HanseMerkur unites data protection, information security, and its internal control system with NEXIS GRC
With NEXIS GRC, HanseMerkur built a comprehensive management system that brings data protection, information security, and the internal control system (ICS) together “all in one”. This maps BaFin’s supervisory IT requirements consistently, originally under VAIT and today under DORA.
About HanseMerkur
HanseMerkur is an independent, mid-sized insurance group headquartered in Hamburg. It offers insurance coverage for health, long-term care, life, risk and retirement provision, travel and leisure, property and accident, as well as supplementary company insurance.
As a mutual insurance association (Versicherungsverein auf Gegenseitigkeit), HanseMerkur is committed solely to its customers and employees, not to shareholders or investors. It is the only self-standing and group-independent insurance group at the Hamburg financial center that operates nationwide. The Hanseatic principle of the Honorable Merchant and the guiding idea “Hand in Hand ist HanseMerkur” shape the company culture and its clear stance toward legal requirements and internal rules.
- Location: Hamburg
- Legal form: Mutual insurance association
- Focus: Independent, mid-sized personal insurance
- Operations: Nationwide (Germany)
- Business lines: Health, long-term care, life, provision, travel and leisure, property and accident
With NEXIS GRC, HanseMerkur was able to
Combine data protection, information security, and the internal control system on one integrated platform.
Map IT strategy, IT governance, and information risk management in line with the supervisory specifications, from VAIT to today's DORA.
Steer, monitor, and advance the required measures along common international standards.
Assess, monitor, and evaluate confidentiality, integrity, availability, and data protection relevance.
Demonstrate responsible conduct through an unbroken historical record and continuous documentation.
Assess information security, data protection, and the ICS in one single assessment procedure.
The Challenge
- Map data protection under the EU GDPR fully integrated alongside the standard ISMS modules
- Establish a complete internal control system (ICS) as standard
- Enable cross-cutting views across all departments and processes
- Consolidate and evaluate data for information security risk management in a user-friendly, resource-saving way
- Gain a partner with many years of experience and references in large security and data protection projects
The Result
With NEXIS GRC, HanseMerkur has significantly more transparency about potential risks and their impact. The company develops appropriate measures to efficiently improve its maturity level across all requirements from data protection, information security, ICS controls, and the supervisory IT specifications (today DORA).
- Data protection, information security, and ICS in one system: “all in one” on an integrated platform
- Supervisory-compliant, from VAIT to DORA: The supervisory IT requirements are mapped and manageable
- More transparency about risks: Protection needs and risks are assessed, monitored, and steered efficiently
- Audit- and examination-proof: An unbroken historical record and continuous documentation for audits and BaFin examinations
- One assessment procedure for business departments: Information security, data protection, and the ICS assessed together
- Manageable maturity: Appropriate measures for the continuous advancement of the maturity level