The 90-Day IT Integration Roadmap Post-Acquisition: Avoid the $200K Surprise

The 90-Day IT Integration Roadmap Post-Acquisition That Prevents the $200K Surprise

The deal closed. The press release went out. The synergy model says integration takes six months and costs roughly nothing beyond a line item marked “IT transition.”

Then week ten arrives.

A file server at the acquired company throws SMART errors under the new load. A compliance auditor sends a letter about obligations nobody flagged during diligence. Two MSPs are billing you for the same endpoint. Someone in the acquired org clicked a phishing link three weeks before close, and the attacker has been quietly moving through the network.

The bill for those four things, and I have seen it, comes in around $200,000 or more.

None of it was in the model.

All of it was preventable.

Why IT Integration Is Consistently Underbudgeted

Post-close, everyone is pointed at synergy. Consolidate GL systems, rationalize the sales stack, get one HRIS running before the next board meeting. Speed to synergy is the metric that shows up in the operating partner’s slide deck.

IT integration gets treated as plumbing. It is assumed to happen in the background while the real work continues.

Here is the reality after 40 years watching this play out.

IT is not the plumbing. IT is the load-bearing structure everything else runs on. Payroll, invoicing, CRM, ERP, security, compliance, communication. When integration is mishandled in the first 90 days, every other synergy target slips, because the foundation those synergies depend on was never built.

The four surprises below are what “mishandled” looks like on the P&L.

The Four Post-Close IT Surprises That Cost Acquirers Six Figures

1. Emergency Infrastructure Replacement

Small and mid-sized businesses run older equipment than the diligence deck suggests. A five-year-old file server humming along under 30 users can look completely healthy on a walkthrough.

Then close happens. Headcount consolidates. The acquired team gets pulled onto shared systems. Load doubles.

The disk array that was fine at 40% utilization fails at 85%. The switch that never dropped a packet at 200 Mbps starts dropping them at 600. The firewall that was rated for the old employee count cannot handle the new VPN concurrency.

I have watched acquirers spend thousands in emergency hardware replacement in the first 60 days post-close, with expedited shipping, because nobody did the load-forward analysis.

The fix is a hardware lifecycle audit inside the first two weeks. Every switch, firewall, server, and access point gets a date stamp and a load rating against projected post-integration usage. Anything within 18 months of end-of-life at 70%+ projected load gets ordered on a normal procurement cycle. Not emergency freight.

2. Compliance Remediation

When you buy a company, you buy its regulatory obligations. All of them.

If the acquired entity handled payment card data, PCI-DSS came with the deal. If they had a single healthcare client, HIPAA came with the deal. If they operated in New York, the SHIELD Act came with the deal. If they served defense contractors, CMMC came with the deal.

Diligence teams often scope the compliance review to what the buyer already handles. That leaves everything the seller was subject to sitting in a blind spot.

The auditor’s letter tends to arrive somewhere between day 40 and day 90 post-close. By then the clock has already started on remediation windows the buyer did not know existed.

Real cost: $30,000 to $150,000 depending on framework and how far the acquired environment had drifted from its stated posture. And that is the cost to get compliant. It does not include the fine if a regulator gets there first.

The fix is a compliance obligation inventory in the first 30 days, mapped against the actual technical environment. Not against the diligence attestation. Against what is actually running.

3. Security Incident Response

This is the one nobody wants to think about.

The acquired company had a dwelling threat before you bought them. An attacker was already inside. Credential stuffing, a business email compromise foothold, a slow-moving ransomware operator doing reconnaissance. The seller did not know. The diligence team did not find it, because security diligence in most deals is a questionnaire and a certificate check.

Then close happens. The attacker sees new activity, new integrations, new domains being trusted. They act.

The acquirer discovers, usually through a bank fraud alert or a ransomware note, that they now own a breach.

Legal fees, forensics, notification obligations, potential litigation, cyber insurance retention. This one runs from $75,000 on the low end to well past a million if the incident is material. Cyber insurance may not cover it, because the incident originated before the policy period, which is exactly the argument the carrier will make.

The fix is a security baseline sweep in the first 14 days. Endpoint detection deployed across the acquired environment. Identity provider audit. Dark web credential check for every acquired-domain email address. External attack surface scan. This is not optional. This is the price of admission to closing a deal.

4. Duplicate Vendor Contract Resolution

Two MSPs. Two backup platforms. Two email security stacks. Two identity providers. Two RMM tools. Two of everything, all with different renewal dates, different contract terms, and at least one with an auto-renewal clause that triggers 45 days after close.

I have seen combined organizations run parallel Microsoft 365 tenants for nine months because nobody wanted to be the person who broke email during Q4. The redundant licensing alone was $18,000 a month.

The fix is a vendor and contract inventory inside the first 30 days, with every renewal date and every termination window mapped on a single timeline. Decisions about what stays, what goes, and what gets renegotiated happen before the first auto-renewal fires. Not after.

The 90-Day IT Integration Roadmap

Here is the actual playbook. Three phases. Specific deliverables at each stage.

Days 1-30: Discovery and Stabilization

The first 30 days are about knowing what you actually own and locking it down.

Asset and infrastructure inventory. Every server, switch, firewall, access point, endpoint, printer, and mobile device. Model, age, warranty status, current utilization. This is done with an RMM tool deployment, not a spreadsheet exercise.

