Imagine you are responsible for security in a merger of two organizations. How do you keep the lights on, the identities clean, and ultimately the adversaries out, while two different worlds are being stitched together into one? Hello and welcome to another episode of the CISO Perspective. I'm Berthold Kerl, CEO of KuppingerCole, a leading analyst firm based in Europe and focused on identity and cybersecurity. In this series, I speak to leading security executives about how they think, how they lead, and how they deal with decisions that shape cybersecurity today.
Today, we are talking about one of the most underestimated security challenges in business life, mergers and acquisitions. M&A processes are typically assessed from a financial and strategic angle.
Synergies, market position, growth potential, and things. Security often comes in late, if at all. But for anyone who has ever sat on the security side of the integration, the picture looks very different. Unknown systems, legacy infrastructure, mismatched identities, double amount of tools, and an attack surface that has suddenly exploded, often before a new organization has even settled in. I am very pleased to welcome today's guest, who knows this territory extremely well, not from theory, but from practice.
Max Killinger is CIO of the Hoffman Group, one of Europe's leading suppliers of quality tools and industrial supplies. While he is responsible for IT mainly, he is also accountable to ensure security, which is itself a statement about how closely IT and security leadership need to be aligned.
Max, thank you for joining me in this episode of the CISO Perspective. Great to have you here.
Thank you, Berthold. This is really a pleasure for me, because this is a topic very interesting. To be precise, my role at Hoffman as a CIO has just gone away, but I'm going to another company. It will be a very interesting discussion with you. Looking forward.
Yeah, Max. But before we get into the core questions, I'd like you to briefly set the scene for our audience. I know the Hoffman Group has gone through significant M&A activities in the recent years. Could you give us a brief understanding about where did you get your experience from, so that our viewers understand the context? So basically, I'm doing IT since some 20, 30 years now, and my first experience began with Infineon and with Siemens and with Kimonda and with companies which were doing large and even small M&As. The difference is very clear.
In the recent year, nine years now at Hoffman, and just end of 2021, we have been acquired from the SFS Group, which is a very successful and cool company from Switzerland doing fasting products. It's more on the production side. Hoffman is more on the B2B sales side. This acquirement in the first two years was like we learned from each other. So two large IT organizations, we learn from each other, we have a lot of synergies. And since the market changed a bit in the last years, I do not need to talk about this, the company decided to start an integration.
So since end of last year, a group CEO is in place, and we are bringing these two organizations together. On one side, this is an organizational part, on the other side, we have two large infrastructure stacks and they are completely developed in a way. They are good as they are, but to bring them together, you have many, many challenges. And that's where we will talk about what we are doing. We are not done yet in the middle, but we have taken some decisions at least.
The first, let's say, hard steps are done. We will have some more in the future, then without me.
But yeah, let's go ahead with the questions. All right. So let's get started. As I already mentioned, a merger is usually assessed from a business perspective. Security is not thought of at most, or at least not in the early phase. At what point should a CISO be involved, in your opinion, in an M&A process? And what happens if this happens too late? One sentence about CISO. I hired CISO in 2017, when I started, so CISO and me, we are kind of the greatest friends and the greatest challengers in both. And this is how we made it the last nine years.
If you do an M&A, you're looking on the risks you buy. You're not only looking on the chances.
And yeah, what should I say, that the security of cyber risk is one of today's largest risks. You can see it in all the lists of CEOs, headaches and whatever. This is really it. And therefore, you should have a close look in the due diligence on what you buy. Because is this a company which is at fire regarding cyber security? Or is it a company which is well prepared and well protected? And that's where the CISO comes in and has to at least assess kind of these risks they buy with that company.
Because it takes definitely some point in the final decision to buy the company in a way that will not prohibit the buy of the company, but it will at least have some discussion at the end to take the right steps. So that's why it should be there. And luckily, in the recent all M&As, this company and the other companies I was in, they were really aware of this and always the CISO or also the IT experts were in the due diligence early enough. So leveraging your experience.
So when you assess a new organization from a security perspective, what do you look at first and what are the warning signs that immediately raise alarm bells? When you buy a company, you buy a value. The value is, and you said it, it's mostly measured by financials, but the value can kind of disappear when the company is hacked tomorrow. So when the company is in the shape that it is well protected, the value stays. If there is any reason why I would just say there is a risk that it is hacked tomorrow after the final phase of the acquirement is done, then the value can vanish.
