A collaborative and valuable engagement. Stratiformis helped break down a complex regulatory subject matter into clear, actionable plans and business outcomes, and supported the end-to-end shaping and implementation of the program over 18 months. Having a trusted advisor and SME alongside our team meant a more efficient and focused delivery overall.
The Challenge
A global Marine Insurer faced increasing regulatory scrutiny, intensified by UK regulatory expectations and post-DORA requirements mandating demonstrable ICT resilience.
The organisation lacked a scalable, integrated Enterprise Resilience (ER) capability to centrally govern cyber resilience, crisis management, third-party risk, and regulatory mapping of critical services and assets. Without measurable evidence of resilience and clearly defined governance, the firm was exposed to both operational disruption and regulatory censure.
Our Approach
Partnering with the Head of Enterprise Resilience and sponsored by the Group COO (SMF24), we designed and operationalised a proportionate, integrated First Line of Defence (1LoD) ER capability.
Key elements included:
- Development of a structured ER Capability Model
- Integration of interdependent resilience domains into a cohesive framework
- Refresh of ER governance, including Terms of Reference and RACI matrices
- Clear definition of roles, responsibilities, and accountabilities
- Alignment to regulatory expectations, including measurable and reportable ICT risk under DORA
All work was delivered proportionately to the organisation’s size and risk profile, leveraging existing artefacts where possible to ensure practicality and sustainability.
The Outcome
- Reorganised and matured Enterprise Resilience function
- Fully defined ER Capability Model
- Strengthened governance framework and accountability structures
- Enhanced regulatory readiness and demonstrable ICT resilience
- Reduced operational and regulatory risk exposure
The client now operates with a scalable, integrated Enterprise Resilience capability that supports business continuity, regulatory confidence, and sustainable application of resiliency practices across jurisdictions.