglass: Data Risks During a Divestiture

  1. Peterdex says:

    kamagra en ligne [url=https://kamagraprix.shop/#]Kamagra pharmacie en ligne[/url] kamagra gel

  2. Peterdex says:

    Pharmacie sans ordonnance [url=https://pharmafst.com/#]pharmacie en ligne fiable[/url] п»їpharmacie en ligne france pharmafst.shop

  3. Peterdex says:

    cialis sans ordonnance [url=https://tadalmed.shop/#]Cialis sans ordonnance 24h[/url] Acheter Cialis tadalmed.com

  4. Peterdex says:

    Achat Cialis en ligne fiable [url=http://tadalmed.com/#]Tadalafil sans ordonnance en ligne[/url] Acheter Cialis 20 mg pas cher tadalmed.com

  5. Peterdex says:

    Kamagra Commander maintenant [url=http://kamagraprix.com/#]kamagra pas cher[/url] kamagra oral jelly

  6. Peterdex says:

    Kamagra Oral Jelly pas cher [url=https://kamagraprix.shop/#]kamagra 100mg prix[/url] kamagra oral jelly

  7. Peterdex says:

    Pharmacie en ligne livraison Europe [url=https://pharmafst.shop/#]trouver un mГ©dicament en pharmacie[/url] pharmacie en ligne pharmafst.shop

  8. MichaelFuB says:

    RxExpressMexico [url=https://rxexpressmexico.com/#]mexico pharmacies prescription drugs[/url] Rx Express Mexico

  9. MichaelFuB says:

    medicine courier from India to USA [url=https://medicinefromindia.shop/#]medicine courier from India to USA[/url] MedicineFromIndia

  10. MichaelFuB says:

    indian pharmacy online shopping [url=https://medicinefromindia.com/#]Medicine From India[/url] indian pharmacy online shopping

  11. MichaelFuB says:

    online pharmacy canada [url=http://expressrxcanada.com/#]Express Rx Canada[/url] reputable canadian online pharmacy

  12. MichaelFuB says:

    mexican online pharmacy [url=https://rxexpressmexico.shop/#]best online pharmacies in mexico[/url] mexican online pharmacy

  13. MichaelFuB says:

    certified canadian pharmacy [url=http://expressrxcanada.com/#]canadian pharmacies compare[/url] canadian pharmacy in canada

  14. MichaelFuB says:

    Rx Express Mexico [url=http://rxexpressmexico.com/#]mexico drug stores pharmacies[/url] mexico pharmacies prescription drugs

  15. Richardanock says:

    вавада [url=https://vavadavhod.tech/#]вавада казино[/url] vavada casino

  16. Richardanock says:

    вавада официальный сайт [url=http://vavadavhod.tech/#]вавада[/url] вавада казино

  17. Richardanock says:

    vavada вход [url=http://vavadavhod.tech/#]вавада казино[/url] вавада казино

  18. Richardanock says:

    пин ап зеркало [url=http://pinuprus.pro/#]пин ап вход[/url] pin up вход

  19. Richardanock says:

    pin up вход [url=http://pinuprus.pro/#]pin up вход[/url] пин ап вход

  20. Richardanock says:

    вавада казино [url=http://vavadavhod.tech/#]vavada casino[/url] vavada casino

  21. Richardanock says:

    пин ап казино [url=http://pinuprus.pro/#]пинап казино[/url] пинап казино

  22. Richardanock says:

    vavada casino [url=https://vavadavhod.tech/#]вавада зеркало[/url] вавада казино

  23. Richardanock says:

    пин ап зеркало [url=http://pinuprus.pro/#]пин ап вход[/url] пин ап вход

  24. Richardanock says:

    вавада официальный сайт [url=http://vavadavhod.tech/#]вавада официальный сайт[/url] вавада

  25. Richardanock says:

    пин ап казино официальный сайт [url=https://pinuprus.pro/#]пин ап зеркало[/url] пинап казино

  26. Richardanock says:

    пин ап зеркало [url=http://pinuprus.pro/#]пинап казино[/url] pin up вход

  27. Richardanock says:

    pin up вход [url=http://pinuprus.pro/#]pin up вход[/url] пинап казино

  28. Richardanock says:

    vavada casino [url=https://vavadavhod.tech/#]вавада официальный сайт[/url] вавада официальный сайт

