Why Zero Trust Fails for the Same Reason Many Mergers Do
Hatched by Tom Haus
Jun 21, 2026
10 min read
1 views
87%
The hidden question behind both cybersecurity and acquisitions
What do a zero trust program and a merger or acquisition have in common? At first glance, almost nothing. One is about cyber defense, the other about corporate strategy. But both live or die on the same overlooked question: Can a complex system absorb new parts without losing its ability to make decisions?
That question matters because many organizations confuse buying components with building capability. They purchase security tools and call it zero trust. They acquire companies and call it growth. In both cases, the surface looks impressive. The deeper reality is often messier: disconnected systems, unclear authority, brittle processes, and a failure to measure whether anything actually improved.
The uncomfortable truth is this: integration, not acquisition, is the real test of maturity. A zero trust environment that cannot unify policy across identity, device, workload, and data is not truly zero trust. A company that cannot integrate cash flow, leadership, systems, and strategy after a deal is not truly ready for one. Both are examples of a broader organizational law: you are only as strong as your decision architecture.
The illusion of readiness: when structure looks stronger than it is
Organizations often mistake visible assets for underlying readiness. In security, that means a stack of point products: identity provider, SIEM, NDR, CDM, endpoint controls, and microsegmentation tools. In M and A, it means a strong balance sheet, a confident leadership team, and an apparently scalable infrastructure. These are all necessary ingredients, but none of them prove the system can actually hold together under pressure.
This is why both domains are haunted by the same illusion. A company can have the money to acquire another business and still be unprepared for the operational shock of integration. Likewise, it can deploy zero trust products and still be unable to verify that security posture has measurably improved. In both cases, the hard part is not procurement. The hard part is coordination across boundaries.
Think of it like adding rooms to a house. A larger house is not necessarily a better house if the plumbing does not connect, the wiring is inconsistent, and no one knows which thermostat controls which zone. Many organizations are building mansions with no blueprint for the internal systems. They look bigger, but they are not yet more capable.
Readiness is not having more parts. Readiness is having a system that can govern more parts.
That is why the most revealing question is not, “Do we have the tools?” or “Can we afford the deal?” It is, “Can we preserve coherence while expanding complexity?”
Why static controls are the corporate equivalent of a one-time due diligence memo
A striking parallel exists between early zero trust deployments and ill-prepared acquisitions. In security, many organizations begin with static signals like user identity and device posture. That is a sensible starting point, but it is only a starting point. The promise of zero trust is dynamic, context-based access, yet the reality often devolves into rule sets that barely evolve after deployment.
Mergers suffer from the same trap. Before a transaction closes, leadership may perform rigorous due diligence, map synergies, and model integration. But once the deal is done, many of those assumptions become stale. What was true in the boardroom may be false in the operating environment. Customer behavior changes, systems conflict, talent leaves, and the “obvious” synergy begins to leak out through every seam.
The core problem is a reliance on static validation in a dynamic system. A one-time checklist can be useful, but it cannot substitute for continuous governance. A pre-deal financial model is not enough if there is no mechanism to monitor integration drift. A basic zero trust policy is not enough if there is no policy decision point capable of ingesting live signals and adapting access in real time.
This suggests a deeper framework: maturity is the capacity to update decisions as reality changes. That applies whether the decision is who may access a workload or how a combined company should allocate capital, talent, and authority after a deal.
A company that prepares for acquisition should ask:
- Can our finance systems reconcile with theirs without manual heroics?
- Can our leadership team make decisions quickly when assumptions change?
- Can our infrastructure absorb new users, data, products, and policies without collapsing into exception handling?
A security team should ask the same structural questions in its own language:
- Can our policy engine ingest signals from identity, endpoint, logs, and threat intelligence?
- Can access decisions adapt when risk changes, or are they frozen at first login?
- Can we verify improvement, or are we merely collecting tools that appear protective?
The parallel is not accidental. Both domains are trying to solve the same governance problem: how to make decisions at scale without turning every edge case into a crisis.
The real asset is not control, it is orchestration
Many leaders talk about control when what they actually need is orchestration. Control implies a central hand directing everything. Orchestration implies something subtler: multiple instruments playing from the same score, with enough flexibility to respond to tempo, volume, and timing.
That distinction is crucial. In zero trust, the temptation is to think in terms of tighter enforcement alone. But if policy cannot flow across systems, enforcement merely creates islands of security. In M and A, the temptation is to think in terms of ownership. But owning a business does not automatically produce integration. You may own the assets, yet still fail to coordinate decision making across finance, IT, HR, legal, and operations.
This is where a useful mental model emerges: the capability of a system is determined by the quality of its policy distribution.
In zero trust, that means the ability to translate identity, device posture, data sensitivity, threat intelligence, logs, and other signals into a usable access decision. In acquisitions, it means the ability to translate the strategic rationale of the deal into operating rules that people can actually execute. The most sophisticated strategy on paper fails if it cannot be distributed through the organization in a way that changes daily behavior.
