The 72-Hour Rule: Manage Acquisition Chaos Before It Spreads
The first 72 hours after a deal closes are chaos. Here, Jason James shares how to turn that chaos into structure.

"The honeymoon ends quickly. It feels like every time you turn over a rock, you find snakes."
The following article is based on a portion of my upcoming book, Make It Work: An IT Playbook for Mergers and Acquisitions.
Understanding someone else’s IT department
The deal has closed and been announced internally. Pats on the back between executives have occurred. High-fives in hallways and animated GIFs of standing ovations have been sent. I like to use the clapping Leonardo DiCaprio animated gif from The Wolf of Wall Street. Sales teams are ready to go and sell. If you are lucky enough to be the one leading the integration, it’s time to schedule a meeting with the combined team.
The first meeting is generally not a deep dive but an overview of the technology and an understanding of the daily activities and challenges. Those challenges will become quite evident soon enough. The honeymoon ends quickly and is displaced by the frustration you now have from daily discoveries of new issues. It feels like every time you turn over a rock, you find snakes. All of the data they shared in the data room didn’t prepare you for how poorly organized this new team seems to be or how many issues exist.
So, where do you start first? When in firefighting mode, follow the VI Plan: Stop and create a project plan. Outline all critical systems, dependencies, and their stakeholders. Collaborate with stakeholders on migration order. Listen to users about their needs.
Pro tip
Make sure key members of tech teams have retention bonuses set in place so they aren’t lost. The people who know where the bodies are buried are the ones you need to keep around the longest.
The 72-hour rule
I have a personal rule that governs the first three days after a deal closes. I call it the 72-Hour Rule, and it has served me well across nearly two dozen deals. In the first 72 hours, you accomplish three things and three things only:
Secure credentials. Every admin password, every root account, every API key, and every domain registrar login must be secured. Get those credentials documented and transferred under your team’s control. The keys protect the corporate crown jewels. An insider threat is always a risk, and not everyone on the target IT team will be excited about the deal announcement.
Meet the people. Go on-site and walk around. Shake hands with everyone in the office and introduce yourself. Do not just focus on the tech teams. Meet with everyone and ask people what they do and what keeps them up at night. You will learn more in water-cooler conversations than in many of the PowerPoint decks. If an on-site visit is not possible, schedule online mini-meetings with the major departments in the business.
Identify the biggest risks. We all have our biggest fear. When I was a child, it was a fear of heights and now it’s the fear of running out of money in retirement. The tech teams have an equivalent of He Who Must Not Be Named. Maybe it’s the ancient firewall that no longer has the manufacturer’s support. It could be the single point of failure in the production database. Or it’s a senior developer who just gave two weeks’ notice. There will be big risks, and not all of them are technological. It is the job of the CIO to find them and mitigate them. Everything else can wait until Day 4.
Focus on those three priorities and push everything to the 30-60-90 plan. There will be pressure for you to move fast. The CEO wants the email migration done by the end of the week and your CFO wants the synergy savings reported by the end of the month. The CRO wants the CRM consolidated yesterday. Everyone will think their priority is the most important integration activity. Smile, nod, and say, “We’re on it.” Then go back to your 72-Hour Rule.
Pro tip
Keep a transition planning note on your phone. If you are more analog in nature, keep a small notebook with you for those first few weeks. Write down every issue, concern, and observation. Review your notes with your technical team lead. Recurring themes help refine your integration priorities.
Managing the announcement
The way the deal is announced internally sets the tone for the entire integration. I have been part of announcements that were meticulously crafted, making them look like the launch of a new Apple product. There were also some that were handled so poorly that the integration was cursed before it started.
A good announcement is transparent, empathetic, and action-oriented. It explains what happened, why it happened, what it means for employees, and what happens next. It comes from visible leadership, acknowledges uncertainty, and provides a clear channel for questions.
