The Day 1 plan in an acquisition

From close to controlled integration: access, monitoring and the controls that cannot wait.

Closing ends one negotiation and opens another, quieter one. The moment the deal completes, the acquirer inherits the target’s exposure: its credentials, its connections, its third-party access and whatever compromise was already present and undetected. Day 1 is not a ceremony. It is the moment risk changes owner.

A good Day 1 plan is written before close, not after. It defines what must be under control from the first day, what can wait for the following weeks, and who is accountable for each thing. The goal is not to integrate everything at once: it is to keep the first days from introducing risks worse than the ones you are trying to manage.

What must hold from day one

Before touching any system, you need clarity on three points: which critical assets and data are in scope, which connections already exist between target and acquirer, and who holds privileged access today. Without that map, every Day 1 action is in the dark.

The temptation is to connect the two networks immediately to show progress. That is the most expensive mistake. A hasty connection turns an incident contained within the target’s perimeter into one that crosses both companies.

You also need a clear list of decision-makers: who can authorise an emergency disconnection, who answers an out-of-hours alert, who keeps the relationship with the target during the transition. On Day 1, confusion over roles costs as much as a technical gap, and it is avoided only by settling it in advance.

Access: who gets in, with what

The first category of controls is identity. In the days after close, roles change, people leave, new managers arrive. It is when orphaned access multiplies: accounts of departed employees, shared service credentials, vendor access no one remembers granting.

The priority actions are concrete: inventory privileged accounts, enforce multi-factor authentication where it is missing on critical systems, revoke access that is no longer justified, and reset high-privilege credentials if there is any doubt about their confidentiality. None of this requires integrating the systems, and all of it reduces the attack surface immediately.

Monitoring before integration

You cannot defend what you cannot see. Before any technical merger, the acquirer must have visibility into the target’s logs and security events, at least on the systems that matter. In most deals this visibility is partial or absent at close.

Establishing minimal monitoring — endpoint telemetry, authentication logs, alerts on privileged actions — means you can tell normal activity from anomalous during the most delicate period. If a pre-existing compromise is dormant in the target, the first weeks under new ownership are when it is most likely to surface.

The controls that cannot wait

Some controls do not tolerate waiting for planned integration. Verifying that backups of critical systems exist, are recent and are restorable. Confirming that anti-ransomware defences are active on endpoints. Closing the most serious external exposures already known from diligence. And an agreed incident-response channel, so that if something happens on Day 1 it is clear who calls whom.

These controls share a trait: the cost of delaying them is asymmetric. Postponing them by a few weeks rarely saves anything, but it can cost a great deal if an incident arrives in the meantime.

It is worth writing this short list before close and assigning it to named people, with a deadline. A Day 1 plan that lists intentions without owners is a document; one that ties each action to a name and a date is a control. The difference shows the moment something goes wrong.

Controlled integration, not immediate merger

Real integration — unified networks, consolidated identity, rationalised tooling — is a path of months, and that is fine. The job of Day 1 is to buy time safely: contain the inherited risk, gain visibility and keep the two companies separate until you truly understand what you have acquired.

Controlled integration proceeds in phases, each with an entry criterion: you connect systems only after verifying that the side you are about to join does not bring a known problem with it.

The takeaway

Day 1 is when risk changes owner, not when integration begins. Agreeing before close on the access to secure, the minimum monitoring to enable and the controls that cannot wait turns a fragile moment into a managed one. Go slow on connections, fast on identity and visibility.

From reading to deciding

Turn this into a decision you can defend.

A confidential 30-minute conversation to apply it to your situation — or start from a practical resource.