Cloud and Resilience Transformation for a UK Composite Insurer
The Challenge
A UK composite insurer was operating critical policy administration and claims platforms on ageing on-premise infrastructure with several end-of-support components. Two recent operational incidents had attracted attention from the PRA's operational resilience supervisors, and the insurer's important business services had not yet been mapped to impact tolerances in line with PS21/3 expectations. The technology estate had grown organically over a decade of acquisitions, with overlapping platforms, undocumented integrations and a shrinking pool of engineers familiar with the legacy stack. The board had approved a multi-year cloud transformation but the previous attempt had stalled after twelve months with limited migration progress and rising hosting costs across both old and new estates. The CIO needed a credible, regulator-defensible plan that combined operational resilience uplift with cloud migration, sequenced to deliver risk reduction quickly rather than waiting for the end of a multi-year programme.
The Solution
Intology was appointed to lead the combined cloud and resilience transformation, reporting to the CIO and Operational Resilience Director. We started by mapping the insurer's important business services end-to-end, agreeing impact tolerances with the executive committee and producing an evidenced view of where current service performance breached those tolerances. The migration roadmap was re-sequenced around resilience risk rather than ease of migration, with the highest-risk legacy components prioritised even where they were technically harder to move. A single landing zone was established on the chosen cloud platform with embedded controls aligned to the insurer's regulatory obligations, removing the per-application security debate that had slowed the previous attempt. Application migrations were delivered in fixed-cost, fixed-scope waves with clear exit criteria, including hosting cost decommissioning evidence before each wave was declared complete. A scenario-testing programme was stood up to evidence resilience improvements to the regulator on a continuous basis rather than as an annual exercise.
Key Outcomes
- All in-scope important business services mapped and operating within agreed impact tolerances within 14 months
- 62 percent of legacy applications migrated to cloud across the first two delivery waves with measurable resilience uplift
- Combined hosting cost across legacy and cloud estates reduced for the first time in five years following disciplined decommissioning gates
- Two further operational incidents in the year following kick-off contained within tolerance and resolved without regulatory escalation
- Regulator engagement materially improved through evidenced, scenario-tested resilience reporting