Phase 1 — Pre-Merger Due Diligence
Complete before deal close. This phase is the most critical — gaps identified here are far cheaper to address than post-close.
Governance
Checklist ItemOwnerTimelineStatus / Notes
Identify GRC lead / integration ownerMediaTech GRCPre-close
Establish joint steering committee (MediaTech + YourNews + MSP rep)BothPre-close
Define decision-making authority during transitionMediaTech Legal & GRCPre-close
Document YourNews's current governance structureYourNewsPre-close
Review YourNews board/management accountability for complianceMediaTech GRCPre-close
Risk Assessment
Checklist ItemOwnerTimelineStatus / Notes
Conduct technical security assessment of YourNews environmentMediaTech SecurityPre-close
Identify all data YourNews holds (user, advertiser, content, contracts)YourNews + GRCPre-close
Map YourNews's regulatory obligations (GDPR, CCPA, press laws etc.)LegalPre-close
Review MSP contract — scope, access rights, termination clausesLegal + GRCPre-close
Assess MSP security posture (SOC 2, ISO 27001, or equivalent)MediaTech SecurityPre-close
Identify MSP subcontractors (fourth-party risk)MediaTech GRCPre-close
Determine if YourNews owns its data or if MSP controls itLegalPre-close
Check for ongoing audits, legal disputes or regulatory investigationsLegalPre-close
Identify crown jewel assets — IP, proprietary content, subscriber dataBoth + GRCPre-close
Compliance
Checklist ItemOwnerTimelineStatus / Notes
Review YourNews compliance certifications (ISO, SOC, etc.)GRCPre-close
Compare YourNews compliance posture against MediaTech baselineGRCPre-close
Identify compliance gaps requiring remediation post-closeGRCPre-close
Confirm data processing agreements are in place with MSPLegalPre-close
Check GDPR data transfer mechanisms (if cross-border data flows)Legal + DPOPre-close
Phase 2 — Day 1 Readiness (Deal Close to First 30 Days)
Immediate actions upon close. Focus on containment, visibility, and MSP relationship management.
Governance
Checklist ItemOwnerTimelineStatus / Notes
Assign single GRC integration owner — accountable end-to-endMediaTechDay 1–30
Formally notify MSP of merger and initiate contract reviewLegalDay 1
Define escalation path for security/compliance decisionsGRCDay 1–7
Communicate merger to YourNews staff with compliance expectationsHR + GRCDay 1–14
Risk & Security
Checklist ItemOwnerTimelineStatus / Notes
Document all MSP access to YourNews systems immediatelySecurityDay 1
Freeze MSP access expansion — no new access to MediaTech systemsIT SecurityDay 1
Separate YourNews and MediaTech networks until security parity achievedITDay 1
Treat YourNews environment as untrusted until assessedSecurityDay 1–30
Onboard YourNews environment to MediaTech SIEM/monitoringIT SecurityDay 1–30
Deploy EDR on all YourNews endpointsIT SecurityDay 1–30
Rotate all shared/default credentials in YourNews environmentIT SecurityDay 1–14
Identify and remove any temporary firewall rules or access exceptionsIT SecurityDay 1–14
Compliance
Checklist ItemOwnerTimelineStatus / Notes
Notify relevant regulators of merger if requiredLegal + DPODay 1
Classify all YourNews data under MediaTech's data governance frameworkGRC + DPODay 1–30
Ensure GDPR obligations for YourNews user data are transferred/maintainedDPO + LegalDay 1
Review active YourNews contracts for change-of-control clausesLegalDay 1–14
Phase 3 — Integration (30–180 Days)
Systematic alignment of policies, vendor contracts, and compliance posture across both entities.
Governance & Policy
Checklist ItemOwnerTimelineStatus / Notes
Decide which policies govern merged entity — MediaTech, YourNews, or combinedGRC30–90 days
Roll out MediaTech policies to YourNews staff with formal sign-offHR + GRC30–60 days
Establish unified risk register covering both entitiesGRC30–60 days
Set up recurring GRC review cadence for integration progressGRC30 days+
Vendor / MSP Management
Checklist ItemOwnerTimelineStatus / Notes
Conduct formal vendor risk assessment of MSPGRC + Security30–60 days
Request SOC 2 Type II or equivalent from MSPGRC30–60 days
Renegotiate MSP contract under MediaTech's vendor standardsLegal + GRC30–90 days
Add right-to-audit clause to MSP contractLegal30–90 days
Define SLAs, incident response obligations for MSPLegal + IT30–90 days
If exiting MSP — plan structured offboarding with credential rotation and data retrievalIT + Legal60–180 days
Confirm all MSP access is fully revoked upon contract endIT SecurityOn exit
Compliance & Controls
Checklist ItemOwnerTimelineStatus / Notes
Run full gap assessment against MediaTech control framework across YourNews environmentGRC + Security30–60 days
Remediate high-risk control gaps first (access, encryption, logging)IT Security30–90 days
Set target date for YourNews compliance parity with MediaTechGRC30 days
Conduct privacy impact assessment for merged data flowsDPO30–60 days
Update data retention schedules to cover YourNews dataGRC + DPO30–60 days
Conduct staff security awareness training for YourNews employeesHR + Security30–60 days
Document lessons learned and update M&A GRC playbookGRC180 days

Key GRC Principles for This Merger

1
Assume the acquired company is not secure until proven otherwise.

Treat YourNews's environment as untrusted from Day 1. Verify everything before granting access to MediaTech systems.

2
The MSP is a vendor, not a team member.

The MSP had a contract with YourNews. They do not automatically have a relationship with MediaTech. Assess, renegotiate, or exit — but never inherit blindly.

3
Compliance obligations transfer immediately on close.

GDPR, data retention, licensing — all of it becomes MediaTech's liability the moment the deal closes. Own it early.

4
Network integration is a security event.

Never connect two environments without achieving security parity first. Temporary firewall rules must have expiry dates and named owners.

5
The gray zone is the danger zone.

The period between close and full onboarding is when attacks happen. Prioritise visibility (SIEM, EDR) in YourNews's environment before anything else.

MediaTech · GRC Integration Programme · Confidential