Embedding Governance, Risk and Compliance into IT strategy: a strategic imperative

Written in collaboration with Carla Santos, a member of The Blog team.  As financial services continue to evolve, the need for innovative solutions has become paramount rather than a luxury. Yet, in their race to deliver cutting-edge digital services, financial institutions face a familiar tension: how to remain agile and …

Empowering banks through a business-led technological transformation

Leonard couldn’t lull himself into dreamland. His bedside clock kept reminding him of the unforgiving passage of time—it was now 5am—and he was getting more and more jittery. You see, later that day, his team would receive training on Artificial Intelligence (AI) and how to use it in their department. …

Cybersecurity Days: The five ideas that resonated the most with us

Recalling the saying, “It’s not a matter of ‘if,’ but a matter of ‘when’,”  when it comes to cybersecurity, isn’t pessimistic. On the contrary, it’s fairly realistic. Technology developments are a gale that is constantly changing not only how we live but also how we are. With great advancements come …

The GDPR, one year after

“Virtue is more feared than vice, because its excesses are not subject to regulation of conscience” stated Adam Smith. Aren’t laws, after all, trying to limit any potential excesses of our conscience? Innovation and regulation are bound to play the cat-and-mouse game. And you can easily figure who tries to …

What’s next? PwC tech leaders’ top trends for second half of 2026 

Welcome to this year’s July blog (always well read because people have more time). This summer we thought we would ask, what’s next for tech?   While many take a step back during the summer months, technology doesn’t slow down. In fact, innovation often accelerates quietly in the background, reshaping how businesses operate, …

CMDB isn’t dead – it’s the foundation of AI‑ready, regulator‑proof IT

When a critical service fails It is 9:42am on a Monday morning. A critical digital service at your company is unavailable. Within minutes, senior IT and business leaders are on a bridge call asking the same questions they always ask during a major incident: What changed? What is impacted? Who is responsible for this?  In many organisations, …

Threat-Led Penetration Testing: lessons from advanced cyber resilience exercises in the financial sector 

Threat-Led Penetration Testing (TLPT) has become one of the most advanced cyber resilience exercises conducted in the financial sector. With the entry into application of the Digital Operational Resilience Act (DORA) in January 2025, these exercises now form part of the regulatory framework for certain financial institutions across the European Union.  TLPT represents a …

Back to Top