Case Study — Workload Migration · Insurance · IRDA Compliance
Insurance — General & Life VMware SRM · vSphere · IBM MaaS360 Demerger-Driven · IRDA Compliant

Migration of Virtual Workloads
Between Data Centers —
Demerger-Driven, IRDA Compliant

A top general and life insurance company separated from its global parent — and with that demerger came a non-negotiable IRDA requirement: isolate every IT workload into India-based infrastructure under the company’s own governance. Softenger migrated 250+ VMs and 12 physical servers from Singapore and India data centers to new India-based facilities, solving a 250 Mbps bandwidth constraint with physical tape.

250+ VMs
Migrated with Minimal Downtime
300+
iOS Devices Secured via MaaS360
2
Countries · Singapore + India → India
Engagement at a Glance

Virtual Workload Migration —Insurance Demerger, IRDA Compliance

🏦
Client Industry
Insurance — General & Life Top insurer, demerged from global parent entity
🔄
Project
Virtual Workload Migration — Multi-DC Singapore DC + India DCs → New India-Based DC (Pune + Bangalore)
📋
Regulatory Driver
IRDA Compliance — IT Infrastructure Isolation Demerger required full separation from global entity’s managed infrastructure
📊
Scope
250+ VMs · 12 Physical Servers · 300+ iOS Devices 5-node VMware HA cluster · VMware SRM DR · IBM MaaS360 MDM
VMware Hypervisor vSphere Replication VMware SRM IBM MaaS360 Tape Seed Copy
🏦
IndustryInsurance — General & Life
🔄
ProjectMulti-DC Virtual Workload Migration
⚙️
TechnologyVMware SRM · vSphere · IBM MaaS360
📋
Regulatory DriverIRDA Compliance — IT Isolation

A demerger created a
compliance deadline — IT had to move

When a top insurance company separates from its global parent, the operational consequences extend well beyond the corporate structure. The Insurance Regulatory and Development Authority of India (IRDA) requires that insurance companies maintain IT infrastructure within India under their own governance — not shared with or managed by a global entity they no longer belong to. A demerger, in other words, triggers a mandatory IT migration with a compliance clock attached.

The company’s IT workloads were running on globally managed data centers in Singapore and India — infrastructure that was now, post-demerger, legally impermissible to continue operating on. Every virtual machine, every physical server, every network dependency had to be extracted from the global entity’s environment and reestablished in new India-based facilities under the demerged company’s own control — all while the business continued operating normally.

Business Need

Isolate IT infrastructure to comply with IRDA regulations following demerger. Migrate 250+ virtual machines and 12 physical servers from Singapore and India-based data centers to new India-based facilities — maintaining disaster recovery readiness, implementing mobile device management, and ensuring zero disruption to insurance operations throughout.

01

IRDA Regulatory Compliance — Mandatory IT Isolation

IRDA regulations required full isolation of the insurance company’s IT infrastructure from the global parent entity — workloads could not remain on globally managed infrastructure post-demerger. Compliance had a deadline; non-compliance carried penalties.

IRDA · Regulatory · Compliance Deadline
02

250+ VMs and 12 Physical Servers — Minimal Business Downtime

The full virtual and physical server estate had to migrate from Singapore and India DCs to new Pune and Bangalore facilities. Insurance operations could not tolerate significant downtime — customer-facing applications had to remain available throughout.

VM Migration · Physical Servers · Business Continuity
03

DR Readiness for Customer-Centric Applications

Post-migration, the new India-based infrastructure had to be configured for disaster recovery — VMware SRM implemented and DR drills conducted to confirm that customer-facing applications could failover reliably in the event of a site incident.

VMware SRM · DR Drills · Business Continuity
04

Mobile Device Management for 300+ iOS Devices

The mobile workforce — 300+ iOS devices previously managed under the global entity’s MDM infrastructure — needed to transition to a standalone MDM solution under the demerged company’s governance. IBM MaaS360 was selected and deployed.

IBM MaaS360 · MDM · iOS · Mobile Security

Two source countries,
one bandwidth constraint, one solution

The Singapore-to-India migration could not use standard vSphere WAN replication as the primary data transfer mechanism. The 250 Mbps Singapore-India link was already being used for live business operations — replication at the required volume would have throttled production traffic. The solution required creative thinking about how data physically moves between continents.

