So, for many vendors looking to cash in on their smart inventions, an acquisition makes sense. But the customers do not see any of this windfall, so how should they react?Jim Melvin, vice president of marketing at RSA, purchased by EMC in June for $2.1 billion, says acquisitions should not negatively impact the customer as long as two key ingredients are in place: alignment of strategy and effective execution. (Melvin, in fact, joined EMC in September after it acquired Network Intelligence.)"Some companies are better at acquisitions than others," he says. "If it's done right, the customer wins, no doubt."In the case of EMC, the storage management giant decided to keep RSA as a standalone division, allowing the authentication mainstay to continue to flourish on its own (IBM is taking a similar approach with ISS). Melvin says this decision won Brownie points with customers because while RSA was able to leverage the EMC brand, it kept its own sales force and marketing teams.EMC's track record: The 31,000-employee, Hopkinton, Mass.-based company has invested $7 billion in the past three years on 22 acquisitions. It now sells to all of the world's Top 10 telecom and pharmaceutical companies and calls 97 of the S&P Global 100 customers."In theory, if you get acquired by a really big company, they should have the cash to throw at the product to keep it good," Nagel says. "The only question is, ‘Do they have the commitment to do that?'"Innovation and influence could suffer
Then, there is Cupertino, Calif.-based Symantec, a multi-billion dollar security bellwether that has acquired more than 25 companies since 2000 and offers solutions in every aspect of IT security but the identity management sector, says Nagel, who co-authored a May report analyzing Symantec's acquisition strategy."Symantec is the poster child for the whole consolidation of the security space," Nagel says.Tom Kendra, group president of worldwide sales and services at Symantec, says customers prefer running solutions from one vendor to minimize complexity and cost, in addition to gaining access to a broad set of partners. "What they want are world-class technologies that work together, and that is what we offer and what drives much of our acquisition strategy," he says.While the company's acquisitions have long-term benefit potential to customers, they may suffer in the short-term as innovation takes a backseat to integration, Nagel says. "Suddenly, [Symantec] engineers have to spend a lot of time to get everything to work together. They simply don't have the development time to keep upgrading the products that their customers have become used to."Kendra says integration is a critical part of any acquisition. The company develops dedicated teams to perform integration, and it works hard to retain the employees of acquired companies. "We do not quit selling the technologies we acquire during the integration phase," he says. "We take tremendous time and care when we integrate acquired companies into Symantec."Aside from worries over whether the acquiring company will continue to support a particular solution, customers also must consider whether their influence over the product roadmap will diminish. "If you're a million-dollar contract to a smaller company, you can rest assured you've got the time and attention of that company at all times," Yoran says. "If you're a smaller size contract for a much larger provider, you may not have that full direction influence and attention at all times."Robert Shaw, CEO of Cupertino, Calif.-based ArcSight, says independent providers such as his 6 1/2-year-old security management company provide the most innovative solutions and most customer focus.He says that the independents — aside from producing best-of-breed solutions — are typically staffed by a small group of people who have been with the company since its inception and feel vested in the technology. Should that vendor be acquired, many employees often decide to leave, even if they are offered a position with the acquiring company."They're driven by a small cadre of people who are really motivated and evangelized in their area, and their intent is on creating something great," Nagel says. "But once they get bought and they can't control the destiny of their baby anymore, they move on."Shaw says that when he hears of a local acquisition, his company soon sees a spike in applications. "If it's anywhere in our area, we see a flood of résumés," he says.Still, Brockway, whose company advises mostly sellers wanting to be acquired, insists that many worry not just about the payday, but also about intangibles, such as customer and employee satisfaction. "They feel loyalty to the technology and to the customers who have worked so closely with them to make them successful," he says.In an evolving industry such as IT security, still in its formative years, only time will tell how acquisitions ultimately play out for the customer. But one thing is certain: it is a seller's market out there. So if your provider appears to fill a hole in a larger player's portfolio, chances are an acquisition may not be far away."It's a trend that's not going to be going away," Yoran says. "The smaller companies will continue to be more aggressive and more innovative, and the larger companies will be the optimal delivery mechanism once these technologies achieve mainstream adoption."ACQUISITIONS:
Partners impacted
Partners feel the effects of an acquisition, too. In some cases, even more than a customer might. They worry they will lose their market share in a flash after devoting many hours toward cultivating clients and developing an understanding of the technology.
Certainly, the acquiring company benefits from a larger partner base — and the seller likely cares more about the value of their technology than losing a global sales distribution, says Doug Brockway, managing director at Innovation Advisors, an investment banking firm focused on the technology space.
When IBM acquired Internet Security Systems, many of ISS's 600 partners voiced concerns that IBM's huge reseller base — about 90,000 strong — would have free reign to peddle ISS solutions.
"There were some concerns that all the ISS products would just become [part] of the [IBM] price list that partners could sell," recalls Peter Evans, vice president of marketing at IBM ISS. "That created some angst among our partners."
Evans and the company responded by implementing a program that required all IBM partners to become certified in ISS products. "The initial angst has been overcome by putting the same rigor in processes required prior to ISS joining IBM," he says.
— Dan Kaplan
