Why Did We Acquire a Cybersecurity Firm? The Business Case—and What Customers Should Expect

Why acquire a cybersecurity firm? Explore Agio’s business rationale, the challenge of integrating IT and security, and what customers should expect beyond a broader service catalog.

An IT-services company can keep systems running without fully addressing the risks those systems create. A cybersecurity firm can identify serious threats without having the authority to fix the underlying technology. Bringing those capabilities together can close an important gap—but only if the integration works.

Agio’s documented rationale was preparation for growing cybersecurity threats and regulatory demands. In its January 15, 2020 company announcement, Agio identified its purchase of Secure Enterprise Computing as a 2013 acquisition. That is the documented transaction date, distinct from the 2019 date in the earlier article’s URL.

This new analysis uses that published history as a starting point, not as a reconstruction of the unavailable article. The broader question remains relevant: why acquire security expertise, and how should customers judge whether the transaction delivers?

A cybersecurity acquisition should buy more than a broader service catalog. It should create a demonstrably better way to protect, respond, and recover.

What an IT-Services Company Is Really Buying

The strongest acquisition rationale begins with a specific capability gap. Perhaps the provider can manage infrastructure but lacks incident-response expertise. Perhaps it has security tools but insufficient staff to investigate alerts. Or perhaps customers need governance and regulatory support alongside technical operations.

The NIST Cybersecurity Framework 2.0 offers a useful structure: Govern, Identify, Protect, Detect, Respond, and Recover. Map existing services against those functions, identify missing capabilities, and determine which gaps the target actually fills.

What matters is the operating capability behind the offering:

  • People: Experienced practitioners with complementary technical and advisory skills.
  • Processes: Repeatable investigation, escalation, remediation, and recovery practices.
  • Evidence: Records showing that services operate as described.
  • Accountability: Clear ownership of decisions and customer outcomes.

These assets are not guaranteed to survive a transaction. If essential employees leave or workflows remain disconnected, the buyer may acquire the brand without retaining the capability.

The Practical Benefit: Connecting Detection to Action

Consider a hypothetical compromised-account incident. A security analyst identifies suspicious activity, but the IT team controls the identity platform. Someone must decide whether to revoke sessions, disable the account, isolate a device, or interrupt a business-critical workflow.

When responsibilities are unclear, the incident can stall between detection and action. Common ownership creates an opportunity to reduce those delays—not an automatic solution.

Before an incident, the combined provider should establish:

  • Who investigates and validates suspicious activity.
  • Who can take containment actions, under what authorization.
  • Who preserves evidence and informs the customer.
  • Who verifies that recovery is safe and complete.

NIST’s incident-response guidance, SP 800-61 Revision 3, finalized in April 2025, integrates incident response into broader cybersecurity risk management. The acquisition lesson is straightforward: connect preparation, detection, response, and recovery rather than simply combining ticket queues.

Why Acquire Instead of Building or Partnering?

Acquisition is one route to stronger security services, not the default answer. Compare it with realistic alternatives.

Build internally

Building allows the provider to shape the service around its customers and operating model. The tradeoff is the work of recruiting specialists, developing procedures, establishing leadership, and sustaining coverage. Hiring talented individuals does not instantly create a functioning security operation.

Partner with specialists

Partnerships can provide targeted expertise without owning the entire operation. They may be especially useful for occasional or highly specialized needs. The tradeoff is dependency: escalation, access, evidence sharing, commercial terms, and exit arrangements must work across organizational boundaries.

Acquire an established capability

Buying can bring a team, processes, and customer relationships together under common ownership. But ownership introduces integration costs and retention risk. Model the full investment, including remediation, overlapping tools, training, and transition work—not just the purchase price.

Test the downside: If key employees leave or expected cross-selling does not materialize, does the acquisition still support a credible operating plan?

Apply Security Due Diligence to the Security Firm

A cybersecurity company should not receive a diligence exemption because of its specialty. Its own administrative systems, remote-access tools, subcontractors, and recovery arrangements deserve scrutiny.

NIST SP 1326, finalized in July 2026, provides a current supplier due-diligence starting point covering ownership and influence, provenance, resilience, foundational cybersecurity practices, and supply-chain dependencies. It is not a complete corporate-acquisition playbook, but its categories can help organize technical questions.

