Independent Review of IT and Security
Kristensson was engaged by a semi-governmental organization in the insurance sector to conduct an independent review of their outsourced IT operations.
Kristensson was engaged by a semi-governmental organization in the insurance sector to conduct an independent review of their outsourced IT operations. The client had several strategic and regulated services managed by external suppliers, and sought a third-party assessment of how these operations were governed and delivered from an IT and information security perspective.
Our consultants performed a structured review, covering areas such as contractual responsibilities, operational maturity, compliance with security frameworks, and alignment with internal policies. This included document analysis, interviews, and technical review sessions with both the client and its suppliers. We assessed whether critical functions were being delivered in a secure and resilient way, and identified potential gaps in governance, risk management and supplier oversight.
The result was a set of clear, actionable recommendations to improve control, reduce risk, and clarify roles between client and supplier. The review provided valuable assurance to internal stakeholders and served as a foundation for future improvements in third-party management.
In brief
- Challenge
- Strategic and regulated services were run by external providers, and the customer needed an independent assessment of governance and delivery from an IT and information security perspective.
- What we did
- Structured review of contractual responsibility, operational maturity, compliance with security frameworks and internal policies, through document analysis, interviews and technical walkthroughs with the customer and its providers.
- Result
- Clear, actionable recommendations for stronger control, lower risk and clarified roles, and assurance for internal stakeholders as a basis for further improvement.
Want to know what a similar engagement would look like for you?
Contact us