Aerospace & Defense Report 2026 | Sponsored by Thrive

ACG: How should deal teams think about the role of IT leadership and cybersecurity talent during the transaction itself? KE: The top priority is that there’s a clear owner of the entire technology separation process on both sides of the transaction. Buyers certainly need that. On the seller side, transactions are more likely to be successful when the seller has a dedicated team that can be available, provide good documentation, and meet project deadlines. ACG: What is the most promising opportunity for private equity sponsors with a strong IT strategy during a carve-out? KE: First and foremost, executing against the TSA and getting ahead of it creates upside, because there are cost savings with becoming a standalone organization faster. The sponsor can then begin adding on additional orga- nizations through mergers and acqui- sitions, which speeds up the value cre- ation roadmap. The physical infrastructure often doesn’t convey with the transaction, so it becomes almost a greenfield opportu- nity. You get to rebuild the IT infrastruc- ture and, if done correctly, it becomes more scalable. When it’s time to make the next acquisition, you know the plat- form and the technology behind it, and you’ve already migrated from point A to point B before. Now you can do it faster. ACG: What are the consequences of a poorly executed IT separation? KE: Sometimes a TSA doesn’t include all the necessary technical considerations. In that instance, the buyer is refueling the plane while it’s in the air. They need

ACG: For A&D companies, how does CMMC readiness change the talent equation? KE: CMMC readiness is as much a rev- enue and market access issue as it is a cybersecurity issue. On Day 1, if you are not prepared and you can’t meet your attestations from a compliance and a technology perspective, you may not have access to the market that you sell into. Having evidence and documenta- tion—not just the security tools—really matters. From a talent standpoint, you need people who understand how to implement the proper controls and prove they’re operating effectively. Technical talent or tools alone aren’t enough. A good cybersecurity engineer isn’t necessarily a good CMMC resource. ACG: What role should external IT and cybersecurity partners play before close, during separation, and throughout the first 100 days? KE: The first 100 days don’t begin on Day 1. From an IT and cybersecu- rity standpoint, they should largely be designed before the transaction closes, and a lot of that design is based on pre- close diligence. It’s important that as the buyer, you have a full understanding of the com- pany’s technical debt and capabilities that will transfer from the parent, as well as any hidden shared services that will be gone on Day 2. Diligence is very important and should inform the TSA with detailed provisions around how long the buyer receives transition ser- vices and which extensions are available. There are certain deliverables that the seller must fulfill, otherwise the TSA can be extended without additional cost.

to make sure all the people coming over to the new company have full access to their applications, critical data, email, and other communications. You also have to maintain continuity of oper- ations for customers, often without direct access to the seller’s infrastruc- ture and data. That can add complex- ity and time, and ultimately require the buyer to extend the TSA, which adds additional cost. Another risk of improper planning is not having continuity of operations on Day 1. The last thing you want is to flip the switch and things aren’t work- ing. That starts to cost hard dollars in terms of profit and revenue, but also reputational damage when customers are impacted. ACG: How can you ensure a carve- out is aligned with the cybersecu- rity and IT culture of its new owner? KE: In instances where the carved-out entity will be a standalone platform, you can lean heavily on the security aspects of the compliance framework for your industry, whether that’s HIPAA in healthcare, CMMC in aerospace and defense, etc., to help establish the cybersecurity and IT culture. The new platform may not have the same security standards, requirements, and/or systems processes as the seller, so it’s also important to implement good change management and commu- nication. We recommend communicat- ing early to begin preparing people for upcoming changes, whether security or operational, and providing regular updates: “Here’s how you use the new portal to request help,” for example, or “Here’s the date that X or Y change is going into effect.”

ACG MAGAZINE 19

Made with FlippingBook interactive PDF creator