<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Private Equity &#8211; TristanPoulsen.com</title>
	<atom:link href="https://tristanpoulsen.com/category/private-equity/feed/" rel="self" type="application/rss+xml" />
	<link>https://tristanpoulsen.com</link>
	<description>Welcome to TristanPoulsen.com</description>
	<lastBuildDate>Tue, 11 Aug 2026 16:07:22 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://tristanpoulsen.com/wp-content/uploads/2024/07/cropped-Tristan-Forryst-Poulsen-initials-logo-32x32.png</url>
	<title>Private Equity &#8211; TristanPoulsen.com</title>
	<link>https://tristanpoulsen.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire</title>
		<link>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/</link>
					<comments>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 15:46:19 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=919</guid>

					<description><![CDATA[Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition. The short version: Two firms, one border between them These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in ... <a title="Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire" class="read-more" href="https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/" aria-label="Read more about Seven Years, Zero Incidents: The Outsourced IT Support Behind an Acqui-Hire">Read more</a>]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><em>Two sister engineering firms, one on each side of the US-Canada border, and the quiet IT work that kept them secure through customer security reviews and into an acquisition.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Two sister engineering firms, one in the US and one in Canada (anonymized), serving industrial clients</li>



<li><strong>Engagement:</strong> Seven years and counting of outsourced IT support and security</li>



<li><strong>Scope:</strong> Email security, cloud storage, remote and in-person helpdesk, phone systems, hardware</li>



<li><strong>Status:</strong> Both firms are now being acquired, primarily for their engineering talent. I still run their security today.</li>
</ul>



<h2 class="wp-block-heading">Two firms, one border between them</h2>



<p class="wp-block-paragraph">These two companies came to me about seven years ago. Sister firms, shared ownership, one operating in the US and one in Canada, both doing engineering work for industrial clients. Neither one had internal IT, and neither one needed a big MSP contract with a 40-page SLA. They needed someone who picked up the phone.</p>



<p class="wp-block-paragraph">That&#8217;s been the shape of the whole relationship. I handle their email security, their cloud storage, and their day-to-day support, remote when that works and in person when it doesn&#8217;t. Over the years the scope grew the way it does with small firms: I&#8217;ve run their phone system migrations, built their workstations by hand when off-the-shelf machines didn&#8217;t fit the budget, and made a hundred small calls about where to spend money and where to hold off. IT support for small business lives in those decisions. The stack matters less than the judgment behind it.</p>



<h2 class="wp-block-heading">The customer security test</h2>



<p class="wp-block-paragraph">A few years in, one of their major industrial customers raised the stakes. Before awarding project work, the customer required compliance with its corporate IT security policy and information security program. Buried in the requirements was a hard one: all project data had to stay in Canada.</p>



<p class="wp-block-paragraph">That&#8217;s a data residency requirement, and it&#8217;s the kind of thing that quietly kills deals for small vendors. The engineering team just wanted to work. The customer wanted proof their data wouldn&#8217;t drift onto US servers. My job was to close that gap without blowing up the budget or the workflow.</p>



<p class="wp-block-paragraph">I laid out three options with real time and cost estimates: client-side encryption with Canadian-held keys on their existing cloud storage, a locally encrypted vault, or a move to a Canadian-hosted cloud platform. They picked the Canadian platform. I ran the migration, kept the working copies flowing for the engineer who needed them daily, and mapped the setup against the customer&#8217;s security policy documents so the answers were ready before anyone asked.</p>



<p class="wp-block-paragraph">Small firms lose big customers over vendor security assessments they can&#8217;t answer. This one kept theirs.</p>



<h2 class="wp-block-heading">Then the acquisition came</h2>



<p class="wp-block-paragraph">Both firms are now being acquired by a larger company, and the deal is mostly about people. The acquirer wants the engineers. That&#8217;s the whole thesis.</p>



<p class="wp-block-paragraph">Talent deals move slowly, and this one has. Which makes the IT story simple to state and hard to fake: through the entire drawn-out process, the engineers have kept working, the systems have stayed up, and the security stack has kept running. Seven years in, the incident count is still zero. Nobody on the buyer&#8217;s side has had to ask why the target&#8217;s email got breached or where the customer data lives, because those answers were settled years ago.</p>



