Context
As part of its IT transformation and in response to increasing regulatory requirements related to cybersecurity and operational resilience, a leading insurance company launched several initiatives to strengthen its IT risk governance. This effort is driven in particular by the upcoming enforcement of the European DORA (Digital Operational Resilience Act) regulation, requiring financial institutions to enhance their management of technology and cybersecurity risks. To support this transition, the client relied on Avaliance to structure risk monitoring, manage remediation plans, and progressively align internal processes with regulatory requirements and security standards.
Challenges
The client needed to improve control over IT risks and strengthen cybersecurity governance to reduce operational risk and ensure regulatory compliance.
Key challenges included maintaining and managing the risk register, ensuring effective implementation of remediation plans, aligning progressively with DORA requirements, and engaging business teams in a sustainable approach to security and operational resilience.

Achievements
-
maintenance and management of the risk register and tracking remediation plans
-
formalization of internal security processes and compliance alignment for process owners
-
preparation of annual security testing and internal control campaigns (process and evidence collection)
-
monitoring of remediation plans resulting from control campaigns and security audits
-
support in implementing and aligning with DORA regulatory requirements
Core Focus Areas
Results
Context
In a context of strengthening its cybersecurity posture and increasing risks linked to digital threats, an international player in the infrastructure and energy sector launched several initiatives aimed at improving security governance and vulnerability management across its critical IT environments.
To support this initiative, Avaliance worked in support of the CISO, with a cross-functional role covering vulnerability tracking, coordination of security audits, incident management and the management of cybersecurity performance indicators.
Key challenges
The client needed to improve its ability to detect and remediate cyber threats while strengthening the integration of security into its IT projects.
The challenges focused on reducing the number of critical vulnerabilities, improving responsiveness to security incidents, ensuring the reliability of cybersecurity indicators (KPIs), and structuring robust technical governance around CISO activities.
Achievements
-
management and monitoring of vulnerabilities identified on critical systems and applications,
-
contribution to the integration of cybersecurity requirements into IT projects,
-
management and coordination of technical security audits, including risk analyses and recommendations,
-
improvement and monitoring of key cybersecurity performance indicators,
-
supervision of patch management activities across critical environments,
-
management and coordination of security incidents and associated remediation actions.
Technologies used
Results
Context
As part of its IT transformation and in response to increasing security requirements related to payment activities, a financial infrastructure player launched an initiative to strengthen governance and resilience of its network environments. Within the scope of PCI DSS compliance, the client engaged Avaliance to conduct a comprehensive audit of its network and security infrastructures across multiple datacenters. The objective was to assess the existing architecture (MPLS, VXLAN, and security devices), identify improvement areas, and recommend solutions to optimize operational management and security governance.
Challenges
The client needed a clear and structured view of its network infrastructure to ensure service continuity and meet strict PCI DSS compliance requirements.
Key challenges included improving network architecture resilience, ensuring consistency of security rules, enhancing the management of operational (MCO) and security (MCS) activities, and addressing the lack of a centralized framework for firewall rule management across multi-datacenter environments.

Achievements
-
audit of network and security infrastructures across multiple datacenters, including MPLS and VXLAN analysis
-
assessment of operational practices related to MCO and MCS to identify improvement areas in resilience
-
formulation of recommendations to simplify and strengthen the global network architecture
-
definition of an approach to automate and centralize security rule management through a unified console
Technologies & Standards
Results
Context
As part of its IT transformation, a leading European transportation player launched several initiatives to improve service quality, modernize infrastructures, and optimize internal processes. The mission entrusted to Avaliance combined operational IT service management, client and vendor coordination, and contribution to several strategic projects such as infrastructure migrations, financial reconciliation programs, and internal tool automation.
Challenges
The client needed to maintain a high level of service quality while simultaneously delivering multiple critical technical projects.
Key challenges included meeting SLA/OLA commitments, improving coordination between internal and external stakeholders, ensuring the success of infrastructure and business tool migrations, and optimizing and automating internal processes.

Achievements
-
management of incidents, service requests, and problems, and service transition follow-up
-
facilitation of meetings with clients and vendors and production of SLA monitoring dashboards
-
contribution to a financial reconciliation project and datacenter migration covering networks and virtualization
-
participation in B2B/B2C reservation system migration projects for European operators
-
development of internal dashboard tools (PHP/MySQL) and billing automation (VBA)
Technologies & Tools
Results
Context
As part of its IT modernization strategy, a national public administration launched several initiatives to strengthen IT production governance and improve coordination between the central IT department and regional entities. The program included the implementation of a Single Point of Contact (SPOC) for incident and service request management, as well as the deployment of a nationwide videoconferencing infrastructure covering the entire territory, including overseas regions. To secure these transformations and ensure coordination between local teams, service providers, and vendors, the client relied on Avaliance to manage projects, structure support processes, and lead change management at a national scale.
Challenges
The client needed to industrialize incident and service request management while improving communication between the central IT department and decentralized teams across the country.
Key challenges included implementing a unified and shared SPOC, harmonizing request processes for over 200 local IT staff, successfully delivering a nationwide videoconferencing rollout, and supporting change adoption among technical and business teams.