From an IT perspective, you need to be prepared for the flood of questions that will come after the announcement. Employees want to know: Will my email change? Will I need a new laptop? Will I lose access to the tools I use? Will my team be reorganized? Will I still have a job? Have answers ready for the first three questions. For the last two, be honest about what you know and what you don’t. These are people’s jobs, and in this economy, uncertainty turns quickly to fear.
Delaying the announcement
I spent almost six years as a CIO in healthcare tech. Healthcare/Healthcare Tech is the second-most-attacked sector in the United States, behind financial services and ahead of retail. During the pandemic, ransomware attacks on hospitals and healthcare centers were an almost weekly occurrence. During this time, I recommended a 30-day delay period before our acquisition announcement went public.
Threat actors read press releases, and they exploit post-announcement uncertainty that an acquisition causes. Ensuring EDR, firewalls, and backups are completed and verified prior to the public announcement will allow you to be as ready and protected as possible post-close.
Many industries do not have the luxury of delaying an announcement, especially public companies. But if you are a private company or a PE-backed company, ask the CEO to give your team time to harden the target environment prior to a public announcement. Share a 30-day plan and explain how a delay reduces the overall cybersecurity risk.
Yes, thirty days may seem like a long time to keep the announcement under wraps, but that delay could be the difference between a successful acquisition and another headline about a company succumbing to ransomware.
Pro tip
Prepare an FAQ document before the public announcement and share it with the IT team so they can answer common questions. This ensures a consistent message from all team members. The FAQ should cover the email transition timeline, VPN and network access changes, application access and how and whom to contact during the transition. The FAQ reduces anxiety and prevents your help desk from being overwhelmed on Day One.
The first all-hands meeting
Within the first week post-close, you should hold a conversational and frank all-hands IT meeting with the combined IT staff. This is your first opportunity to introduce yourself to the acquired team, explain the integration approach, and start building the relationship that will carry you through the next 12 months.
I start every first all-hands with the same message: “Han shot first!” Kidding, most of this generation probably wouldn’t even get that reference. I say, “I’m excited at the potential of our combined forces. We have a lot of work to do, and at times it will be challenging. But if we do this right, the combined team will be stronger than either team was on its own. Most importantly, I need your help to make that happen.”
It’s a good idea to open with an “AMA: Ask Me Anything” format. Some of the questions will be technical, and some will be political. The details of the integration can wait. This initial meeting is more about them learning your background and perspective on the integration. Some may be bold enough to ask the big question: “Will I have a job after integration is complete?” If you know, share that if there are headcount reductions, you’ll work together to ensure the transition is as supportive as possible. If the answer is no, reassure them that additional headcount reductions are not currently necessary, but how they work towards a successful integration will cement their position and future in the combined organization.
Don’t oversell your team or insinuate your team’s work is in any way superior. Don’t make promises you cannot keep, and don’t pretend that everything will be easy. People’s bullshit detector is on high alert post-close. These are people who were doing their jobs and often had little to no idea an acquisition was happening. Now they have merged with another group of strangers and have new leadership. Show them honesty, competence, and empathy. Give them that, and you will earn their trust. Lose their trust in this meeting, and you may never get it back.
Jason James is Chief Information Officer (CIO) at Aptos, a leader in retail technology solutions, where he oversees the company's ever-evolving digital landscape and translates the company’s vision into an actionable IT roadmap. He has over two decades of leadership experience in SaaS, cybersecurity, IT infrastructure, and digital transformation. Before joining Aptos, Jason was CIO at several high-growth software and data analytics organizations within the healthcare sector. Earlier in his career, Jason held executive-level IT roles at the supply chain optimization provider, Servigistics (now PTC), the data intelligence firm PRGX, and internet service provider EarthLink. He is the author of Make IT Work: An IT Playbook for Mergers and Acquisitions.
If this caught your attention, that’s not accidental.
The best editorial systems don’t happen by accident. Outlever builds them.