So that's the point we have to look at. And what is what I look for? And that is the IT organization. So we have a very long list of assessment questions and criteria, but the IT organization and how they protect, do they have an assessment report or recent? If they have, great, because then you can look into it. It's not the most value, but it at least gives you some picture about how is the tech surface, what do they have found there as hard facts, which can be hacked and so on. So this is where I look for.
And the second I look for is how this company is aware of that it has to be protected because some companies still are not so aware. They think I'm not the one, the other will be. But if this happens, this is a cultural thing. It's much more dangerous because then most likely the measurements are not there. For our case now, it's the company acquired Hoffman. It was a very interesting due diligence. I was on the other side of that metal, but for some other M&As running, it's always the same. I look for these risks and then you put up your hand and say, there's a red flag and to talk about it.
Okay. Yeah, so we just discussed what to look first or to pay attention most. In the opposite, what has been your biggest, oh no moment in an integration so far?
Yeah, honestly, they were never so large because in every case, every company develops. But what I, let's say, if companies are still extremely on-prem and if they do not have their identity management practice in a good shape, like synchronizing the on-prem world with the intro world, with whatever they have, Azure, for example, and intro and Microsoft. If this is not in a good shape, well, it makes it a bit risky.
I don't like that if this happens, but if you have it, you take it and there are reasons why this is there because budget restrictions or whatever, and then you have to make something out of it. As you know, we at Copenhagen Coase see identity always as a central topic in cybersecurity and in M&A scenarios, where two organizations grow together, you typically have different directories, role models, and access rights. Would you also agree that the identity plays a central role in an M&A scenario?
Yes, definitely. I'm totally with you and we have talked about this for months before and why is it, in our case, the most difficult question in the beginning is, which tenant stays and which goes, which active directory stays and which goes, where do you migrate in and where do you migrate out? And what do you do with the, let's say, not only user identity, but also the identity objects, but also the machine objects? And how do you make sure that access, like authentication options, are really permanently, whatever you do, they must be in place. They must stay.
You cannot open it and just change it for a while. This has to be in place. And therefore, yes, definitely. Identity management is one of the central triggers with decisions. When you take these decisions, after these decisions, you can go ahead. Many things depend on that and then you can do more. So we have many dependencies in this. We took some decisions on, not to go into details, but we took the decision, which tenant stays. This was really extremely important. And this is also important for many other IT areas surrounding this discussion, not only infrastructure.
So yes, I think this is all said about this, yeah. Perhaps, in your view, what are the biggest mistakes organizations make or can make when they try to consolidate identities?
Yeah, I guess it's not far enough thought if you just do user migrations. User migration is not it. It goes far beyond of that. It goes even completely up, depending on a few points, down to the workplace. Workplace and authentication and how secure all the other things are. This is far more than just user migration or just doing that. Even if you look on these architectures today, zero trust is not just a wish. Zero trust for me, it's a basic, you have to have no discussion. Zero trust is there.
And then you have for identity migration or for integration, one organization which is really completely zero trust and the other not. Then you have some homework because you join two organizations which have a completely different level of security or maturity for doing all these protection for the company. So this is, I guess, sometimes underestimated. Experts do not, but companies maybe want to save money or whatever.
Yeah, so identity is important. I think we both agree to that, but of course it is not just about identities. So when in a merger situation, when two organizations come together, overnight the two landscape is doubling. Each organization brings its own solutions, often all the same problems. So what is your advice to deal with such a situation?
Yeah, before that, that's the headache you have even without any M&As because the companies buy software in the past, the software comes back to IT, IT has to manage the software because license costs and so on, and we have it already. So one of the tasks for the last nine years was to go down from nearly 3,000 software products in a 3,000 user company to half of it. And now come two stacks, these two product areas with hopefully some of them overlapping, but in many cases not overlapping. We have that.
And even if you then focus on the protection software, because this is an architecture, both stacks have different software products to protect, like CrowdStrike, for example. If the one has CrowdStrike and the other has others, these software products match some security protection requirements and they must be formed and they must be after that, and to bring these together and have a new stack, which is making sense for the new, let's say, infrastructure you get, this is also something you have to do. It's a lot of work to do that, definitely.