Migration Topology — Source DCs → Destination DCs
🇸🇬 Source — Singapore
Singapore Data Center
Global Entity — Managed Infrastructure
🇮🇳 Source — India
India Data Centers
Global Entity — India-Managed
🇮🇳 Destination — New DC
Pune Data Center
5-node VMware HA Cluster · vSphere Replication Appliance
🇮🇳 Destination — New DC
Bangalore Data Center
5-node VMware HA Cluster · VMware SRM (DR)
🖥️
VMware Hypervisor
🔄
vSphere Replication
🛡️
VMware SRM
📱
IBM MaaS360
📼
Tape Backup & Restore

Two constraints — both
solved before go-live

The bandwidth constraint and the DNS isolation challenge were identified and designed around in the Advise phase — not discovered mid-migration. Both had solutions that required creative engineering rather than simply throwing more bandwidth at the problem.

Challenge 01 — Connectivity
📡

Data Migration Over a Shared 250 Mbps Singapore-India Link

The Problem
The 250 Mbps Singapore-India link was the only available path for replication — and it was already carrying live business traffic. Dedicating it to bulk VM replication would have throttled production operations. Standard vSphere WAN replication for 250+ VMs at this bandwidth would have taken weeks and impacted the business throughout.
Softenger’s Solution
Physically shipped data on tape to the target India data centers — bypassing the WAN link entirely for the bulk data transfer. Once the tape-based seed copy was loaded at the destination, vSphere replication was used only to sync the delta — the changes accumulated since the tape was created. This compressed a multi-week WAN transfer into a short delta-sync window, with zero impact on the live 250 Mbps business link.
✓ Bulk data moved via tape · Delta only over WAN · Business link unimpacted
Challenge 02 — DNS Isolation
🌐

DNS Migration Without AD Integration — Built from Scratch

The Problem
The existing infrastructure lacked Active Directory-integrated DNS — meaning DNS records were not part of the AD replication that would naturally propagate during domain separation. Standalone DNS servers belonging to the global entity’s infrastructure had to be fully replaced for each Business Unit being separated, with all DNS records migrated, without causing service outages during the cutover window.
Softenger’s Solution
Built new standalone DNS servers from scratch for each Business Unit being separated from the global entity. DNS records were systematically migrated and validated before each cutover — with the old DNS servers kept running in parallel until every dependent service had confirmed resolution against the new servers. Record updates were sequenced to ensure no service went dark between DNS decommission and DNS go-live.
✓ Standalone DNS built per BU · Records validated · Zero service interruption at cutover

Five workstreams — infrastructure to mobile,
migration to DR

The engagement covered five distinct delivery areas. Each required different technical expertise — VMware infrastructure design, workload migration engineering, identity and DNS architecture, disaster recovery configuration, and mobile device management. All five ran in parallel across the migration program.

Workstream 01
🏗️

Migration Infrastructure Setup

Designed and deployed the destination infrastructure in Pune and Bangalore before a single workload moved — the foundation everything else ran on.

  • 5-node VMware HA cluster designed and implemented at both Pune and Bangalore DCs
  • vSphere replication appliances deployed at each destination site
  • Network connectivity validated — 1 Gbps India-India link confirmed for inter-DC replication
  • Infrastructure readiness confirmed before any source workloads were touched
Workstream 02
🔄

Phase-Level Workload Migration

Singapore DC migration used the tape seed copy + delta approach. India DC migration used vSphere replication directly over the 1 Gbps India-India link. Both phased — workloads validated at destination before source decommission.

  • Singapore DC: tape seed copy shipped to India DCs, delta synced via vSphere replication
  • India DC: direct vSphere replication over 1 Gbps link to new destination DCs
  • 250+ VMs and 12 physical servers migrated in planned phases with validation gates
  • Go-live only after data synchronisation confirmed at destination
Workstream 03
🔐

Authentication & DNS Isolation

Built the identity and name resolution infrastructure the demerged entity needed to operate independently — domain controllers and DNS servers that belonged to the insurance company alone, not the global parent.

  • Additional domain controllers built for each Business Unit being separated
  • Standalone DNS servers established per BU — replacing global-entity-owned DNS
  • DNS records migrated systematically with parallel operation during cutover
  • Post-cutover validation confirmed all services resolving correctly against new DNS
Workstream 04
🛡️

Disaster Recovery Implementation

VMware SRM configured between the Pune and Bangalore DCs — ensuring the insurance company had validated DR readiness for customer-facing applications from day one of operating on the new infrastructure.

  • VMware Site Recovery Manager configured between Pune and Bangalore DCs
  • Recovery plans built for customer-centric applications — RPO and RTO targets defined
  • DR drills conducted and results documented — readiness confirmed before sign-off
  • DR architecture designed to scale as new workloads are added post-migration
Workstream 05
📱

Mobile Device Management

300+ iOS devices previously enrolled in the global entity’s MDM infrastructure needed to transition to a standalone MDM platform under the demerged insurance company’s own governance.

