Migration of Virtual Workloads
Between Data Centers —
Demerger-Driven, IRDA Compliant
A top general and life insurance company separated from its global parent — and with that demerger came a non-negotiable IRDA requirement: isolate every IT workload into India-based infrastructure under the company’s own governance. Softenger migrated 250+ VMs and 12 physical servers from Singapore and India data centers to new India-based facilities, solving a 250 Mbps bandwidth constraint with physical tape.
Virtual Workload Migration —Insurance Demerger, IRDA Compliance
A demerger created a
compliance deadline — IT had to move
When a top insurance company separates from its global parent, the operational consequences extend well beyond the corporate structure. The Insurance Regulatory and Development Authority of India (IRDA) requires that insurance companies maintain IT infrastructure within India under their own governance — not shared with or managed by a global entity they no longer belong to. A demerger, in other words, triggers a mandatory IT migration with a compliance clock attached.
The company’s IT workloads were running on globally managed data centers in Singapore and India — infrastructure that was now, post-demerger, legally impermissible to continue operating on. Every virtual machine, every physical server, every network dependency had to be extracted from the global entity’s environment and reestablished in new India-based facilities under the demerged company’s own control — all while the business continued operating normally.
Isolate IT infrastructure to comply with IRDA regulations following demerger. Migrate 250+ virtual machines and 12 physical servers from Singapore and India-based data centers to new India-based facilities — maintaining disaster recovery readiness, implementing mobile device management, and ensuring zero disruption to insurance operations throughout.
IRDA Regulatory Compliance — Mandatory IT Isolation
IRDA regulations required full isolation of the insurance company’s IT infrastructure from the global parent entity — workloads could not remain on globally managed infrastructure post-demerger. Compliance had a deadline; non-compliance carried penalties.
IRDA · Regulatory · Compliance Deadline250+ VMs and 12 Physical Servers — Minimal Business Downtime
The full virtual and physical server estate had to migrate from Singapore and India DCs to new Pune and Bangalore facilities. Insurance operations could not tolerate significant downtime — customer-facing applications had to remain available throughout.
VM Migration · Physical Servers · Business ContinuityDR Readiness for Customer-Centric Applications
Post-migration, the new India-based infrastructure had to be configured for disaster recovery — VMware SRM implemented and DR drills conducted to confirm that customer-facing applications could failover reliably in the event of a site incident.
VMware SRM · DR Drills · Business ContinuityMobile Device Management for 300+ iOS Devices
The mobile workforce — 300+ iOS devices previously managed under the global entity’s MDM infrastructure — needed to transition to a standalone MDM solution under the demerged company’s governance. IBM MaaS360 was selected and deployed.
IBM MaaS360 · MDM · iOS · Mobile SecurityTwo source countries,
one bandwidth constraint, one solution
The Singapore-to-India migration could not use standard vSphere WAN replication as the primary data transfer mechanism. The 250 Mbps Singapore-India link was already being used for live business operations — replication at the required volume would have throttled production traffic. The solution required creative thinking about how data physically moves between continents.
Two constraints — both
solved before go-live
The bandwidth constraint and the DNS isolation challenge were identified and designed around in the Advise phase — not discovered mid-migration. Both had solutions that required creative engineering rather than simply throwing more bandwidth at the problem.
Data Migration Over a Shared 250 Mbps Singapore-India Link
DNS Migration Without AD Integration — Built from Scratch
Five workstreams — infrastructure to mobile,
migration to DR
The engagement covered five distinct delivery areas. Each required different technical expertise — VMware infrastructure design, workload migration engineering, identity and DNS architecture, disaster recovery configuration, and mobile device management. All five ran in parallel across the migration program.
Migration Infrastructure Setup
Designed and deployed the destination infrastructure in Pune and Bangalore before a single workload moved — the foundation everything else ran on.
- 5-node VMware HA cluster designed and implemented at both Pune and Bangalore DCs
- vSphere replication appliances deployed at each destination site
- Network connectivity validated — 1 Gbps India-India link confirmed for inter-DC replication
- Infrastructure readiness confirmed before any source workloads were touched
Phase-Level Workload Migration
Singapore DC migration used the tape seed copy + delta approach. India DC migration used vSphere replication directly over the 1 Gbps India-India link. Both phased — workloads validated at destination before source decommission.
- Singapore DC: tape seed copy shipped to India DCs, delta synced via vSphere replication
- India DC: direct vSphere replication over 1 Gbps link to new destination DCs
- 250+ VMs and 12 physical servers migrated in planned phases with validation gates
- Go-live only after data synchronisation confirmed at destination
Authentication & DNS Isolation
Built the identity and name resolution infrastructure the demerged entity needed to operate independently — domain controllers and DNS servers that belonged to the insurance company alone, not the global parent.
- Additional domain controllers built for each Business Unit being separated
- Standalone DNS servers established per BU — replacing global-entity-owned DNS
- DNS records migrated systematically with parallel operation during cutover
- Post-cutover validation confirmed all services resolving correctly against new DNS
Disaster Recovery Implementation
VMware SRM configured between the Pune and Bangalore DCs — ensuring the insurance company had validated DR readiness for customer-facing applications from day one of operating on the new infrastructure.
- VMware Site Recovery Manager configured between Pune and Bangalore DCs
- Recovery plans built for customer-centric applications — RPO and RTO targets defined
- DR drills conducted and results documented — readiness confirmed before sign-off
- DR architecture designed to scale as new workloads are added post-migration
Mobile Device Management
300+ iOS devices previously enrolled in the global entity’s MDM infrastructure needed to transition to a standalone MDM platform under the demerged insurance company’s own governance.
