Post-Acquisition IT Integration: The 90-Day Playbook That Protects the Deal

The deal closed on a Friday. By the following Monday, the acquiring CEO wanted a synergy update, and the IT question got a one-line answer in a status deck.

I’ve watched that moment repeat across multiple acquisitions in compliance-driven businesses. Finance gets a workstream. Legal gets a workstream. HR gets a workstream. IT gets thirty days of attention and then rolls quietly to whoever happens to run infrastructure at the acquirer.

Six months later, the acquired company still runs on its own domain, its own security stack, and its own vendor contracts. Two environments. Two attack surfaces. Two cost centers. The synergies that justified the purchase price leak out through friction nobody named.

After four decades in technology and years working both sides of acquisition due diligence, the pattern is consistent enough to build a playbook around. Here it is.

Why IT Integration Gets Underbudgeted

Deal models treat IT integration as a line item. A single number in a spreadsheet, often a small percentage of transaction value.

The actual work looks closer to a full operational program. Discovery of systems nobody documented. Security remediation on an environment you didn’t build. Identity consolidation across two directories that were never designed to talk to each other. Compliance alignment when the target operated under a different standard entirely.

Speed pressure compounds the problem. Boards want synergies visible within two quarters. Done correctly, IT integration takes longer than that. Rushed, it breaks things that take even longer to repair.

The buyers who protect deal value treat IT integration as its own executive workstream with its own owner, its own budget, and its own timeline. The ones who fold it into general operations discover the true cost when a security incident, a failed audit, or a productivity collapse forces the conversation.

The Three Failure Modes

Every stalled or broken integration I’ve reviewed maps to one of three patterns.

Moving too fast. The acquirer forces both companies onto one tenant, one ERP, and one network in ninety days because the deal model promised it. Nobody documented what the target actually runs. Business-critical applications break in production, employees lose access to their files, and the acquired workforce loses trust in leadership because their tools stopped working.

Moving too slow. Twelve months after close, two separate IT environments still operate side by side. Two identity providers, two firewalls, two managed service providers. Security posture stays inconsistent, and an attacker who compromises the weaker company gains a lateral path into the stronger one. Costs run double because nobody consolidated licenses or contracts.

No clear accountability. The acquirer’s IT lead assumes the target’s IT manager owns integration. The target’s IT manager assumes the reverse. The private equity operating partner assumes both handle it. Decisions that need executive alignment stall for weeks, and integration work happens in fragments, stops, then restarts under a new person.

The fix for all three is identical. One named executive sponsor. One integration lead with authority across both environments. A written 90-day plan with weekly checkpoints. A budget that reflects real scope.

Days 1 to 30: Discovery and Documentation

You cannot integrate an environment you don’t understand. The first thirty days exist to find out what you actually bought.

Here’s the discovery checklist I run:

  • Inventory every system. Servers, endpoints, network gear, cloud tenants, software subscriptions, backups, security tools. Capture license counts, renewal dates, and admin credentials.

  • Map every business-critical application. Who owns it, what data lives in it, what it connects to, and what breaks when it goes down.

  • Document identity infrastructure. Directory structures, service accounts, privileged access, multi-factor authentication coverage, emergency access procedures.

  • Audit security posture. Endpoint protection coverage, patch levels, firewall rules, backup verification, incident response documentation.

  • Review compliance status. Whatever framework applies, verify where the target actually stands. Sell-side representations describe intentions. You need evidence.

  • Interview the IT team. The one or two people who ran the environment know more about what actually works than any document you’ll find.

By day thirty, you hold a written inventory, a risk register, and a prioritized list of everything that needs to change. That document drives the next sixty days.

Days 31 to 60: Security Baseline and Risk Triage

Close the gaps before you consolidate anything. Think of this phase as treating the disease before scheduling the surgery.

The acquired environment almost always carries weaker security posture than the acquirer. That reflects smaller scale, different threat models, and different budget realities rather than negligence.

The work in this window:

  • Standardize endpoint protection. One detection platform, one policy, one console covering both companies.

  • Enforce multi-factor authentication everywhere. No exceptions for executives, legacy applications, or old service accounts that modern authentication replaces.

