Insurance has a distinctive risk profile: it manages some of the most sensitive personal data (including health data), and policy and claims processing relies heavily on external suppliers and platforms. The supervisor (EIOPA) and DORA therefore require a serious level of security, operational resilience and, above all, supply chain control — exactly where an incident at a supplier becomes the insurer’s incident.
What we cover
- EIOPA requirements for ICT security and governance
- Third-party and outsourcing risk management, with contractual clauses and audit rights
- Operational resilience (DORA) and business continuity for critical processes
- Protection of sensitive policyholder data, at rest and in transit
How we work and what you get
Gap analysis → control testing → evidence → report suitable for the supervisor, with a remediation roadmap. You receive the gap analysis aligned to EIOPA / DORA, the ICT third-party risk assessment and a prioritised roadmap.