Security is not only about technology and work is also not only about technology, it's also about culture. So when two organizations come together, you are also faced with different security cultures coming from two different teams. So what's your experience in that space? You see me smiling because this is one of the most relevant roadblocks to go ahead. And even my CISO and some other experts will smile if they see that, because this was a reason for that it lasted a bit longer than we wanted to last it. Because what is the reason behind?
You have two stacks, you have people which are knowledgeable, which are really good IT experts, and on both sides, they know their environment. On both sides, they would pretend that this is the best environment you can get and that we are secure and we are safe.
In fact, on a pure technical level, they are different, definitely, and you cannot compare. And if you are on the one side, they know the one side and would say it's best on the other side too. How do you bring this culture from defending your own babies to both our babies? And that's the target behind. Try to change, that's a change management problem, try to change this protection situation from the experts knowing and loving their environment, how they did it, and it's all good they did. You never would say that the one or the other is the best or the better.
And how you bring them to that situation, it's all mine. So everybody should think that's all mine. We should take care about everything together. We are not on one or the other side.
And yeah, honestly, this was one of the challenges we had for the last month. And since now, end of February, March, we just got it in a way that now it's working for the complete infrastructure for the future, for the vision. We created a vision like we want to have one structure, one platform, one identity, every user should have only one account and not one account in the others, in one side of this infrastructure and another, because you want to access something else. So this vision and all we did now led to a new situation and now it's going ahead very well. Yeah.
I think the other perspective I'd like to open up is when the integration takes place. So I think the integration itself is a very critical phase and attackers know this, they actively exploit it. And obviously, it's your job as a security responsible person to be aware of that and protect the organization. So what do you need to do in order to avoid being attacked?
OK, it's quite hard to protect something you don't know. So know your assets, know both your assets, know all your assets, not assets, not only one, but also the other. So to know how and what you have to protect is one thing. And then the next thing, and this is we're working together with, from my point of view, really good, very good security company, we're not named companies yet. And there we are talking about attack surface and we do not have an assessment like just what things we have to fix.
It's more, it's an attack surface analysis. And this we did for both infrastructure stacks. So we know all the attack surface we have. And only by that we know when we pick one of the specific open things we have. Sometimes you know a new problem in the software and you exactly know when we fix this one, then we are safe.
And again, there can be 10 more, not a problem, but this one has to be fixed. And this is also important for the transition of when you do the migration, because when you're aware of that, you can take care about this. And in every time of the migration, every time of the integration activities, you have to make sure that, I said it already, that all the measures are still in place. The two factor must be in place and not made up and everything must work. This is a challenge, but we have very good engineers and architects and people and we will manage to do that. We'll be next year, by the way.
This is not for this year. Yeah. All right. So interesting. So we touched base on obviously the different technologies and tools that the companies bring with them, the different cultures, potentially. If the organizations come from different countries or regions, you often also have to deal with different regulatory requirements. How do you look at this problem?
Yeah, I have never worked in a non-multinational company. So every company I have worked in was in a way multinational and there are countries which are not so problem, but there are also countries and I look for direction Asia, Asia, China. They have to take care. But basically if you try to align with NIST or BSI standards or ISO norms, if you try to hook your security operation and organization and your protection, all these key standards, then you're at least on a major good path where you have everything. There are some specifics like TSACs for automotive.
You have to have some certifications for that, but if you do that, it's okay. And then you just have to take care about countries like China with a strong data protection law, because then you have to take care that whatever you change, this has to, let's say, stay to this protection level. Data has to stay in China, for example. Not yet. Different thing we can talk about. There's exactly about 10 minutes more, but we don't. So from my point of view, if you stay to standards, you're already well prepared and can make out the specifics.
So overall, when you look back at all the M&A processes you have supported, is there anything you would do fundamentally different from today's perspective? Or if you prefer, you can also answer the question the other way around.
What, in your view, is best practice, the number one thing you always have to or must do? If you have a standard of, let's say, assessment in due diligence, it's very helpful because you just pick this and then it's important to differentiate the size of the company you are assessing. Because if you have a very small company with 10 people, you don't need to assess their cybersecurity organization or something. There is none. You cannot.