  • Patch every critical and high vulnerability. If the target ran six months behind, catch up now.

  • Rotate every credential with unknown history. Local admin passwords, shared logins, VPN keys, cloud API tokens.

  • Verify backups actually restore. Run a real recovery test on a business-critical system inside a controlled window.

  • Align incident response. One playbook, one escalation path, one on-call rotation covering both entities.

💡 The point of this window: both companies now operate under one security standard, even while they sit on separate infrastructure. If something goes wrong at the acquired entity before consolidation completes, the damage stays contained.

Days 61 to 90: Consolidation and Standardization

Now the actual merge begins.

Consolidate identity first. Get both companies onto one identity tenant with a single governance model. Everything else depends on this working correctly.

Standardize the productivity stack. One collaboration platform, one file storage architecture, one email environment. Data migration follows a documented plan with rollback procedures.

Rationalize network architecture. If both companies ran their own network gear, decide which stack survives and plan the cutover, with security policies enforced consistently across every location.

Align cloud strategy. When one company built cloud-first and the other stayed on-premises, this is where you decide where workloads live going forward. That decision drives the next twelve months of infrastructure investment.

Consolidate vendor contracts where timing works. Renewals inside the next six months are immediate opportunities. Longer contracts get scheduled for future cycles.

At day ninety, you hold a single identity plane, a single security standard, a documented plan for remaining consolidation, and a clear timeline for finishing. The integration is controlled, understood, and actively managed rather than finished, and that distinction is exactly where it should be.

The Five Decisions That Determine Success

Everything above is execution. These five decisions are strategy, and they belong to the executive sponsor.

  1. Identity architecture. One tenant or federated tenants. Federated setups make sense when regulation requires separation. A single tenant runs faster and cheaper in every other case.

  2. Network architecture. Whether acquired locations become branches of the acquirer’s network or stay autonomous with controlled interconnection. This choice drives firewall strategy and incident response design.

  3. Cloud versus on-premises. The two companies usually arrive with different positions. Pick one strategy and plan the migration. Running parallel strategies indefinitely recreates the two-environment problem this whole playbook exists to prevent.

  4. Compliance posture. The combined company operates under whichever framework sets the higher bar. If the acquirer holds a certification the target lacks, the target starts remediation now. Budget the audit and set the timeline.

  5. Vendor rationalization. Every duplicate vendor is a decision waiting to happen. Rationalize on strategic fit and total cost of ownership rather than on which contract expires first.

Getting these five right in the first ninety days separates integrations that finish clean from ones that drag on for years.

What Done Looks Like

Integration is complete when you can point to specific evidence across six areas.

One identity plane covers both companies, with consistent authentication and access policies for every user and device. Security posture is uniform, with the same protection standard, patch cadence, and response procedures everywhere. Infrastructure operates as one environment, or as a documented federated model where separation is intentional.

The vendor stack is rationalized, with duplicate contracts consolidated or scheduled for consolidation. IT operations report through one structure, with one service desk, one budget owner, and one roadmap. Deal synergies show up as measurable numbers, with cost consolidation visible in the financials and productivity gains visible in operations.

⚠️ If you can’t produce evidence on any of these six by day one hundred eighty, the integration stalled and needs executive intervention.

The Real Cost of Getting This Wrong

Every acquisition thesis includes an integration timeline, and that timeline usually runs optimistic. IT integration is where the optimism meets reality.

The cost of failure shows up in three places. Direct cost from running duplicate infrastructure longer than the model assumed. Security cost from inconsistent posture across two entities. Opportunity cost from leadership attention consumed by unresolved integration instead of growth.

Buyers who protect deal value have run this playbook before. They know what discovery actually takes, where the security gaps hide, and which decisions cannot be delegated. The team at Strix has run this framework across acquisitions in technically complex organizations, and we’ve seen how it holds up under audit pressure and board scrutiny.

The deal only works if the integration works. If you’re sixty to ninety days from close, or just past it, pull this playbook out, name your executive sponsor, and put the first thirty-day discovery plan in writing this week.