2015 to 2016
M&A

Stop the Bleeding, Then Build to Scale

Regional & National Banks
The Challenge

A merger doubled the bank and fused two technology estates

The merger doubled the bank’s scale and inherited the operational consequences of fusing two technology estates built independently. At the point of engagement the environment was unstable and high-risk: frequent severity-one outages with real customer, employee, and brand impact, inadequate failover, and an IT organization without the capacity to resolve incidents, finish the post-merger transition, and handle business-as-usual demand at the same time. Endurance Advisory was engaged by the chief operating officer, initially to assess and stabilize technology and support strategic and cybersecurity planning. Over roughly eight months the mandate broadened into a full enterprise risk, risk appetite, and acquisition-policy build.

How the environment was stabilized
  • Sequence recovery before transformation. An organization without spare capacity cannot transform.
  • A merger is not finished when the deal closes. The operational consequences arrive afterward.
  • Rank remediation by achievability, not just by severity. A ranked roadmap beats an exhaustive findings list.
  • Turn acquisition into a capability with a policy, named teams, and defined Legal Day One decisions.
  • Ran a three-phase plan: a 30-day change-management lockdown to stop the bleeding, a 90-day consolidation phase, and a six-to-nine-month phase to build a scalable platform.
  • Drove down the full findings backlog across internal audit, SOX, penetration testing, business continuity, and the regulatory cybersecurity self-assessment under a weekly-tracked program.
  • Mapped cybersecurity maturity against the FFIEC framework and ranked each gap by how achievable a remediated state was, turning a self-assessment full of negative answers into a ranked roadmap.
  • Rebuilt the IT and information-security policy suite, designed a board-level Enterprise Risk Committee, and authored a Statement of Risk Appetite spanning nine risk categories.
  • Built an acquisition due-diligence and integration policy with function-by-function teams and defined Legal Day One decisions, turning M&A from an event the bank survives into a capability it operates.
THE PROCESS

Recover capacity before attempting transformation

EAP staffed a small rapid-response team and sequenced the work so the organization could recover capacity before attempting transformation.

What the engagement covered

30-day change lockdown, 90-day consolidation, audit and cybersecurity backlog reduction, FFIEC maturity mapping, IT and security policy rebuild, risk appetite statement, M&A integration policy

What changed in eight months

Day phasing from lockdown to scalable platform

Outcomes

What changed in eight months

Day phasing from lockdown to scalable platform

A 30-day change-management lockdown stopped the bleeding, a 90-day consolidation phase followed, then a six-to-nine-month build.

Risk appetite statement authored

A board-level Enterprise Risk Committee was designed and a Statement of Risk Appetite spanning nine risk categories was authored.

Weekly-tracked remediation

Findings across internal audit, SOX, penetration testing, business continuity, and the regulatory cybersecurity self-assessment were driven down under a weekly cadence.

Not a recurring emergency

An acquisition due-diligence and integration policy with function-by-function teams and defined Legal Day One decisions replaced ad hoc integration.

THE SOLUTION

A governed platform and a repeatable acquisition capability

The environment stabilized as change discipline, daily stand-ups, and a corrective-action process took hold. The audit and cybersecurity backlog came down under a weekly cadence. A board-level risk structure and a nine-category risk appetite statement were established and operating. The bank moved from reacting to outages to operating a governed platform with a repeatable approach to its next acquisition.

Most IT instability is a governance problem wearing a technology costume The outage logs described a technology problem. The real problem was governance. Nearly every severity-one event traced not to a hardware limitation but to a process gap: a change made during business hours, a vendor change that was never vetted, a configuration that was never documented. The hardware was capable and current. What it lacked was the discipline to operate it.

Banks working through post-merger integration, institutions with a large unresolved audit or cybersecurity findings backlog, and acquirers who want M&A to be a repeatable capability rather than a recurring emergency.

The Approach

Recover capacity before attempting transformation

EAP staffed a small rapid-response team and sequenced the work so the organization could recover capacity before attempting transformation.

Outcomes

What changed in eight months

Day phasing from lockdown to scalable platform

A 30-day change-management lockdown stopped the bleeding, a 90-day consolidation phase followed, then a six-to-nine-month build.

Risk appetite statement authored

A board-level Enterprise Risk Committee was designed and a Statement of Risk Appetite spanning nine risk categories was authored.

Weekly-tracked remediation

Findings across internal audit, SOX, penetration testing, business continuity, and the regulatory cybersecurity self-assessment were driven down under a weekly cadence.

Not a recurring emergency

An acquisition due-diligence and integration policy with function-by-function teams and defined Legal Day One decisions replaced ad hoc integration.

Get Started

Put these insights to work.

Tak through what you are reading with the practitioners who wrote it.