  • IBM MaaS360 deployed as the standalone MDM solution for the demerged entity
  • 300+ iOS devices enrolled, policies applied, and compliance baselines established
  • Device security configuration aligned to insurance industry data protection requirements
  • Mobile workforce transition executed without device downtime during the migration window
📼

The tape seed copy technique — why it was the right call

Physical tape shipment is not the obvious answer to a WAN bandwidth constraint in 2024. But it was the correct one here. The volume of data to be moved from Singapore exceeded what the 250 Mbps shared link could transfer in a reasonable timeframe without impacting live operations. Tape bypassed the constraint entirely — moving the bulk of the data at the physical speed of air freight rather than the practical throughput of a shared business link. vSphere replication then handled only the delta, which was small enough to transit the link without competing with business traffic. The result was a faster migration, with no impact on the Singapore link, and no delay to the IRDA compliance deadline.

Virtual Workload Migration Architecture — Insurance Demerger VMware · vSphere Replication · SRM · IBM MaaS360 · Tape Seed Copy
Virtual Workload Migration Architecture — Insurance Demerger

What the insurance company had when the new India infrastructure went live

Four outcomes — each measuring a different dimension of what a demerger-driven, IRDA-mandated migration had to deliver: compliance, operational continuity, DR readiness, and mobile security.

Outcome 01 — Compliance

IRDA Compliance Achieved — Penalties Avoided

  • IT infrastructure fully isolated in compliance with IRDA regulations — no workloads remaining on global entity-managed infrastructure
  • Regulatory deadline met — compliance penalties avoided through timely migration delivery
  • All Business Units separated with independent domain controllers and standalone DNS
  • Demerged entity operating on fully owned and governed India-based infrastructure
Outcome 02 — Migration Efficiency

250+ VMs and 12 Servers — Minimal Downtime

  • 250+ virtual machines and 12 physical servers migrated seamlessly to new India-based facilities
  • Tape seed copy technique eliminated WAN bandwidth bottleneck for Singapore-India transfer
  • Data synchronisation maintained until go-live via vSphere replication — no data gap at cutover
  • Insurance operations maintained throughout — customer-facing applications uninterrupted
Outcome 03 — Disaster Recovery

Robust DR Readiness via VMware SRM

  • VMware SRM configured between Pune and Bangalore DCs — DR readiness operational from go-live
  • DR drills conducted and documented — recovery plans validated for customer-centric applications
  • Business continuity confirmed for insurance operations in the event of a primary DC incident
  • DR architecture scalable as the company’s workload grows post-demerger
Outcome 04 — Mobile Security

300+ iOS Devices Secured Under IBM MaaS360

  • IBM MaaS360 deployed — 300+ iOS devices enrolled and secured under the demerged company’s own MDM governance
  • Device security policies aligned to insurance industry data protection requirements
  • Mobile workforce transition completed without device downtime during the migration window
  • MDM infrastructure now fully independent — no dependency on former global parent’s systems
💡

Key Takeaways

Three specific engineering insights from this engagement. First — when WAN bandwidth is a constraint, think physically: tape seed copy bypassed a shared 250 Mbps link entirely and compressed the Singapore migration timeline. Second — DNS isolation is the hidden complexity in demerger migrations: the absence of AD-integrated DNS required building new DNS infrastructure from scratch before any DNS records could move. Third — DR readiness must be validated, not assumed: VMware SRM configuration was followed by actual DR drills — the insurance company’s business continuity was confirmed through testing, not documentation.

Softenger’s Engagement Framework

Every engagement follows
the AOTS framework

The demerger migration followed Softenger’s AOTS model — and the Advise phase was where the tape seed copy decision was made. Waiting to discover the bandwidth constraint mid-migration would have forced a choice between throttling the business link or missing the IRDA compliance deadline. Identifying it upfront meant the tape approach was designed into the plan from day one — not retrofitted under pressure.

The DNS isolation challenge was also an Advise-phase discovery: the absence of AD-integrated DNS was found during infrastructure assessment, and the standalone DNS build was scoped before the migration began. In a demerger migration, pre-discovery of technical constraints is the difference between a scheduled cutover and an emergency workaround.

A
Phase 01

Advise

Clarity Before Action

Assessed full scope: 250+ VMs, 12 physical servers, 300+ iOS devices across Singapore and India DCs. Identified bandwidth constraint and DNS gap. Designed tape seed copy approach. Confirmed 5-node VMware HA cluster architecture.

