# Why security makes or breaks M&As, with Matt O'Leary

DevFeed: [Why security makes or breaks M&As, with Matt O'Leary](<https://devfeed.tech/articles/why-security-makes-or-breaks-m-as-with-matt-o-leary-1976.md>)

Original publisher: [Read original article](<https://1password.com/blog/why-security-makes-or-breaks-mandas-with-matt-oleary>)

Author: info@1password.com (Dave Lewis)

Published: 2026-05-06T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [business](<https://devfeed.tech/tags/business.md>), [corporate](<https://devfeed.tech/tags/corporate.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [deals](<https://devfeed.tech/tags/deals.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [leadership](<https://devfeed.tech/tags/leadership.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>), [product-engineering](<https://devfeed.tech/tags/product-engineering.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This Chasing Entropy episode examines how security diligence affects acquisitions and strategic partnerships. Matt O'Leary explains that companies inherit a target's technology, processes, legal exposure, and security weaknesses, making serious technology or cybersecurity risks potential deal breakers. The discussion also covers partnership risk, shared trust, and the need to align corporate development with product, engineering, and security leadership.

## Source excerpt

Listen to this episode on Apple Podcasts null Listen now Listen to this episode on Spotify null Listen now Security is tied to business operations in many (often unappreciated) ways, but the connection is rarely more visible or consequential than during an acquisition or partnership. In those deals, a company stakes its reputation and finances on another company, and a lapse in security can throw the whole thing into chaos. That's the subject of this episode of Chasing Entropy, in which Dave Lewis talks with Matt O'Leary, 1Password's Vice President of Corporate Development and Strategic Partnerships. They discuss what changes about M&As and partnerships when security is tied directly to the product, the brand, and the deal itself. Caveat emptor in M&As O'Leary's core idea is simple: when a company makes an acquisition, it inherits the whole business, not just the part that looked attractive in the pitch. That includes the technology, the team, the process gaps, the legal exposure, and any security weaknesses that were not obvious at first glance. O'Leary makes the case that strong dealmaking starts with risk discipline, because a transaction only creates value if the company can integrate what it buys without importing problems that slow everything down. He also explains that good corporate development starts with the roadmap, not the deal. An acquisition makes sense when it helps the company move faster than building on its own. That is why corp dev has to stay tightly aligned with product, engineering, and security leadership. In a cybersecurity company, technical diligence carries extra weight. If a target has a serious security or technology issue, that is not a detail to clean up later. It is a reason to walk away. Go as deep as you possibly can, before you cut the proverbial check...If there is any major issue with the technology, if there is any significant exposure to cybersecurity risks in a company we are targeting, those are deal killers." - Matt O'Leary Th