Consider two companies merging. If one uses one finance stack, another uses a different one, and neither side has a common language for cost centers, approvals, or reporting cadence, then leadership is not running a company anymore. It is running an argument. Security suffers a similar fate when different tools enforce different definitions of risk. The result is not stronger defense. It is policy fragmentation.
Fragmentation is not a side effect of complexity. It is what complexity becomes when there is no shared decision layer.
This is why vendor-neutrality matters in security, and why integration architecture matters in acquisitions. You cannot govern what you cannot translate.
A maturity model for complex systems: from acquisition to orchestration
The deepest connection between these domains is that both require a shift from asset thinking to system thinking. Here is a simple model that can help.
Stage 1: Accumulation
At this stage, organizations add tools, capabilities, or targets. A security team deploys ZTNA, microsegmentation, SIEM, and NDR. A company explores acquisitions, builds a war chest, and gathers leadership consensus. This is the easiest stage to confuse with progress.
Stage 2: Alignment
Now the organization tries to make the parts point in the same direction. Policies are defined, rationale is clarified, and the leadership team agrees on strategic goals. In zero trust, this means determining where static signals are enough and where dynamic access is needed. In M and A, this means asking why the deal exists at all, whether for market expansion, capability acquisition, or cost synergy.
Stage 3: Integration
This is the hard stage. Systems must actually talk to each other. Policy decision points must consume relevant signals. Finance, IT, HR, and operations must reconcile processes. Without integration, alignment remains aspirational.
Stage 4: Adaptation
The most mature systems do not merely integrate once. They keep learning. Zero trust policies evolve as risk signals change. Post-merger operations evolve as the combined company discovers which assumptions were false. Adaptation is what turns a structure into a living system.
This model matters because it reframes maturity as a process rather than a destination. A company is not “ready” for a merger because it has strong numbers. It is ready when it has the governance mechanisms to absorb complexity without improvising everything from scratch. A security program is not mature because it has many products. It is mature when it can continuously convert signals into decisions across a distributed environment.
In other words, readiness is not a threshold. It is an operating discipline.
The measurable gap: proving improvement is the hardest part
One of the most revealing challenges in zero trust is the inability to easily verify that security posture has actually improved. That problem has a mirror image in acquisitions: leaders often struggle to prove that a deal created real value rather than just bigger revenue and more complexity.
This is a profound organizational blind spot. We like to believe that effort, investment, or activity will necessarily translate into outcome. But complex systems are full of false positives. More controls can mean more friction without more protection. More acquisitions can mean more scale without more profit.
The answer is not just measurement, but measurement tied to governance. If you cannot measure the effect of a zero trust rollout, you cannot mature it. If you cannot measure whether a merger improved operating performance, you cannot learn from it. In both cases, leaders need metrics that go beyond activity and into decision quality.
Useful questions include:
- Did access decisions become more context-aware after deployment?
- Did exceptions decrease, or did they simply move elsewhere?
- Did the combined company reduce duplicated work, or just increase coordination overhead?
- Did leaders gain clarity after the deal, or do they now spend more time resolving interface problems?
These questions matter because they reveal whether an organization is creating decision leverage or just adding surface area. The point is not to have more rules, but to have better ones. The point is not to have more entities under one roof, but to have a roof that actually works in bad weather.
Key Takeaways
-
Stop asking whether you have enough tools or enough capital. Ask whether your system can absorb complexity without losing coherence.
-
Treat integration as the real proof of maturity. In security, that means policy engines that can ingest multiple signals. In M and A, that means systems and teams that can operate as one.
-
Move from static decisions to adaptive governance. Static controls and one-time due diligence are only the beginning. Mature organizations keep updating decisions as conditions change.
-
Measure outcomes, not just activity. A deployed tool or a closed deal is not evidence of success. Look for improved decision quality, reduced exceptions, and lower friction.
-
Build a shared decision layer. Whether you are managing access or combining companies, the real advantage comes from a common framework for policy, escalation, and adaptation.
The deeper lesson: growth is a test of governance
We usually talk about security and acquisitions as if they are different kinds of ambition. But both are really tests of governance under stress. Growth exposes whether an organization understands its own decision architecture. If it does not, expansion makes the weaknesses visible faster.
This is why some organizations become less agile as they get bigger. They add capabilities without improving coordination. They increase surface area without increasing intelligence. The result is a system that is technically larger, but functionally weaker. Zero trust failures and failed integrations are not separate problems. They are symptoms of the same disease: the inability to turn distributed complexity into coherent action.
That is the real challenge in modern organizations. It is not simply to defend more territory or acquire more assets. It is to build systems that can think, decide, and adapt across boundaries. When you do that, security becomes more than protection, and acquisitions become more than expansion. They become evidence that the organization has learned how to grow without breaking itself.
And that may be the most important strategic capability of all: not the power to add, but the discipline to integrate.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