Client: a leading global reinsurance group and international insurer (name withheld under NDA)
The EU Digital Operational Resilience Act (DORA) sets one standard for digital resilience, but a global insurance group has to implement it separately in each of its legal entities. This is where regulation meets day-to-day governance practice.
The challenge
Operating across multiple legal entities globally, this client needed to align its ICT governance and risk practices with the EU Digital Operational Resilience Act (DORA), translating one regulatory framework into consistent, entity-level implementation.
Our role
Our CTO led the governance and ICT risk alignment workstreams across multiple legal entities, driving structured remediation of gaps in ICT governance, operational resilience, third-party risk, and incident management, while establishing governance, reporting, and escalation mechanisms for executive oversight.
Outcome
Improved control transparency, clearer accountability, and structured risk tracking, raising the group’s operational resilience maturity and supporting audit and supervisory readiness.