Achievements
-
implementation of a Production SPOC centralizing incidents and requests through a unified entry point
-
national coordination of over 200 local IT staff across decentralized entities and overseas regions
-
operational interface with managed service providers to improve support processes and resolution times
-
management of the nationwide videoconferencing rollout coordinating approximately 100 endpoints
-
change management support to ensure adoption of new processes and audio-video technical standards
Core Focus Areas
Results
Context
As part of its IT transformation and business process digitalization, the client launched several initiatives to modernize internal services and automate operations related to insurance contract management. These initiatives rely on two key applications: C-Services, a REST API platform designed to dematerialize commercial offerings and management operations, and C-URSA, a web application used by operators to manage financial, commercial, and post-sales activities. To support these projects and ensure the secure delivery of critical features, the client relied on Avaliance to design, develop, and integrate both front-end and back-end components within an Agile Scrum environment.
Challenges
The client needed to accelerate the digitalization of its business operations while ensuring the reliability of financial workflows and the quality of applications delivered to operational teams.
Key challenges included automating management processes (subscription, redemption, payments, arbitrage), improving document management, enhancing user experience, and strengthening software quality through rigorous unit and integration testing.

Achievements
-
design and development of C-Services REST APIs for core operations (subscription, redemption, payments, arbitrage)
-
development of web services for CRM, document management, and implementation of unit/integration testing
-
design of C-URSA application features, including authentication modules, user interfaces, and dashboards
-
implementation of end-to-end financial workflows (consultation, tracking, control, validation)
-
development of a document management module and participation in Agile Scrum ceremonies
Technologies & Frameworks
Results
Context
The client launched an initiative to strengthen the quality, reliability, and industrialization of its application development processes. This program relies on a continuous integration platform and shared technical foundations used across all group applications. To structure these technical foundations, enhance development tools, and ensure consistency of practices across internal teams and international service centers, the client relied on Avaliance to define technical standards, evolve the CI platform, and support teams in their adoption.
Challenges
The client needed to improve the reliability of its continuous integration platform while harmonizing the technical foundations used across applications.
Key challenges included enhancing code quality, improving application performance, introducing new technologies, standardizing frameworks, and aligning development practices between internal teams and international maintenance teams.

Achievements
-
administration and evolution of the CI platform based on GitLab, Jenkins, Nexus, and Sonar
-
design and maintenance of shared application foundations for Java Web, Java Batch, and Angular
-
development of cross-functional frameworks and Maven plugins to standardize development practices
-
facilitation of code audits, application performance optimization, and technical proofs of concept
-
technical support and training on Java, Spring Boot, and Git for internal and international teams
Technologies & Tools
Results
Context
The client launched a strategic initiative to modernize its software engineering practices, industrialize deployments, and harmonize its application technology stack. This cross-functional program covered software architecture, technical governance, DevOps adoption, Cloud industrialization, and the implementation of microservices architectures. To drive this transformation and ensure overall technical consistency, the client relied on Avaliance to define standards, coordinate teams, and support the evolution of development practices.
Challenges
The client needed to transform its development and deployment practices to improve reliability, accelerate delivery cycles, and enhance software quality.
Key challenges included harmonizing technical foundations, securing application architectures, adopting modern tooling, industrializing Cloud deployments, transitioning to Git-based workflows, and defining shared patterns across applications and frameworks.

Achievements
-
structuring and leading a cross-functional team of technical experts and establishing architecture governance
-
supporting DevOps adoption, leading change management, and industrializing Cloud deployments
-
designing microservices architectures and evolving CI/CD platforms (GitLab, Jenkins, Nexus, Sonar)
-
defining shared application foundations and cross-functional frameworks (Java, Batch, Angular)
-
providing technical support to internal development teams and international service centers
Technologies & Ecosystem
Results
Context
The client launched several application initiatives requiring a robust, scalable software architecture aligned with group technology standards. These projects involved high technical expectations, close collaboration between development teams, and precise delivery management within an Agile environment. To secure technical decisions and ensure overall consistency of the solutions, the client relied on Avaliance to structure the application architecture, guide technical teams, and ensure reliable delivery.
Challenges
The client needed to design application architectures capable of supporting increasing workloads while ensuring code quality and maintainability.
Key challenges included defining technical standards, supporting development teams, streamlining delivery cycles, managing technical risks, and establishing sustainable software engineering practices across the project scope.

Achievements
-
design of application technical architecture and definition of technology choices and frameworks
-
technical guidance of teams and resolution of complex issues during implementation
-
contribution to both front-end and back-end development to secure critical features
-
structuring development practices to improve long-term software quality
-
facilitation of Agile rituals including planning, grooming, demos, and sprint follow-up
Technologies & Agility
Results
Context
The client initiated the modernization of its application environment dedicated to securitization operations, historically based on a legacy system that had become obsolete. This strategic evolution aimed to meet increasing requirements in terms of performance, reliability, and regulatory compliance, while ensuring continuity of critical financial processes. To secure this transformation and design a robust target solution, the client relied on Avaliance to develop a new application capable of replacing the existing system while aligning with modern technology standards.
Challenges
The client needed to modernize its securitization system while minimizing operational risks associated with the legacy solution.
Key challenges included ensuring regulatory compliance, maintaining the accuracy and reliability of financial calculations, improving transparency of operations, enhancing processing performance, and building a scalable and secure system capable of supporting market activities.

Achievements
-
design and development of a new securitization application to replace the legacy system
-
implementation of a modern and scalable application architecture
-
securing financial processing, data flows, and robustness of calculations
-
improving overall system performance to meet high-volume market activity needs
-
supporting the transition from legacy environments to the new solution with minimal risk