<p class="wp-block-paragraph">I&#8217;m not running this deal, and this case study isn&#8217;t about deal work. It&#8217;s about the thing that makes deal work easy: an acquirer doing diligence on these firms finds documented systems, a customer-vetted security posture, and a support relationship that didn&#8217;t wobble when ownership went into limbo.</p>



<h2 class="wp-block-heading">What seven years buys</h2>



<p class="wp-block-paragraph">Here&#8217;s the honest math on long-term outsourced IT support. Any provider can look good for six months. The value shows up in year three when a customer&#8217;s security team comes knocking, and in year seven when a buyer does, and both times the answers are already written down.</p>



<p class="wp-block-paragraph">These two firms got acquired for their talent. The reason talent was the <em>only</em> thing under negotiation, rather than talent minus a pile of IT risk, is seven years of unglamorous maintenance: patched systems, secured email, data where the contracts say it should be.</p>



<h2 class="wp-block-heading">If your customers are bigger than you</h2>



<p class="wp-block-paragraph">Industrial customers push their security requirements downstream, and acquirers read your environment like a balance sheet. Both happen on their schedule, not yours. The firms that come through clean are the ones that treated security as routine long before anyone was checking.</p>



<p class="wp-block-paragraph">If you&#8217;re staring down a customer&#8217;s vendor security assessment, a data residency requirement, or a sale where your IT needs to hold up to inspection, that&#8217;s the work I do.</p>



<p class="wp-block-paragraph"><em>Facing a security review you&#8217;re not sure you&#8217;d pass? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/outsourced-it-support-acquisition-case-study/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybersecurity Due Diligence Case Study: A Real PE Acquisition</title>
		<link>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/</link>
					<comments>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/#respond</comments>
		
		<dc:creator><![CDATA[tristanpoulsen]]></dc:creator>
		<pubDate>Tue, 11 Aug 2026 15:00:28 +0000</pubDate>
				<category><![CDATA[Cyber-Security]]></category>
		<category><![CDATA[Private Equity]]></category>
		<guid isPermaLink="false">https://tristanpoulsen.com/?p=912</guid>

					<description><![CDATA[From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities. The short version: It started with a breach They found me the way ... <a title="Cybersecurity Due Diligence Case Study: A Real PE Acquisition" class="read-more" href="https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/" aria-label="Read more about Cybersecurity Due Diligence Case Study: A Real PE Acquisition">Read more</a>]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">From Breach Cleanup to Buyout: Cybersecurity Due Diligence in a Real Acquisition</h2>



<p class="wp-block-paragraph"><em>How 4.5 years of security work turned a single-location self-storage company into a clean acquisition target, and what a three-week technology handoff looks like when the buyer runs 50+ facilities.</em></p>



<p class="wp-block-paragraph"><strong>The short version:</strong></p>



<ul class="wp-block-list">
<li><strong>Client:</strong> Single-location self-storage operator in Colorado (anonymized)</li>



<li><strong>Buyer:</strong> Private equity-backed storage operator with 50+ facilities</li>



<li><strong>My role:</strong> IT and security provider for 4.5 years, then transition lead on the seller side</li>



<li><strong>Handoff:</strong> Three weeks, kickoff to done</li>
</ul>



<h2 class="wp-block-heading">It started with a breach</h2>



<p class="wp-block-paragraph">They found me the way a lot of my clients do: mid-incident. Their previous IT provider had gone defunct, and the provider&#8217;s abandoned website was serving malware. Someone at the storage company opened that site looking for support and infected their machine instead.</p>



<p class="wp-block-paragraph">I took the call, cleaned the infection, recovered their systems, and combed through everything for leftover malicious code. Then I rebuilt their stack so it wouldn&#8217;t happen twice: antivirus, EDR through Huntress, cloud backup, and same-day helpdesk, remote and onsite. All of it sized and priced for a single-location business.</p>



<h2 class="wp-block-heading">Four and a half years of quiet</h2>



<p class="wp-block-paragraph">For the next 4.5 years I ran their IT and security. Webroot and Huntress covered the endpoints. Backups ran to the cloud and got checked. When something broke, I fixed it the same day. No repeat incidents, no drama.</p>



