Confidential mandate

Cyber M&A Separation Leader — Metals Processing

Urgent / Unplanned

Cyber M&A Separation Leader mandate in Johannesburg, South Africa · Metals Processing

After a divestment exposed shared cyber dependencies, a metals group needs executive separation leadership to establish secure buyer and seller boundaries and hand over tested independence within twelve months.

The mandate

Legal completion transferred a processing division while identity administration, monitoring, vulnerability tooling and plant remote access remained shared under loosely drafted transition services. The cyber separation director resigned after a buyer test account retained seller privilege beyond its approved perimeter. Neither side can now prove which alerts, credentials or OT connections will survive each TSA exit.

The interim must start within three weeks for twelve months, working across Johannesburg, the Durban operation and monthly buyer sessions in London. The first quarter centres on containing cross-perimeter privilege and rewriting separation gates. A permanent regional security search begins after two major TSA exits in month seven, followed by six weeks of overlap; extension is possible only for a delayed successor start.

Handover requires separate identity and privileged administration, independent monitoring and incident evidence, mutually tested vulnerability and disclosure routes, severed unapproved plant connectivity and closure of every cyber TSA. Buyer and seller must complete a joint boundary-compromise exercise, residual data access must match legal agreements, and the successor must chair one post-separation risk review.

The leader may revoke cross-company access, freeze unsafe migrations, sequence cyber TSA exits, require independent testing and redirect the approved ZAR 90 million separation budget. Steering approval is required for business interruption beyond forty-eight hours, material TSA amendment, permanent hiring and acceptance of a shared residual control; each party's CISO retains incident and disclosure authority within its legal perimeter.

Application functional separation, plant production strategy, data-migration content and broader technology cost removal are excluded. The appointee records dependencies where they affect cyber trust but does not own the transaction's complete IT carve-out. The assignment ends at demonstrable security independence, not at legal completion or transfer of service invoices.

Why this seat is open

The lingering buyer privilege disproved assumptions that contractual boundaries had become technical boundaries. Prior leadership exited before the seller and buyer agreed a single evidence standard for cyber separation. Temporary executive authority is needed to contain exposure, arbitrate TSA sequencing and leave permanent leadership with independent operations.

What you will own

  • Reconcile the legal perimeter to directories, privileged accounts, networks, monitoring, security tools, data stores and plant support paths.
  • Decide immediate revocation, temporary shared control and sequenced exit using business impact and cross-company compromise exposure.
  • Rewrite cyber TSA schedules with service scope, accountable operator, evidence, incident rights, charges and objective exit tests.
  • Establish buyer-seller protocols for alerts, vulnerability disclosure, forensic preservation and incidents crossing the separation boundary.
  • Run access, monitoring and remote-maintenance cutovers with rollback, retained evidence and authorised business acceptance.
  • Exercise compromise originating on each side and prove escalation, containment and information sharing under transaction constraints.
  • Transfer closed TSAs, residual access, decision history, evidence packs and ninety-day assurance priorities to the permanent leader.

Candidate qualifications

  • Led cybersecurity separation for a completed carve-out involving identity, monitoring, infrastructure and operational-technology dependencies.
  • Can evidence closure of cyber transition services through technical exit tests rather than contractual date or tool deployment.
  • Governed buyer-seller incident, vulnerability and forensic-information sharing under confidentiality and competition constraints.
  • Removed cross-company privileged and remote access without causing uncontrolled plant or business interruption.
  • Held director or CISO-level authority across transaction, security, operations and legal stakeholders with competing priorities.
  • Handed independently operable cyber controls and residual-risk records to permanent leadership after separation completion.

Non-negotiables

  • Available within three weeks for the South Africa and London transaction cadence.
  • Independent of buyer, seller and both parties' principal transaction or managed-security advisers.
  • Will revoke unsupported access despite pressure to preserve convenient shared services.
  • Has principal-side cyber-separation authority, not solely diligence or transaction-PMO experience.
  1. 49 words maximum. State your availability and one cyber TSA exit you personally accepted.
  2. 49 words maximum. Which technical evidence proved buyer and seller identity were genuinely separated?
  3. 49 words maximum. Describe a shared cyber service you retained temporarily and the trigger that ended it.

This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.