
Case Study · Insurance / M&A
Pre-transaction posture assessment of an insurance group
- 6 weeksassessment duration
- 4priority risk areas
- 90third parties reviewed
The challenge
An insurance group was preparing for a corporate transaction, and the board wanted an independent read of its security posture before coming to the table. The concern was not only technical: a weak posture or unmanaged third-party risk could surface during the counterparty’s due diligence and affect the perception of value.
The group worked with an extended ecosystem of intermediaries, service providers, and technology partners, with uneven visibility into the risk introduced by each. It needed a credible, defensible picture, understandable to a non-technical board.
My approach
I ran a posture assessment based on a recognised framework, covering governance, data protection, access management, resilience, and incident response capability. The approach was pragmatic: identify the risks that genuinely matter in a transaction context, not compile an exhaustive list of every possible weakness.
In parallel I analysed third-party risk, segmenting the ecosystem by criticality and focusing the deep dive on partners with access to sensitive data or a role in core processes. This made it possible to separate baseline risk from exposures that warranted immediate attention.
The output was delivered as a board roadmap: four priority areas, each with impact, effort, and timeline, so the board could decide what to address before the transaction and what to fold into the subsequent integration plan.
Related