- IBM MaaS360 deployed as the standalone MDM solution for the demerged entity
- 300+ iOS devices enrolled, policies applied, and compliance baselines established
- Device security configuration aligned to insurance industry data protection requirements
- Mobile workforce transition executed without device downtime during the migration window
The tape seed copy technique — why it was the right call
Physical tape shipment is not the obvious answer to a WAN bandwidth constraint in 2024. But it was the correct one here. The volume of data to be moved from Singapore exceeded what the 250 Mbps shared link could transfer in a reasonable timeframe without impacting live operations. Tape bypassed the constraint entirely — moving the bulk of the data at the physical speed of air freight rather than the practical throughput of a shared business link. vSphere replication then handled only the delta, which was small enough to transit the link without competing with business traffic. The result was a faster migration, with no impact on the Singapore link, and no delay to the IRDA compliance deadline.
What the insurance company had when the new India infrastructure went live
Four outcomes — each measuring a different dimension of what a demerger-driven, IRDA-mandated migration had to deliver: compliance, operational continuity, DR readiness, and mobile security.
IRDA Compliance Achieved — Penalties Avoided
- IT infrastructure fully isolated in compliance with IRDA regulations — no workloads remaining on global entity-managed infrastructure
- Regulatory deadline met — compliance penalties avoided through timely migration delivery
- All Business Units separated with independent domain controllers and standalone DNS
- Demerged entity operating on fully owned and governed India-based infrastructure
250+ VMs and 12 Servers — Minimal Downtime
- 250+ virtual machines and 12 physical servers migrated seamlessly to new India-based facilities
- Tape seed copy technique eliminated WAN bandwidth bottleneck for Singapore-India transfer
- Data synchronisation maintained until go-live via vSphere replication — no data gap at cutover
- Insurance operations maintained throughout — customer-facing applications uninterrupted
Robust DR Readiness via VMware SRM
- VMware SRM configured between Pune and Bangalore DCs — DR readiness operational from go-live
- DR drills conducted and documented — recovery plans validated for customer-centric applications
- Business continuity confirmed for insurance operations in the event of a primary DC incident
- DR architecture scalable as the company’s workload grows post-demerger
300+ iOS Devices Secured Under IBM MaaS360
- IBM MaaS360 deployed — 300+ iOS devices enrolled and secured under the demerged company’s own MDM governance
- Device security policies aligned to insurance industry data protection requirements
- Mobile workforce transition completed without device downtime during the migration window
- MDM infrastructure now fully independent — no dependency on former global parent’s systems
Key Takeaways
Three specific engineering insights from this engagement. First — when WAN bandwidth is a constraint, think physically: tape seed copy bypassed a shared 250 Mbps link entirely and compressed the Singapore migration timeline. Second — DNS isolation is the hidden complexity in demerger migrations: the absence of AD-integrated DNS required building new DNS infrastructure from scratch before any DNS records could move. Third — DR readiness must be validated, not assumed: VMware SRM configuration was followed by actual DR drills — the insurance company’s business continuity was confirmed through testing, not documentation.
Every engagement follows
the AOTS framework
The demerger migration followed Softenger’s AOTS model — and the Advise phase was where the tape seed copy decision was made. Waiting to discover the bandwidth constraint mid-migration would have forced a choice between throttling the business link or missing the IRDA compliance deadline. Identifying it upfront meant the tape approach was designed into the plan from day one — not retrofitted under pressure.
The DNS isolation challenge was also an Advise-phase discovery: the absence of AD-integrated DNS was found during infrastructure assessment, and the standalone DNS build was scoped before the migration began. In a demerger migration, pre-discovery of technical constraints is the difference between a scheduled cutover and an emergency workaround.
Advise
Assessed full scope: 250+ VMs, 12 physical servers, 300+ iOS devices across Singapore and India DCs. Identified bandwidth constraint and DNS gap. Designed tape seed copy approach. Confirmed 5-node VMware HA cluster architecture.
Migration architecture confirmed. Tape approach approved. DNS isolation plan scoped. IRDA compliance timeline mapped to migration phases.
Optimize
Destination infrastructure built — VMware HA clusters at Pune and Bangalore. Tape seed copies prepared and shipped. vSphere replication appliances deployed. DNS servers built. IBM MaaS360 tenant configured.
Destination DCs infrastructure-ready. Tape data loaded at destinations. Replication delta syncing. New DNS and DCs live and tested.
Transform
Production cutover executed — 250+ VMs and 12 physical servers live on new India infrastructure. DNS cutover completed. 300+ iOS devices enrolled in MaaS360. VMware SRM configured and DR drills conducted. IRDA compliance achieved.
Full migration complete. IRDA compliance confirmed. DR readiness validated. Insurance operations uninterrupted. Global entity infrastructure decommissioned.
Support
New India-based infrastructure operating under the demerged company’s governance. VMware SRM monitored and DR plans kept current. IBM MaaS360 managing the mobile fleet. Infrastructure ready for growth as the insurer expands independently.
Demerged insurer operating on fully independent India-based IT infrastructure — owned, governed, and maintained entirely within the company.
The AOTS model is applied to every Softenger engagement
Whether it’s a demerger-driven migration, a datacenter consolidation, an ERP upgrade, or ongoing SOC operations — Advise, Optimize, Transform, Support provides the structure. The discipline is consistent; the application is specific to what each client needs.
Questions about demerger-driven workload migrations
Tell us the compliance
constraint — we’ll engineer
around it, not through it.
Whether it’s a demerger-driven infrastructure separation, a regulatory-mandated workload migration, a DC consolidation across geographies, or a VMware environment that needs restructuring — Softenger designs migrations around your constraints before they become incidents. A conversation with one of our infrastructure migration specialists starts with the regulatory timeline and the technical reality, not a standard migration template.
🔄 Discuss a Workload Migration
ISO 27001 certified. Your information is handled securely and never shared.