OSec × Interfor International
Live · Sept 23 Register Now
Live Webinar · OSec & Interfor International

You Didn't Build It. You Own It Anyway.

Inherited security risk, and what happens when someone finally puts a price on it.

  • Real numbers on what inherited security gaps cost in live M&A deals
  • Three perspectives in one room: the investigator, the pentester, and the CISO who inherits the result
  • Practical takeaways you can use Monday — whether or not you touch deals
Featuring Don Aviv (CEO, Interfor International), Mark Stamford (Founder, OSec) and Dr. Ed Harris (CISO, Mauser Packaging Solutions)
Live · Online
Date Wed, Sept 23, 2026
Time 2:00 – 3:00 PM ET
Format Fireside chat + live Q&A
Save My Spot →
Can't make it live? Register anyway — we'll send the recording to everyone who signs up.

Built for both sides of the table.

Security & Risk

  • CISOs, security directors and managers
  • Security architects and engineers running third-party and vendor assessment
  • IT leaders at acquiring or recently acquired companies
  • GRC and risk teams
  • Penetration testers and red teamers

The Deal Side

  • Private equity deal and operating partners
  • M&A and securities counsel
  • Corporate development
  • Family office principals
  • Transaction liability underwriters
See your team on that list? You should be in the room. Wed, September 23, 2026 · 2:00–3:00 PM ET · Live online
Register Now

Almost nothing a security team defends was built by the security team.

You inherit it: an acquisition, a subsidiary, a vendor, a platform someone bought without telling you, or a decade of decisions made before you arrived. You are accountable for an environment you did not design and often cannot fully see. Most of the time you absorb that quietly. Occasionally, someone puts a number on it.

That is what makes M&A the sharpest lens on inherited risk — the one situation where security gaps get converted into hard dollars in front of an audience that cares.

Purchase prices get cut. Money goes into escrow. Deals die.

50%+
of acquirers find significant cyber problems only after closing on a deal.
42%
of executives who hit a cyber incident around a deal watched the deal value drop.

Don Aviv runs Interfor International, which assesses organizations from the outside: investigations, corporate intelligence, and enhanced due diligence for Fortune 500 acquirers, private equity groups and family offices. Mark Stamford founded OSec, which breaks into them. Dr. Ed Harris runs security at Mauser Packaging Solutions and is the one who has to live with what they find. This is a conversation about what they find in environments nobody has properly looked at — and what those findings turn out to be worth.

Six things you can use on Monday morning.

01
Assessing what you don't controlHow to evaluate an environment with limited access, no cooperation and a deadline — the diligence playbook works the same for a vendor, a subsidiary, or an acquisition.
02
What assessors find firstWhat experienced assessors find first in an environment nobody has audited, and why it's almost always the same short list.
03
What actually gets fixedWhich findings a business will actually pay to fix and which get filed away — plus the M&A evidence for why.
04
Translating risk into dollarsHow to translate a technical finding into the language that moves money: valuation, escrow, indemnity, insurance premiums.
05
"We inherited it" — and the regulatorWhat that excuse does and doesn't get you: the SEC's four-business-day disclosure clock, GDPR, and FTC enforcement.
06
Where accountability landsWhere accountability for an inherited vulnerability actually lands, and how to establish that before you need to know.

60 minutes. No wasted time.

0:00 – 0:03 Welcome, setting the context
0:03 – 0:12 The inheritance problem — almost nobody defends an environment they built
0:12 – 0:24 What We FindAssessing an environment with limited access and no cooperation
0:24 – 0:36 What It's WorthThe findings that move money, and how much
0:36 – 0:45 Accountability and disclosure — who owns an inherited vulnerability
0:45 – 1:00 Live audience Q&A
60 minutes. Six takeaways. One live session. Bring your team — forward this page to anyone handling diligence or inherited risk.
Register Now

Three vantage points on the same environments: the investigator, the attacker, and the defender who has to live with it.

Don Aviv

Don Aviv

CEO, Interfor International

Don Aviv is Chief Executive Officer of Interfor International. He oversees the firm's operations and leads its investigations and security consulting practices, advising clients on complex matters involving corporate investigations, threat mitigation, crisis response, and intelligence-driven risk management.

Mr. Aviv is a frequent media commentator on corporate investigations and security matters, and has authored numerous articles on physical security, global investigations, threat mitigation, and corporate security. He also serves as an expert witness in security-related litigation.

Mark Stamford

Mark Stamford

Founder, OSec

Mark has over 30 years' experience in IT security, operations, control assessment and re-engineering, and risk management. Prior to OSec he worked for UBS AG as Director of Threat and Vulnerability Management, responsible for threat identification, testing, and remediation for systems and applications across the organization.

Before that he worked at KPMG, where he was the lead penetration tester for the Americas and managed a number of Fortune 100 security engagements. Prior to KPMG, he worked at a financial services company in London.

Dr. Ed Harris

Dr. Ed Harris

CISO, Mauser Packaging Solutions

Dr. Ed Harris is CISO at Mauser Packaging Solutions, a global leader in solutions and services across the packaging lifecycle. He has spent more than 30 years building and leading cybersecurity programs across the manufacturing sector, often in environments never designed with security in mind.

Harris holds the CISSP and DIT-IAC credentials and is a Fellow at the Institute for Critical Infrastructure Technology (ICIT). He writes and speaks widely on CISO leadership, arguing the role is less about testing the latest point product and more about being “a leader, mentor, teacher, and motivator.”

If you've ever been handed an environment and told to make it safe — this is your problem too.

Join Don Aviv, Mark Stamford and Dr. Ed Harris live. 45 minutes of conversation, then 15 minutes of your questions. No product demo, no compliance lecture.

60-Minute Session Live Q&A Recording Sent to Registrants
Register Now →
Wednesday, September 23, 2026 · 2:00–3:00 PM ET · Live online
Can't attend live? Register anyway and we'll email you the recording.
Live WebinarWed, Sept 23 · 2 PM ET
Register Now