MidMarketNow
Get the Weekly

Strategic Management Partners buys 60% of Gesta

#Strategic Management Partners#Gesta#GRC#cybersecurity consulting#NIS2 Italy
By MarcusAI-generated3 min read

Deal at a glance

Type
acquisition · Other
Enterprise value
—
Original amount
—
Target
Gesta
Acquirer
Strategic Management Partners
Investor
—
Sector
Technology
Region
—
Announced
6 Oct 2023

Deal-ID: MMN-001082

Key facts

Buyer
Strategic Management Partners
Target
Gesta
Sector
Technology
Geography
—
Deal volume
—
Date
6 Oct 2023

Strategic Management Partners (SMP) is using M&A to assemble a broader cybersecurity and risk advisory platform. Its acquisition of a 60% stake in Italian consultancy Gesta positions the target as the group’s governance, risk and compliance (GRC) hub, extending SMP’s IT-security and strategic-consulting footprint as regulation tightens across Europe.

Terms were not disclosed.

Deal snapshot

  • Buyer: Strategic Management Partners
  • Target: Gesta (Italy)
  • Stake acquired: 60%
  • Type: Acquisition
  • Date announced: 6 October 2023

Why this deal, why now

SMP is explicitly framing the transaction as part of an expansion and internationalization plan. The group has been active on the acquisition trail, with prior deals for Peekaboo, BF Partners and Core, and has opened offices in Poland and Spain. Adding Gesta is consistent with a platform build that aims to cover more of the compliance-heavy cybersecurity stack, not just technical security delivery.

The timing also matters. The EU’s NIS2 regime raises the bar on cybersecurity risk management, reporting, supervision and enforcement for critical sectors. Italy has transposed NIS2 through Legislative Decree 138/2024, effective 16 October 2024, and the directive assigns accountability for cybersecurity compliance to management bodies. That shift tends to pull demand toward firms that can bridge board-level governance with operational controls, audit readiness and certification.

Strategic logic: a GRC control tower inside a cyber platform

According to available coverage, SMP is combining:

  • Gesta: GRC, cybersecurity, privacy and certification expertise, with an explicit specialization in AI governance alongside organizational models and risk management.
  • SMP: IT-security and strategic-consulting capabilities.

The key strategic move is organizational, not just commercial: Gesta is being positioned as the group’s GRC coordination hub, supporting Italian and international activities. At the same time, Gesta’s headquarters and local units are expected to continue operating with existing governance and operational autonomy.

This “hub-and-spoke” model can work in advisory-led sectors where client relationships and delivery talent are local, but methodology, tooling and quality assurance need central direction. The open question is how quickly SMP can standardize playbooks across privacy, cybersecurity governance, certification and risk management without slowing down delivery.

Sector exposure: regulation-intensive verticals

Gesta is positioned to serve specialized, compliance-heavy sectors including defense, nautical, logistics and mechanical industries. If SMP can use the acquisition to deepen vertical credibility, it may be able to win larger, multi-service mandates where governance, risk, privacy and security controls are bundled.

Market growth is supportive. One forecast projects the Italian cybersecurity market to expand from $5.72 billion in 2025 to $9.68 billion in 2030 (an implied 11.1% CAGR). While forecasts vary, the direction is clear: spend is rising, and regulatory compliance is becoming a board-level issue.

Integration focus: autonomy promised, coordination required

SMP’s decision to preserve Gesta’s operational autonomy reduces near-term disruption risk, but it does not remove integration work. Key execution questions include:

  • Operating model: How will the GRC hub mandate be enforced across acquired entities, especially if delivery teams use different frameworks, tooling and reporting formats?
  • Leadership depth: Whether Gesta has the bench to act as a group-wide standards-setter while continuing to serve its own client base.
  • Go-to-market overlap: How SMP will avoid internal competition between cybersecurity delivery and advisory-led governance work, while creating a coherent cross-sell motion.
  • AI governance positioning: Gesta is specialized in AI governance, but available coverage does not establish it as a specific acquisition driver. SMP will need to decide whether to productize this capability or keep it as an expert-led niche offer.

What to watch next

  • Whether SMP announces a unified GRC methodology and toolchain anchored by Gesta.
  • Early evidence of cross-selling between SMP’s IT-security services and Gesta’s governance, privacy and certification work.
  • Client demand tied to NIS2 implementation in Italy ahead of the October 2024 effective date.
  • Further bolt-on acquisitions as SMP continues its internationalization push in Europe.

Companies & investors in this story

More in this sector

We use privacy-respecting product analytics to understand how readers use MidMarketNow and improve it. No personal data (email, IP) is sent. See our privacy policy.