Identity and access audit. Who has access to what, at what privilege level. Every admin account. Every service account. Every shared credential. Terminated employees still active. Vendors with standing access nobody remembers granting.

Security baseline sweep. Endpoint detection deployed everywhere. MFA verified on every identity provider. Backup integrity tested with an actual restore, not a green checkmark in the dashboard. Dark web credential exposure check.

Communication infrastructure alignment. Email routing, calendar federation, chat platforms, phone systems. Whatever is going to be the shared environment gets tested and validated before anyone is asked to switch.

Compliance obligation mapping. Every regulatory framework is subject to, mapped against the actual technical state. Gaps flagged with remediation timelines.

What cannot wait. Anything that could cause business interruption or security exposure in the next 30 days gets an owner, a date, and a budget allocated. Everything else waits for phase two.

Days 31-60: Integration Architecture Decisions

Phase one told you what you own. Phase two is where the five decisions that shape everything else get made.

Decision 1: Identity management. One identity provider or two. If one, which one, and what is the migration path. Microsoft Entra ID is usually the answer for combined Microsoft shops. If you have inherited Google Workspace on one side and Microsoft on the other, that is a real decision with real consequences. Make it now.

Decision 2: Network architecture. Site-to-site VPN, SD-WAN, or full cloud-forward with no site interconnection. This depends on how much data actually needs to flow between locations and how much latency the applications can tolerate.

Decision 3: Cloud and on-prem strategy. What stays on-prem, what moves to cloud, what gets retired. This is where the load-forward analysis from phase one earns its keep. A server that fails under new load might be the trigger for a cloud migration you were going to do anyway.

Decision 4: Compliance posture alignment. One security framework, applied to the combined environment. Usually the more rigorous of the two, applied everywhere. Trying to run two different security baselines across one merged company is how things fall through the cracks.

Decision 5: Vendor rationalization. Which MSP, which backup, which email security, which SaaS stack. Every duplicate contract gets a decision and a termination date. The other one gets renegotiated with the leverage of consolidated spend.

Days 61-90: Execution and Documentation

Phase three is where the decisions become reality.

Identity migration runs on the schedule set in phase two. Network changes get implemented during defined maintenance windows. Retired systems get decommissioned properly, including data retention obligations. New systems get deployed and tested.

Documentation happens in parallel, not after the fact. Network diagrams get updated. Access matrices get published. Runbooks get written for the new environment.

The final deliverable is an operational baseline for the combined entity. Not a project close-out deck. A functioning, documented, secured environment that internal IT or your managed IT services partner can operate against on day 91.

What “Done” Looks Like

You cannot manage what you cannot measure. Here are six evidence points that integration is actually complete.

  1. Single identity provider. Every user in the combined organization authenticates through one system. Not two. Not “we will get to it in Q2.”

  2. Unified security baseline. One endpoint detection platform, one MFA policy, one backup standard, one patch management cadence, applied across the entire combined environment.

  3. Consolidated vendor contracts. No duplicate MSP, no duplicate SaaS, no unfavorable auto-renewals left standing. Every vendor relationship is intentional.

  4. Documented environment. Network diagrams, access matrices, asset inventories, and runbooks all current. New IT staff or a new MSP could operate this environment from the documentation.

  5. Compliance obligations mapped. Every framework the combined entity is subject to has a written control mapping and a named owner. Auditors get answers, not scrambles.

  6. Operational runbook in place. Incident response, change management, backup and recovery, onboarding and offboarding. Written down. Tested. Followed.

If you cannot check all six by day 90, integration is not done. Say so out loud and keep working.

Already Six Months Post-Close and Behind

If you are reading this and you closed nine months ago, and something in the four surprises section made your stomach drop, here is the triage sequence.

Week 1: Assess the actual exposure. Get an independent security and compliance assessment done. Not by the incumbent MSP. By someone with no incentive to soften the findings.

Week 2: Stop the bleeding. Whatever is actively costing money or creating exposure gets addressed first. Duplicate contracts hitting auto-renewal. Unpatched systems in the acquired environment. Terminated employees still active in the identity provider.

Weeks 3-6: Rebuild the foundation. Run the phase one discovery work retroactively. You skipped it. Do it now. You cannot make good phase two decisions without knowing what you actually own.

Weeks 7-12: Execute the plan you should have executed at close. The five architecture decisions still need to be made. The vendor rationalization still needs to happen. The compliance mapping still needs to exist. The work does not get easier by being delayed. It gets more expensive.

This can be done without disrupting operations. It requires an IT partner who has done it before and who is willing to move fast without breaking things you cannot afford to break.

The Direct Offer

Strix has run this roadmap across acquisitions in financial services, insurance, engineering, and PE-backed platforms. Multi-regional integrations, technically complex environments, compliance-driven environments where the cost of getting it wrong shows up on the front page.

If you are 60 to 90 days from close, this is the moment to get the roadmap in place before the surprises land.

If you just closed, the first 30 days matter more than the next 60. Get the discovery work started this week.

If you are six months post-close and behind, the triage path above works. It has worked before.

The playbook is not proprietary. The execution is what separates a $200,000 surprise from a clean integration.

Get in touch. Let us walk through your specific situation.