In this engagement

Migration architecture confirmed. Tape approach approved. DNS isolation plan scoped. IRDA compliance timeline mapped to migration phases.

O
Phase 02

Optimize

Precision Over Patchwork

Destination infrastructure built — VMware HA clusters at Pune and Bangalore. Tape seed copies prepared and shipped. vSphere replication appliances deployed. DNS servers built. IBM MaaS360 tenant configured.

In this engagement

Destination DCs infrastructure-ready. Tape data loaded at destinations. Replication delta syncing. New DNS and DCs live and tested.

T
Phase 03

Transform

Evolution Without Disruption

Production cutover executed — 250+ VMs and 12 physical servers live on new India infrastructure. DNS cutover completed. 300+ iOS devices enrolled in MaaS360. VMware SRM configured and DR drills conducted. IRDA compliance achieved.

In this engagement

Full migration complete. IRDA compliance confirmed. DR readiness validated. Insurance operations uninterrupted. Global entity infrastructure decommissioned.

S
Phase 04

Support

Continuity as a Standard

New India-based infrastructure operating under the demerged company’s governance. VMware SRM monitored and DR plans kept current. IBM MaaS360 managing the mobile fleet. Infrastructure ready for growth as the insurer expands independently.

In this engagement

Demerged insurer operating on fully independent India-based IT infrastructure — owned, governed, and maintained entirely within the company.

The AOTS model is applied to every Softenger engagement

Whether it’s a demerger-driven migration, a datacenter consolidation, an ERP upgrade, or ongoing SOC operations — Advise, Optimize, Transform, Support provides the structure. The discipline is consistent; the application is specific to what each client needs.

Advise Optimize Transform Support

Questions about demerger-driven workload migrations

Q1 How did Softenger migrate data from Singapore to India when the available bandwidth was already being used by live business operations? +
The 250 Mbps Singapore-India link couldn’t be dedicated to replication without impacting live operations — a constraint that ruled out a standard vSphere replication-over-WAN approach for the bulk data transfer. Softenger’s solution was to physically ship the data on tape to the target India data centers, bypassing the bandwidth constraint entirely for the initial bulk transfer. Once the tape-based seed data was loaded at the destination, vSphere replication was then used to synchronise the delta — the changes that had accumulated since the tape was created — over the existing link. This approach compressed what would have been weeks of network-constrained replication into a fraction of the time, while leaving the business link unimpacted throughout.
Q2 Why did the demerger require IRDA compliance, and what did IT isolation actually involve? +
IRDA — the Insurance Regulatory and Development Authority of India — requires that insurance companies maintain IT infrastructure within India and under their own governance, not shared with or managed by a parent or affiliated global entity. When the insurance company demerged from its global parent, its IT workloads were running on globally managed data centers in Singapore and India — infrastructure the demerged entity could no longer legally operate on. Isolation meant migrating every workload, authentication system, and DNS record out of the shared global infrastructure and into new India-based facilities owned and governed entirely by the demerged company. The migration wasn’t optional — it was a regulatory requirement with a compliance deadline.
Q3 What was the DNS isolation challenge, and why was it more complex than a standard DNS migration? +
Most enterprise environments run Active Directory-integrated DNS — where DNS records are stored and replicated within the AD domain, and DNS isolation happens naturally when you separate the AD domain. This insurance company’s existing infrastructure lacked AD-integrated DNS, meaning DNS was running on standalone servers that were part of the global entity’s shared infrastructure. Isolating DNS required building new standalone DNS servers from scratch for each Business Unit being separated, manually migrating all DNS records, and carefully sequencing the record updates so that services didn’t go dark between the old DNS being decommissioned and the new DNS being live. A misconfigured DNS record during this window would have taken down dependent services — making the sequencing and validation of record updates the critical path in the isolation workstream.

Tell us the compliance
constraint — we’ll engineer
around it, not through it.

Whether it’s a demerger-driven infrastructure separation, a regulatory-mandated workload migration, a DC consolidation across geographies, or a VMware environment that needs restructuring — Softenger designs migrations around your constraints before they become incidents. A conversation with one of our infrastructure migration specialists starts with the regulatory timeline and the technical reality, not a standard migration template.

🔄 Discuss a Workload Migration

ISO 27001 certified. Your information is handled securely and never shared.

🛡️
ISO 27001:2022Information Security Management
ISO 9001:2015Quality Management System
🔄
Workload MigrationVMware · vSphere · SRM · Insurance · IRDA
📅
Est. 199925 Years of Enterprise IT Delivery
Scroll to Top