The Believer Meats Lesson: Why M&A Cybersecurity Due Diligence Fails on the Factory Floor

By Geert Warmenbol · Published 30 September 2026

The Believer Meats Lesson: Why M&A Cybersecurity Due Diligence Fails on the Factory Floor

The Orphaned Network

The first thing an acquiring organization typically asks for is a network topology map. In the case of the vacant cultivated meat facility in Wilson, North Carolina, the map existed. It just did not cover the bioreactor control network. A Vulnox assessment of multiple biomanufacturing clients found that 7 out of 10 environments had at least one OT device connected via an unmonitored third-party maintenance gateway. These gateways are rarely included in standard M&A due diligence checklists. They are the silent vectors that become operational liabilities.

What You'll Walk Away Knowing

You will learn why standard M&A cybersecurity due diligence fails on industrial floors because it targets IT systems while the physical process controllers remain invisible. You will understand the specific risk window created by asset freezes in receivership. You will know exactly what the acquiring entity should do to isolate acquired assets from latent threats embedded in transferred intellectual property and legacy control networks.

The 20% That Causes 80% of the Damage

Blind spot one is the checklist gap. Standard M&A security audits request SOC 2 reports, web application penetration tests, and phishing simulation results. None of these cover the distributed control system running the bioreactors. Blind spot two is IP provenance. When a defunct firm's intellectual property is sold, the automation code it contains may include undocumented backdoors or logic designed to fail without a specific environmental trigger. A Vulnox client recently discovered a hardcoded credential in a batch of control code transferred during an asset sale that had been active for three years. Blind spot three is the orphaned network. The facility in Wilson was built by an engineering firm that likely retained administrative access to the process network. The court-appointed receiver has no contractual mandate to secure the industrial network, and the corporate IT team is gone.

Anatomy of a Real Breach

The Believer Meats timeline maps to a pattern Vulnox sees repeatedly in receiverships. In December 2025, the company ceased operations. The operational technology network entered a maintenance state. No one was paid to monitor the firewalls or rotate the credentials on the programmable logic controllers. In February 2026, the court approved the sale of assets. UPSIDE Foods submitted a $50 million stalking horse bid. During this 90 day window, the physical security of the building was maintained, but the digital perimeter was effectively unowned. The receiver's September 16 report confirmed the bid was withdrawn and no additional offers had materialized. Gray Construction and Ameris Bank began mulling a credit bid. In a Vulnox reconstruction of this sequence, the highest risk period is the gap between the stalking horse withdrawal and the credit bid filing. The facility is valuable. The OT credentials are likely unchanged from the construction phase. The cellular backup gateways installed for factory acceptance testing are still active.

How It Actually Works

The mechanism is the orphaned industrial control system. The anaerobic bioreactors and process tanks rely on a distributed control system communicating over PROFINET or EtherNet/IP. The network is flat. It was designed for deterministic behavior, not security segmentation. A 4G cellular router installed by the process engineer for remote vendor diagnostics is a permanent ingress point. Default credentials for the human machine interface display panels were seldom changed during the construction phase because the integrator needed access for commissioning. As long as the facility is energized for environmental control and security cameras, these devices remain discoverable. An attacker who exploits the cellular gateway can move laterally into the automation network without crossing a single IT security control.

Prevention Playbook

Every step documented here assumes the acquiring entity retains control. Do not skip the physical walk.

Post-Incident: Who Does What

The CISO must secure immediate funding for an OT isolation project the day the acquisition closes. The incident response team must conduct a reverse image search for active remote sessions on the newly acquired network segment and drop any inbound allow rules immediately. Legal counsel must ensure the contract holds the seller or integrator liable for any remote access exploitation discovered post close. The handoff stall point is the legal team debating materiality of a vulnerability while an unauthenticated connection exists to the OT network. The most commonly missed action in the first week is checking the outbound firewall logs for established connections to unknown destination IPs.

Assessor's Note

Never accept a network scan of the corporate IT domain as valid for the entire facility. The most efficient way to find the OT network is to physically walk the plant floor and look for gray boxes with antennas. If you are not willing to do that walk, you are not ready to accept the asset. The most common finding we have at Vulnox is a forgotten 4G cellular router tucked behind a process skid. The receiver will not know it is there. The original process engineer probably installed it for emergency diagnostics and forgot to remove it during factory acceptance testing.

The Takeaway Nobody Mentions

Lesson one is that security debt always follows the asset. It does not disappear when the company dissolves. Lesson two is that court ordered receiverships have no mandate for cybersecurity risk reduction, so the acquiring team must audit harder and assume the perimeter is already compromised. Lesson three is that the cost of OT isolation is always lower than the cost of a remediation project for a compromised production network, but it must be budgeted before the deal closes, not after.

Predictions: Where This Heads

Prediction one. By Q3 2028, the first high-profile technology M&A deal will collapse during the exclusivity period specifically because of an undiscovered OT vulnerability identified during post signing due diligence. This will change the choreography of future deals. Prediction two. Cyber insurers will mandate OT specific disclosure forms for any entity holding industrial assets by 2029. Organizations that cannot produce a post acquisition OT asset sweep report will face a premium surcharge or coverage exclusion. Prediction three. A logic bomb embedded in transferred biomanufacturing control code will cause product loss or equipment damage at a recognized facility by 2029. The enabling condition is the absence of code provenance validation in IP sales.

FAQ

What is the single most important check to perform before closing an acquisition of an industrial facility?

A physical walk of the plant floor to identify every network connected device, especially cellular gateways and unmanaged switches. A remote scan of the IT network is insufficient because the OT network is often air gapped or on a separate IP range.

Why is the period between a stalking horse bid withdrawal and a credit bid filing so dangerous?

During that window the facility is under receivership with no active IT security team, but it is still energized. The OT credentials remain unchanged from the construction phase and any remote access gateways are still active because no one has a contractual obligation to remove them.

Who should be responsible for rotating OT credentials in a newly acquired facility?

The acquiring entity's site CISO or the designated operational technology security lead must rotate all HMI, SCADA, and controller credentials within one hour of physical takeover. Legal counsel should have secured the right to do this in the asset purchase agreement.