<p class="wp-block-paragraph">That stretch of quiet matters more than it sounds. When a buyer showed up years later, the company had a documented, monitored environment with a real security history behind it. Most small businesses walk into a sale with none of that.</p>



<h2 class="wp-block-heading">Then a buyer showed up</h2>



<p class="wp-block-paragraph">A private equity-backed storage operator with 50+ facilities acquired the company. Deals like this live or die in diligence, and the buyer&#8217;s team had two questions about IT: is this environment secure, and is it cost-effective?</p>



<p class="wp-block-paragraph">That&#8217;s technology due diligence in one sentence. Buyers want proof, and on small acquisitions they rarely get it, because the seller&#8217;s IT knowledge lives in one person&#8217;s head or a defunct vendor&#8217;s filing cabinet. Here, I had run the environment for years and could answer with documentation instead of guesses. That alone shortened the timeline.</p>



<h2 class="wp-block-heading">The three-week handoff</h2>



<p class="wp-block-paragraph">Post merger IT integration for this deal came down to four workstreams.</p>



<p class="wp-block-paragraph"><strong>RMM migration.</strong> The buyer standardized every acquisition onto their own remote management platform. Instead of touching each machine by hand, I wrote a script that deployed their agent and removed mine (ConnectWise Automate, at the time) across all systems in one pass.</p>



<p class="wp-block-paragraph"><strong>Backup migration.</strong> I moved their cloud backups off my platform and onto the buyer&#8217;s, and verified restore points on both ends before cutting over. A migration without verified restores is a gamble, and nobody gambles during a closing.</p>



<p class="wp-block-paragraph"><strong>Access control.</strong> The buyer&#8217;s team ran the access control migration themselves. I supported from the client side, kept credentials flowing, and made sure nothing on our end held them up.</p>



<p class="wp-block-paragraph"><strong>Data cleanup and destruction.</strong> The buyer&#8217;s compliance requirements meant old data had to go, and go for real. I purged stale records the business no longer needed, then dealt with the retired hard drives that held customer data: a seven-pass wipe on each drive, and then I opened them up and pulled the platters out. Nobody is recovering that data. The platters make decent coasters, if you&#8217;re wondering.</p>



<p class="wp-block-paragraph">Secure data destruction is the step small-business acquisitions skip most, and it&#8217;s the one that turns into a lawsuit years later when a drive full of customer records surfaces at a pawn shop.</p>



<p class="wp-block-paragraph">Total time, including the buyer&#8217;s inspection and the back-and-forth between their team and my client: three weeks.</p>



<h2 class="wp-block-heading">The result</h2>



<p class="wp-block-paragraph">The buyer got what diligence teams almost never get from a small acquisition: a documented environment, a working security stack, verified backups, and proof that legacy customer data was destroyed instead of forgotten in a closet. My client walked into closing without IT sitting on the deal as an open issue.</p>



<p class="wp-block-paragraph">And the whole thing traced back to a malware infection five years earlier. The same work that saved them from a breach made them a cleaner company to buy.</p>



<h2 class="wp-block-heading">Why this matters if you&#8217;re buying or selling</h2>



<p class="wp-block-paragraph">Most small businesses run on undocumented IT held together by whoever set it up. In an acquisition, undocumented becomes risk, and risk becomes a price reduction or a delayed close. Buyers now run cybersecurity due diligence on deals of every size, and sellers who can&#8217;t answer basic questions about their environment pay for it at the negotiating table.</p>



<p class="wp-block-paragraph">If you&#8217;re a buyer, a searcher, or an owner planning an exit, the cheapest time to fix your technology story is before diligence starts. That&#8217;s the work I do: assess the stack, close the gaps, and run the handoff so the deal keeps moving.</p>



<p class="wp-block-paragraph"><em>Working a deal and want a second set of eyes on the technology? <a href="https://tristanpoulsen.com/contact/">Get in touch.</a></em></p>
]]></content:encoded>
					
					<wfw:commentRss>https://tristanpoulsen.com/case-studies-cybersecurity-due-diligence-acquisition/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
