Skip to main contentSkip to footer

The Challenge

A global Marine Insurer faced increasing regulatory scrutiny, intensified by UK regulatory expectations and post-DORA requirements mandating demonstrable ICT resilience.

The organisation lacked a scalable, integrated Enterprise Resilience (ER) capability to centrally govern cyber resilience, crisis management, third-party risk, and regulatory mapping of critical services and assets. Without measurable evidence of resilience and clearly defined governance, the firm was exposed to both operational disruption and regulatory censure.

Our Approach

Partnering with the Head of Enterprise Resilience and sponsored by the Group COO (SMF24), we designed and operationalised a proportionate, integrated First Line of Defence (1LoD) ER capability.

Key elements included:

  • Development of a structured ER Capability Model
  • Integration of interdependent resilience domains into a cohesive framework
  • Refresh of ER governance, including Terms of Reference and RACI matrices
  • Clear definition of roles, responsibilities, and accountabilities
  • Alignment to regulatory expectations, including measurable and reportable ICT risk under DORA

All work was delivered proportionately to the organisation’s size and risk profile, leveraging existing artefacts where possible to ensure practicality and sustainability.

The Outcome

  • Reorganised and matured Enterprise Resilience function
  • Fully defined ER Capability Model
  • Strengthened governance framework and accountability structures
  • Enhanced regulatory readiness and demonstrable ICT resilience
  • Reduced operational and regulatory risk exposure

The client now operates with a scalable, integrated Enterprise Resilience capability that supports business continuity, regulatory confidence, and sustainable application of resiliency practices across jurisdictions.

Testimonials