THE CONTEXT
Aggressive
Multi-Continental Expansion
pivot in its core business
revenue model
strategic consolidation
via merger & acquisiton
portfolio company
Problem statement
An international payments provider and its technology investor requested support for an IT and Security Risk assessment to assess its technical set-up and potential risks stemming from its regional set-up and operating model
our approach
This engagement focused on fact-finding only, meaning the focus was on a four week assessment and presenting observations to the global managing board. The engagement was scoped so to not provide implementation services following the assessment.
The assessment drew a picture of the IT landscape, generated overview of agreements related to systems and applications, and mapped systems and applications to the business value chain. As the payment provider followed a multi-continental acquisition strategy, generating high level insights into global architecture, capabilities and agreements between entities was foundation to generating insights and providing observations and recommendations.
Together with the client’s deal team we conducted the assessment across five geographic regions. Based on interviews with key people, we provided insights into various capabilities. Considering the limited time against an extensive geographic and capability scope, the assessment was considered to ‘scratch the surface’.
THE RESULT
The assessment created a common, high-level understanding of the global technology set-up of the company. We provided insights on risks based on confidentiality, integrity and availability of systems. Furthermore, we provided a common framework to understand and measure effectiveness of business capabilities, business functionality, and third party services. This understanding helped create a basis for the global risk team and the investor to talk to individual geographic regions and subsequently streamline services.