Signs you're about to be acquired (2020)
yolken.net
yolken.net
Meeting day comes and the CEO proudly announces that the company is getting a brand new logo...
Relevant: https://reclaim.ai/blog/this-meeting-could-have-been-an-emai...
The danger is that there are signs for lots of things, so jumping to conclusions regarding the reason can be dangerous.
For example, we recently got a contract with a company fanatical about security. They wanted additional special insurances, which in turn wanted additional company-wide security policies.
This affected everyone, even though the potential contract only affected 3 employees. (And there was an NDA regarding the possibility of a deal.) The policy changes (despite being good policy anyway) likely caused some anguish.
So by all means speculate away, staff love a good rumor, and in the absence of information will speculate anything and everything. But I caution against making big life choices based on that speculation.
That said, we now have some customers who have extremely stringent security requirements, and for understandable reasons. They want every CVE resolved for every release; this is going to cause a notable amount of work to 'resolve' issues which aren't issues by taking developer time to update and test third-party libraries, or even patch the libraries ourselves if the upstream CVE hasn't been resolved yet.
It's unquestionably worth doing if this is a dealbreaker for our customers, but could definitely impact things in the short term by requiring fixes which are technically unnecessary.
here's some ways it could happen:
- startup doesn't have ability to hire competent, experienced developers. they end up with rookies with potential but not enough experience to avoid security foot-guns, and/or experienced expert-beginner developers who have a low level of ability
- leadership doesn't value quality or security, so the company culture reflects this and focuses on what leadership values
- startup outsources development work and has no in-house technical capability to check quality or security of deliverables
- startup is pre product-market fit in a domain where security is less relevant, and security issues are less of a risk to the business than the more existential concern around identifying and de-risking a scalable, profitable business model. then suddenly the throwaway proof of concept codebase for the 7th pivot starts getting traction, and by shovelling features on top it is possible to win more customers
I guess the exception might be the decision to wait a couple of months before making some other decision!
The distractedness of the executives is spot on. But it always seems to be in hindsight that we look back and go "huh, funny..." I am sure we could write an inference bot that monitors the calendars of people in the organization and estimates that an acquisition is imminent.
And the security/bug fixing. "Yeah, that bug has been there for three years, nobody has time to fix it." Well, all of a sudden, we are fixing it. And more besides. And the licensing of software and source code. Getting a full run down of every open source license, and I mean _every_ license, and then going back and checking them again. A sudden drive to document everything.
I've also seen the ugly side of acquisition too. An equity claw back that happened to me many years ago that I am still sore about. Sudden acceleration of equity grants and a "re-interpretation of what 'it' means" or extreme scrutiny of whether you actually qualify for the equity in your contract. I've seen a few good people suddenly not get anything because there was a missing signature on a document even though the person had been at the company three years.
Large amounts of acquisition money does strange things to people.
My supervisor called me to a meeting room, he let me first sign a non-disclosure agreement, or he can't tell me nothing. I had to sign that paper. Then he told me that the company was acquired, and you have choice to either leave or work for Tencent. If you want work for Tencent, you had to go over their interview and only talented people will get offer.
But actually 95% of my colleagues get offer, including me.
Also, the morning of a big announcement, my boss asked me "can the blog handle heavy load?" and I was like "yeah sure, but nobody reads the blog", "they will, can we make it like a static page or something?" ... So, like ok, whatever, stupid thing to ask for, but it's easy. Got that going, and also we had a meeting added, no agenda. And one of my coworkers was convinced something was going on, he said people had been in the office all weekend.
This sounds dodgy as fuck! If this ever happens to you, please don't sign the paperwork without running it past a lawyer. It's definitely not there to grant you more rights.
Don't let false urgency ever pressure you to do otherwise.
If they need your signature, they can wait to get it. If they don't need your signature then they shouldn't have a problem anyway.
Also running tools like Black Duck over your source code tree to check open source license types or use of unlicensed code snippets from the Web.
NDAs can be given to people who know how something is done, knowledge that they could use to re-create the product or service elsewhere, which the acquired does not want. In some cases (that I have not personally seen) making people sign non-compete agreements, meaning if they quit they cannot work on the same thing for some time (not legal everywhere).
The only thing you would have to document are the things you specifically added.
At least, that’s been my experience.
If someone asks for source code for a library, simple point them to the GitHub repository. This isn’t rocket science and it isn’t worth automating because practically nobody asks for it.
For GPL-licensed code, you should provide the sources yourself. "Point them to a GitHub repository" is not acceptable, since the repo might disappear or change contents without you noticing.
And it is definitely worth automating, if you are releasing at scale (either many products or many versions). Otherwise you will be left having to handle requests like "does anyone remember the exact contents of our product X, of version of 2023-03-03?"
At a big company, we (as in the team) had to review any and every library and its dependencies before we could use it, then the security team had to review it. The amount of shit code out there is outstanding; many times we would just reimplement it ourselves, unless the library did something substantial that we didn’t want to maintain. (This is also why zero-dependency libraries are a thing)
Generally, this can be solved by simply vendoring your dependencies (aka, commit them to the repository instead of fetching them for every build).
> For GPL-licensed code, you should provide the sources yourself.