  29. Richardanock says:

    пин ап зеркало [url=https://pinuprus.pro/#]пинап казино[/url] пин ап казино

  30. Richardanock says:

    вавада официальный сайт [url=http://vavadavhod.tech/#]vavada[/url] вавада официальный сайт

  31. Richardanock says:

    пин ап казино официальный сайт [url=http://pinuprus.pro/#]пин ап казино[/url] пинап казино

  32. Richardanock says:

    пин ап вход [url=https://pinuprus.pro/#]пин ап зеркало[/url] пинап казино

  33. Thomassar says:

    Тележка с подъемной платформой предназначена для работы в складских помещениях, производственных предприятий для транспортировки коробок, инструментов и других грузов. Способны поднимать и перемещать грузы весом до 0,5т на высоту до 1500мм.
    Высота подъёма: 450-1500 мм.
    В качестве защиты от раздавливания подъемный стол оснащен кромкой безопасности, расположенной под наружными краями платформы. При активации она прекращает опускание. Для продолжения опускания платформа должна быть поднята для сброса защиты.
    Получить коммерческое предложение:
    Надежный гидроцилиндр обеспечивает плавный подъем.
    Опыт разработки и производства гидравлических подъемных столов более 50 лет!

  34. Richardanock says:

    вавада официальный сайт [url=https://vavadavhod.tech/#]вавада казино[/url] вавада официальный сайт

  35. Richardanock says:

    vavada вход [url=http://vavadavhod.tech/#]вавада официальный сайт[/url] вавада официальный сайт

  36. Richardanock says:

    вавада зеркало [url=http://vavadavhod.tech/#]вавада официальный сайт[/url] vavada casino

  37. Lorenzoalera says:

    generic tadalafil [url=http://zipgenericmd.com/#]affordable ED medication[/url] cheap Cialis online

  38. Lorenzoalera says:

    verified Modafinil vendors [url=https://modafinilmd.store/#]buy modafinil online[/url] verified Modafinil vendors

  39. Lorenzoalera says:

    discreet shipping [url=http://maxviagramd.com/#]fast Viagra delivery[/url] best price for Viagra

  40. Lorenzoalera says:

    doctor-reviewed advice [url=https://modafinilmd.store/#]modafinil pharmacy[/url] verified Modafinil vendors

  41. Lorenzoalera says:

    order Cialis online no prescription [url=https://zipgenericmd.shop/#]secure checkout ED drugs[/url] online Cialis pharmacy

  42. Lorenzoalera says:

    cheap Viagra online [url=http://maxviagramd.com/#]fast Viagra delivery[/url] legit Viagra online

  43. Lorenzoalera says:

    secure checkout ED drugs [url=https://zipgenericmd.com/#]secure checkout ED drugs[/url] discreet shipping ED pills

  44. Lorenzoalera says:

    same-day Viagra shipping [url=https://maxviagramd.shop/#]generic sildenafil 100mg[/url] cheap Viagra online

  45. Lorenzoalera says:

    affordable ED medication [url=http://zipgenericmd.com/#]online Cialis pharmacy[/url] cheap Cialis online

  46. Lorenzoalera says:

    order Cialis online no prescription [url=https://zipgenericmd.shop/#]affordable ED medication[/url] reliable online pharmacy Cialis

  47. Lorenzoalera says:

    secure checkout Viagra [url=http://maxviagramd.com/#]legit Viagra online[/url] discreet shipping

  48. Matthewvek says:

    amoxicillin 500mg buy online uk [url=https://amohealthcare.store/#]how to get amoxicillin[/url] Amo Health Care

  49. Matthewvek says:

    generic clomid without dr prescription [url=http://clomhealth.com/#]Clom Health[/url] where to buy cheap clomid online

  50. Matthewvek says:

    amoxicillin 250 mg capsule [url=https://amohealthcare.store/#]Amo Health Care[/url] Amo Health Care

  51. Matthewvek says:

    Amo Health Care [url=https://amohealthcare.store/#]can you buy amoxicillin over the counter in canada[/url] Amo Health Care

  52. Matthewvek says:

    prednisone over the counter uk [url=https://prednihealth.com/#]PredniHealth[/url] prednisone 4mg tab

  53. Matthewvek says:

    where to buy amoxicillin pharmacy [url=https://amohealthcare.store/#]order amoxicillin 500mg[/url] Amo Health Care

Comments are closed.

Securely Divesting ERP Data

ERP systems contain sensitive information from all parts of an organization. Separating this data cleanly can be complex and risky. Deciding what information to provide to the divested entity and...Read More