The Acquired Company With a Flat Network

The deal completed on a Friday and the networks were connected on the Monday, because the finance team needed access to a shared file server and a site-to-site tunnel was the quickest answer. The acquired business ran a flat network, gave every user local administrator rights and had no endpoint detection. Six weeks later a ransomware crew that entered through their side encrypted servers in both organisations.

What the acquired estate looked like
A single broadcast domain covering offices and servers, with no separation between user machines and the systems holding data. Remote desktop published to the internet for a supplier who had needed it two years earlier. Local administrator rights for all staff, because an old application had required them. No central logging and a backup routine writing to a share on the same network. None of this was hidden. It simply had not been examined, because the diligence process had covered financials, contracts and customer lists rather than infrastructure. Nobody had asked to see a network diagram.
How one network became two
The intrusion started on the acquired side through the exposed remote desktop service and a weak password. From there the attacker moved laterally without resistance, gathered domain credentials and found the tunnel. The connection had been configured to permit any traffic between the two networks because narrowing it would have taken a change request nobody wanted to raise during an integration. Two weeks of convenience produced eleven days of outage. The NCSC’s guidance on preventing lateral movement describes exactly the controls that were missing, and the outcome shows why they matter.
“Assess the network before you connect it, not after. A week of testing during due diligence would have found the exposed remote access and the flat design, and the acquiring business could have connected through a restricted gateway instead of a permissive tunnel. That decision was made by people with no security input, at the point where security input was most valuable.”
William Fieldhouse, Director, Aardwolf Security Ltd
What the recovery involved
Eleven days of disruption across both businesses, restoration from backups that were partially encrypted on the acquired side, and a rebuild of the smaller company’s estate from scratch. Insurance covered part of it, after a claims process that ran for months. What insurance could not fix was the effect on the acquisition itself: the integration timetable slipped by six months and several key staff left during the disruption. The technical cost was significant and the commercial cost was larger.
How integration should be staged
Connect through a controlled boundary and open it gradually. Start with no connectivity, then permit only the specific services the business genuinely needs, through a firewall with rules that name source, destination and port. Require the acquired estate to reach an agreed baseline before wider access is granted, covering endpoint protection, patching, removal of local administrator rights and multi-factor authentication on remote access. Run an internal network assessment of the acquired environment early, along with an external network reviewof their internet-facing systems, since those are the two questions that decide how much of a hurry you should be in.
Frequently asked questions about acquisition security
These questions come up whenever an integration is being planned.
How long does technical due diligence take?
A useful assessment of a small estate takes a week and can run in parallel with commercial diligence. That is short enough to fit most deal timetables and long enough to find the problems that would otherwise become somebody’s first month in charge.
What if the deal has already completed?
Assess before connecting, even retrospectively. If a connection already exists, restrict it to specific services while the assessment runs rather than leaving a permissive tunnel in place for the duration.