Version 3 of the GPL simply states that "clear directions" on how to find the source code may be given. There's no requirement for you to distribute those sources yourself unless you make modifications and make the software available for sale or download. Internal use/private modifications do not need to be given away.
> it is definitely worth automating
I worked at a company that dealt in nothing but commercially licensed open source code. That meant we were much more likely to get requests for our source code because it was obvious we were running heavily modified open source software. That being said, despite having millions of users, we only got a few requests a month and we still didn't bother automating it.
So, I'm not convinced it is worth automating unless you are in the hundreds of millions of users range.
- everyone gets rich (including employees with equity)
- founders and investors get rich, nobody else gets shit
- investors get good return, founders get a bit, nobody else gets shit
- investors make mediocre return based on liquidation pref, nobody else gets shit
- nobody gets shit (but people keep their jobs in the acquirer)
In all but the first situation, you as an employee (even a high-up one) are basically being sold to another company without any upside, and whether or not you want to stay will depend 100% what you think about the acquirer.
So the acquirer will offer some golden handcuffs, usually some stock options with delayed vesting to motivate the acquired to stay.
Sometimes. Sometimes they're weirdly incompetent, treat everyone like shit, and then act surprised when half of the company leaves. Sometimes after that they'll offer a promise of a pittance bonus, and act surprised once again when yet another half of the company leaves after the meager bonus comes through.
Honestly that seems to be the norm in my, admittedly limited, experience.
General cost cutting without any other visible reasons. Cut backs on travel, social budgets, contractors, any other expenses that can be trimmed to make the financials look sexier.
Departments like Finance, Legal, Risk/Compliance and HR are overworked and distracted. These people, at least some of them, get involved after the execs but before everyone else. As someone else said this can start with the CFO but it'll spread to whole teams of paralegals and accountants before you are told about it.
Speaking of HR, do they suddenly want everyone to sign contract addendums or "compliance papers" or whatever? Asking you to fill out a "skills inventory"? Everyone got to get background checks?
Sales teams rushing to finish deals (to sexy up financials) and clear their comp (before the new boss brings new rules). I guess this isn't really that different from BAU.
As has been pointed out these things can all have other causes. But all together, all at the same time, without any stated reason....
Unfortunately ICs are often the least plugged in politically and end up the last to know. The compensation is being retained, unlike everyone else above who heard it through the grapevine before you.
Insider trading. It happens.
Unusual executive travel. The CEO, CFO and VP of Legal spending a week of "workshops with a customer" in Hong Kong?
- Unusual visitors to the office (or even having visitors at all!)
- Sudden shifts in roadmap priorities
- Sudden changes in interest or emphasis on reliability- A lack of guiding objectives and growth plans (which are vital in this particular industry)
- Major personnel change on the executive team. New exec had lead CIC events at several prior orgs.
- Complete re-organization of the development side of the business, with a focus on cost cutting and separation into separate divisions.
- Entirely new HR dept hired. More red tape and internal scrutiny.
- Increased political power consolidation within legal department, with several odd (politically motivated?) high level promotions there.
- Lack of internal promotion and compensation. Not replacing personnel who left because of this environment.
Any one of these wouldn’t be a red flag by itself, but all combined were a fairly clear indication.
Facts on the ground are always subject to change and you should be prepared:
1. Keep an up to date career document where you list all of your accomplishments in STAR format
2. Keep an up to date resume
3. Keep your skill set aligned with the market
4. Keep a strong and active network and guard your reputation
5. Don’t be a “ticket taker”. Be able to talk about initiatives you have led
6. Live below your means and have a 3-6 months emergency fund
7. Even though I haven’t and haven’t found a need to. “Grind leetcode” (tm r/cscareerquestions).
There has never been a day that I haven’t been ready to change jobs at a moments notice since 2008 (I’ve worked longer). This is true whether I was working for a startup or working at $BigTech and everything in between.
And even if you are at a company that realistically won’t be acquired, you should always be prepared to look for a job at a moment’s notice.
(I was a CISO. I absolutely would have told the company afterward so that they knew what happened and what to watch out for next time.)
Always, always. If it’s legit, the CEO will ask you to do that and then get back ASAP. Anyone who objects to you doing this is trying to screw you.
The new company made sweeping cuts and I for sure thought I was out of a job. Luckily, the IT team on both sides is small and I got to keep my job (3 years now).
It also helped that upper management of the new company made really terrible IT decisions (the director was fired about a year after the acquisition). We were supposed to convert our proprietary systems (that I maintain) to Net suite. The plan was terrible and crashed and burned.
They tried again last year, and we were successful.
Anecdotally, plenty of companies are still running their hiring pipeline even when someone - including HR - knows that they're about to be acquired, and nearly everyone who doesn't have a signed offer in hand (and sometimes, not even them) is going to be either completely ghosted, or get apologetic letters from a different company's HR department.
I’m a general python contractor. So far all of my clients have been acquired or had layoffs within a year of hiring me.
This might be UK specific because of how UK labour laws work.
While it can be fun to fantasize about what every little oddity means, I’d recommend against making this a priority in your daily life. If you find yourself that distracted from your work, it’s a good time to dust off your resume anyway, regardless of if M&A forces you to.
And changes in the work hours of execs