Request evidence rather than relying on presentations:

  • Identity and access: Privileged-account inventories, access reviews, and authentication controls.
  • Operational security: Vulnerability-management records, incident procedures, and unresolved findings.
  • Resilience: Restoration-test results and dependencies that could interrupt service.
  • Delivery model: Which services employees operate and which depend on subcontractors.
  • Continuity: Key-person dependencies, documented procedures, and retention arrangements.

Separately, qualified legal, financial, and transaction advisers should examine liabilities, customer concentration, contract transferability, intellectual property, and commercial obligations. Strong technical diligence cannot substitute for complete deal diligence.

Integration Creates Concentration Risk, Too

A combined IT and security provider may hold extensive access to customer environments. That access makes coordination possible, but it also makes the provider an attractive attack path.

The joint government advisory on threats to managed service providers and their customers recommends measures including multifactor authentication, least privilege, separation of customer environments, and logging. Those controls become especially important when integrating organizations.

Do not merge administrative access merely because the deal has closed. Validate identity controls, remote-management paths, customer boundaries, and visibility into provider activity first.

For example, replacing separate management platforms with one shared platform may simplify operations. It can also concentrate access and create migration risk. Consolidate only after testing permissions, monitoring, rollback procedures, and customer separation.

There is also an assurance tradeoff. The team managing a system should not be its only evaluator. Customers may still need independent assessments to test whether controls work as claimed.

What Customers Should Gain—and What Must Be Written Down

Customers should expect clearer responsibility, coordinated response, and access to relevant expertise. They should not have to infer service changes from an acquisition announcement.

Provide a written explanation of:

  • Scope: What is included, excluded, unchanged, or separately priced.
  • Authority: Whether monitoring includes active containment and who approves disruptive actions.
  • Communication: Incident-notification expectations and escalation contacts.
  • Recovery: What restoration support is included and who validates readiness.
  • Data and exit: How logs, evidence, and access are handled during transition or termination.

An acquisition also does not automatically make customers compliant. Security services can support regulatory obligations, but customers still need governance, appropriate legal advice, and evidence that relevant controls operate effectively.

Integrate in Stages and Measure the Result

Use a risk-based sequence rather than treating closing day as permission to connect everything.

Establish the baseline

Document capability gaps, critical dependencies, unresolved risks, and essential personnel. Define the conditions that must be satisfied before systems or access are combined.

Stabilize and exercise

Confirm service ownership and escalation contacts. Run a joint incident exercise that follows a realistic alert through authorized containment and recovery. Record missing permissions and ambiguous decisions.

Consolidate selectively

Retire overlapping tools only after validating coverage, evidence retention, customer boundaries, and rollback arrangements. Tool reduction is useful only when it does not weaken the service.

Measure verified monitoring coverage, elapsed time from a validated alert to authorized containment, overdue remediation, and successful restoration tests. Define scope and establish baselines before claiming improvement. A faster response metric means little if important systems are excluded from monitoring.

Cybersecurity Acquisition Success Checklist

Use this checklist during deal approval, integration reviews, and customer-service evaluations:

  • The acquisition addresses a documented capability gap.
  • Building and partnering were evaluated as alternatives.
  • The business case includes retention, remediation, and integration costs.
  • Critical expertise has a credible continuity plan.
  • Technical diligence examined the target’s controls and dependencies.
  • Privileged access and customer boundaries were validated before integration.
  • Customers received clear scope and responsibility statements.
  • Incident-response authority and escalation paths were exercised.
  • Recovery was demonstrated through testing.
  • Leadership assigned measurable outcomes and owners for unresolved risks.

The Acquisition Is the Beginning, Not the Result

Agio’s published explanation points to preparation for cybersecurity threats and regulatory demands. For any comparable acquisition today, the enduring business case is connecting security expertise with the operational ability to act.

But the transaction itself proves little. Better protection must show up in clear responsibilities, controlled access, tested response, and reliable recovery.

Before approving an acquisition—or accepting a provider’s claims about one—ask for the capability map, responsibility matrix, integration safeguards, and outcome scorecard. Those documents turn a strategic announcement into an accountable delivery plan.

Browse all insights · Contact Bart McDonough