Key Takeaways
- The sector has shifted from framework design to execution — the focus now is whether recovery arrangements function under real stress, not whether frameworks exist.
- Testing has become more severe and routinely includes joint exercises with third-party suppliers, often exceeding regulatory minimums.
- Regulatory convergence (DORA, the UK regime, MAS, and others) has unlocked budget and board attention, but is also driving firms toward consolidated internal frameworks to manage the added reporting burden.
- Structural reliance on a small number of critical third parties is being managed through oversight and joint exercising rather than diversification, while resilience is increasingly built into change governance and daily business operations.
The insurance sector’s approach to operational resilience has moved from framework design to execution. The defining questions are no longer whether firms have identified important business services or set impact tolerances — that work is largely done. What matters now is whether recovery arrangements function under stress, whether data supports decisions during disruption, and whether resilience holds across third parties as well as internal operations.
General practice reflects that shift. It also reflects a constraint practitioners raise consistently: the expectations reaching insurers have been shaped by practice in banking, and insurers work to them with materially smaller budgets. That constraint shapes prioritisation across the sector.
Testing and Exercising
Testing has become more severe. Firms run severe but plausible scenarios and, in some cases, go beyond them, including extended outages, full infrastructure loss, and bare-metal recovery, which often further than formal regulatory requirements demand. Joint exercises with third-party suppliers are now established practice, extending validation past the organisational boundary to the dependencies that determine actual recovery.
The work is resource-intensive: exercises are sometimes run outside office hours, and timing around seasonal peaks materially affects realism, so scheduling is deliberate. When teams exercise, they are frequently surprised by what they find:
- Untested assumptions
- Unclear ownership
- Recovery steps that don’t work as written
Surfacing those findings in a test rather than a live incident is the point — vulnerabilities can be closed in controlled conditions instead of under disruption.
The Regulatory Position
DORA is in force, the UK regime has passed its transition milestone, new operational incident and third-party reporting requirements are arriving, and international firms must reconcile these with other jurisdictions’ regimes, such as MAS requirements in Singapore. Regulation has unlocked board attention and budget that internal cases alone did not, and audit findings against newer requirements are directing investment to specific gaps.
It has also created cost. Firms report diverting resource from recovery itself to meet incident-reporting timelines; where a requirement is not explicit, funding is harder to secure; and concepts such as the minimum viable firm — which originated with the global systemically important banks before being taken up by regulators — are raised in supervisory conversations without formal definition, leaving firms to interpret expectations that aren’t yet written down.
The response has been consolidation rather than parallel compliance. Overlapping regimes are being mapped into single internal frameworks with common thresholds, shared language and more consistent reporting, which reduces duplication and the demand placed on the business. Some chief operating and risk officers are engaging regulators directly, using that dialogue to take their organisations beyond minimum compliance.
Third-Party and Concentration Risk
Reliance on cloud providers, technology vendors and outsourcing partners is structural, and concentration in a small number of hyperscale providers is a fact of the market rather than a procurement failure. Diversification carries real cost — one large migration between cloud providers ran to many millions — so the risk is managed through oversight rather than avoidance. That oversight includes:
- Tiered dependency mapping beyond direct suppliers to fourth parties and beyond
- Country and infrastructure risk profiling
- Contractual accountability, such as service credits and coverage of regulatory fines
- Direct supplier engagement, including, in some firms, dedicated supplier resilience summits
- Joint exercising with critical third parties
Where multiple insurers rely on the same critical third party, the need for a consistent, scalable assurance model is recognised across the market. Geopolitical exposure sits within the same discipline — conflict-related supply delays, civil unrest and physical security now feature in third-party and country risk assessment alongside technology failure.
Integration with the Business
Resilience is now being embedded in two places: how firms manage change, and the business itself. The first is change: operational resilience impact assessment is being built into project and change governance, so that resilience is considered at design rather than retrofitted. Dedicated resilience-by-design teams now exist in a number of firms, though the discipline remains further advanced in banking (in the largest banks it has reached executive level) a gap that marks out where insurer investment has yet to catch up.
The second is the business itself. Resilience delivered to the business rather than with it produces fatigue and weak engagement, and firms are working to close that gap: sustained frontline involvement rather than requests tied to testing cycles, escalation that carries incident learning beyond the team that experienced it, and board reporting framed in business impact rather than regulatory language.
Remaining Gaps
The picture is not complete, and the gaps are broader than any one discipline:
- Definitions are still settling, firms are working through what “intolerable harm” means in practice and how thresholds should move as new regulation lands
- Risk language is inconsistent; the three lines of defence often describe the same exposure differently, and with every business unit regarding itself as critical, prioritisation is harder than it should be
- Risk data remains fragmented within many firms; a single source of truth is still an aspiration rather than a fact
- In parts of the market, third-party risk management runs on small teams and manual tools, and AI adoption is raising governance and oversight questions faster than frameworks are adapting
These are the sector’s own findings.
The Overall Position
The foundational work, including identifying important business services, setting impact tolerances, building frameworks, is largely done, and firms are now running resilience as an operating discipline: testing against severe scenarios, exercising jointly with suppliers, consolidating regulatory regimes into single internal frameworks, and building resilience into change and governance.
They do so on smaller budgets than the banks where much of this practice originated, which makes disciplined prioritisation a permanent feature of the job. The direction of effort is consistent across the market — from documentation to demonstrated capability, from supplier oversight to ecosystem resilience, from compliance-driven activity to resilience by design — and the remaining work concentrates on known ground.