But if on the other side is, let's say, a middle or a large company, you have to be very close or you can do a lot more and can look into it because the risks are higher, the financials you put in when you buy are higher, so you have to spend some more and basically every company is different. So you have to always adapt to what you're assessing. But it's also important, what you see is always good because you have to treat these companies always with respect. A company that is bought is kind of on a weak side, so they are assessed. That's not a good situation for them.
So do the talks with respect, do not judge them for something. They have reasons for where they have gone. And so from that point of view, I think this is always a process where you learn a lot, where the others learn a lot, and when you are done, the company is bought and will be your brother there. So you want to work with them together. Thank you for your insights so far. I think one could clearly see and hear that you are not only talking theory, but you're really talking out of practice. And I think that is exactly what everyone wants to hear. Thank you for that.
Now, before we close our conversation, I obviously would like to do our usual quick fire round. Quick fire round, that means I fire the questions and you should answer very briefly and spontaneously whatever comes to mind first.
All right, so let's start. AI is now writing code, analyzing logs, detecting threats. Does the human security analyst still have a future or are we training our own replacements?
Yeah, simple answer. AI will never take account for cyber risk. It will always be a human. So from that perspective, always a human will do the final decisions for that. And this will not go away. It will be very helpful. There will be many scenarios where it can be. And all of the attackers will be more efficient, but it will never. So if you ask young people if they should go in that direction, you can easily do. It will be different in a few years, but the job will still be there. That's very good to hear. So you mentioned CrowdStrike earlier.
So there was obviously this outage taking place in July 2024. What was the first thing that came to your mind when you heard about it? Very honest. The first thing was, good that Hoffman does not have CrowdStrike. This was the first thing. We are not a part of this, what happens all in the world. And this was the best thing. And the second thing was, yeah, CrowdStrike is a good product. And how could they do this? How could this happen? That never can happen.
Yeah, but it did. So more regulation and cybersecurity. Is this rather helpful or is this the unnecessary paperwork? It's enough. And it's good that it's there, but it's enough. Shouldn't be much more. NIST is good. NIST2 is very good.
Yeah, ISONORM is very good. And all on BSI, these basic security guidelines, they're also good.
But yeah, don't overrule it. So I know the next one is a challenge, but nevertheless, best security advice you ever received in one sentence? Three words. Protect your identity. Full stop. I love that. Okay. Especially because you are a CIO and a security expert at the same time. What is the one moment when those two roles, so CIO and CSO, argued with each other?
Yeah, no, the CSO is always the Mr. No, no. He wants to protect, the CIO has to fulfill, or all the IT generally has to fulfill business requirements, has to make it easy for a business to make their business, and in some discussions, this can definitely have some hard discussions on do we take the risk or not, but it's a very easy thing to solve that. And there's a risk and the CSO don't want to take the risk, he writes a risk letter. And if someone in business signs this, he's out, he's okay. You can solve this in any case. And we did this a lot and this is working really good.
So we do have obviously young colleagues in the audience who are just starting their career in cybersecurity. If you could give them one piece of advice, so what would it be? This is a very difficult question because coming from an age where IT was in the child's shoes, I don't know if this is the right word, but you learn a lot. And by learning this, you have a lot of experience inside and you get a feeling in your guts about security.
If you want to start, the most important thing is be really interested, be behind it, look for what happened in the past a bit, but look also for the technology and everything. So if this is really something you want, then you will get it. And it is a really cool job to go for that.
Marc, thank you so much for your insights so far. What I take away from this conversation is that an M&A integration from a security perspective is certainly not a checklist exercise only. You have to look at the technology, at the culture, regulation, the people, management, etc. And you have to ensure that nothing happens in a moment when everything around us, around you, is changing, is in flux. Any last words from your end?
Yeah, thank you. It was a really interesting and challenging questions game with you together.
Again, if you like, separate topic, separate time and good luck for everybody with cybersecurity, hearing what we have here. Marc, thank you for being with us today. And to everyone watching, thank you very much to watch this third episode. We will be back soon with the next conversation. Until then, take care and stay resilient.