By Nina Bjerregaard, Head of Operations & Compliance, Process Factory
Security, resilience and compliance have long been fundamental priorities across the insurance industry. This reflects both the critical role insurers play in society and their reliance on digital infrastructure.
Yet the requirements and challenges facing the industry are changing.
Cyber threats are becoming increasingly sophisticated, while geopolitical tensions continue to affect global digital supply chains. New regulatory requirements are raising expectations around documentation, governance and operational resilience. Meanwhile, organisation are under growing pressure to accelerate innovation through data, autamation and AI. The World Economic Forum identifies the convergence of AI, cyber risk and geopolitical uncertainty as one of the defining characteristics of today’s threat environment.
94% of respondents expect AI to be the most significant driver of change in cybersecurity in the years ahead.
This does not necessarily indicate increased infrastructure vulnerability. It reflects a significant rise in the expectations placed on modern infrastructure.
From Systems to Interconnections
Historically, resilience has often been associated with individual systems: Are they stable, secure and scalable?
Those questions remain important.
Today, most business processes rely on data flowing across platforms, providers and organisational boundaries. Value no longer resides within individual systems alone, but in the way they work together.
As a result, regulatory frameworks are increasingly focused on operational resilience, third-party dependencies and end-to-end visibility across digital value chains.
According to Deloitte’s 2026 European DORA survey, financial insitutions continue to invest in stronger third-party governance, operational resilience testing and greater visibility across their supply chains. Notably, none of the organisations surveyed have full end-to-end visibility across their supply chains. McKinsey similarly describes DORA as a comprehensive European framework for digital operational resilience, imposing requirements on both financial institutions and critical ICT service providers.
Integrations are not inherently a source of risk. Risk arises from how they are implemented, documented, monitored and governed.
The Question Is Not How Many, But How
The growing adoption of digital services, AI solutions, new data sources and partner ecosystems is creating an increasing need for connectivity across systems and business processes. As a result, the risks associated with integrations are receiving greater attention.
When security, documentation, monitoring and governance are built into the design, integrations become an active component of operational resilience. This requires organisations to move beyond treating integrations as projects that can be added to a backlog and completed once and for all. They must be recognised as a strategic capability.
As AI continues to expand into business-critical processes, these considerations become even more important. According to the World Economic Forum, AI is both enhancing cyber defence capabilities and enabling more sophisticated attacks, making it essential for organisations to balance innovation with security.
Integrations as a Service: Reducing Operational Risk
We believe Integration as a Service is far more than a technical delivery model.
The underlying principle is simple: integrations should serve a purpose beyond connecting systems.
The goal is to establish integrations in a way that reduces operational risk and creates greater control over complexity by embedding struture, governance and security from day one.
A shared, standardised integration foundation provides greater visibility, stronger governance and improved control. It enables organisations to support business processes more efficiently and respond to new requirements with greater agility. Security and compliance are built into the solution from the outset, rather than being repeatedly addressed and documented for each individual project.
It makes governance and control easier to operationalise. More importantly, it enables organisations to pursue new business initatives without complexity and risk scaling alongside their ambitions.
The Intersection of Technology, Operations and Compliance
The value of bringing technology, operations and compliance together extends far beyond internal processes. It lies in transforming requirements, governance and security into solutions that perfom reliably in real-world operational environments.
As Head of Operations & Compliance, my role is to bridge regulatory requirements, technology and operations, ensuring that these principles are embedded in how solutions are designed and managed.
With resilience requirements continuing to grow, the ability to operationalise compliance is becoming an increasingly important competitive advantage, both for us and for our customers.
Operational Resilience: What Comes Next
The insurance industry has already made considerable progress in strengthening its digital foundations.
Operational resilience is already firmly established as a a priority across the insurance industry. The next step is to ensure that innovation, automation and new technologies can be adopted without adding unnecessary complexity or risk.
We believe the answer lies in the way infrastructure is architected and managed.
Operational resilience depends on a flexible infrastructure. Achieving this requires organisations to treat integrations as a strategic capability, with structure, governance and security built in from the start.






