Cybersecurity emphasizes operational resilience

Why banks can no longer treat cyber risk as an IT problem

In the past, cyber risk was regarded pretty much exclusively as an IT security issue. These days, as instances of increasingly sophisticated cyberattacks proliferate, cyber risk has become much more of an operational resilience issue.

For banks, planning increasingly must account for the possibility of a serious cyber incident. The consequences can include suspension of payments services, prevention of customers from accessing deposits, disablement of lending or trading systems, and corruption of data. In those circumstances, the ability of the bank to continue delivering critical services when part of its technological capabilities has been compromised is paramount.

The distinction between IT security and operational resilience has become increasingly explicit in regulation. In its 2026 consolidated operational risk and resilience guidelines, the Basel Committee positions cybersecurity alongside business continuity, incident management, mapping of critical operations, and third-party dependency management.

Core Insights

  • Cyber risk in banking is increasingly an operational resilience issue, not only an IT security issue.
  • Banks need to plan for the possibility of serious disruption and focus on whether critical services can continue or be restored quickly.
  • Operational resilience shifts attention from individual systems toward the business services customers and markets depend on.
  • Effective incident preparedness requires clear escalation criteria, decision rights, cyber playbooks, communication protocols, and recovery priorities.
  • Recovery should be guided by the importance of business services rather than by technical convenience alone.
  • Third-party providers such as cloud, software, payment, and FinTech companies can create significant operational vulnerabilities.
  • Apparent vendor diversification can still hide shared dependencies, creating potential single points of failure.
  • Third-party concentration risk can become systemic when many financial institutions depend on the same critical technology providers.
  • Operational resilience therefore extends beyond a bank’s internal systems to the external infrastructure supporting its critical services.

In this article

 

This article is also available in podcast/video form. Watch the video below from our YouTube channel, or follow The Intuition Finance Digest on Spotify, Apple Podcasts, or Amazon Music.

Operational resilience prioritizes services not systems

Operational resilience effectively requires banks to assume that disruption may occur, including because of a successful cyberattack. In that case, the question is what happens to a bank’s customers and critical services, and how quickly those services can be restored. This goes beyond prevention of unauthorized access, malware, data loss, and system compromise.

All of this requires a change in emphasis toward services rather than systems.

Historically and culturally, technology departments would have classified servers and applications according to technical importance. Operational resilience, however, requires banks to work backward from critical business services. It is then up to the bank to determine what level of disruption to the services it could tolerate.

Incident preparedness key to banks’ resilience

Once banks have identified the services that matter most, the challenge is being ready to make decisions when those services are disrupted. Effective cyber preparedness therefore depends on having clear response arrangements in place before an incident occurs.

The Basel Committee expects banks to have several interconnected capabilities in place.

  • Detection and escalation: Banks need to specifically define escalation criteria, which might for example be the number of customers affected, service downtime, financial exposure, data loss, and potential systemic consequences.
  • Crisis command arrangements: The organization needs clearly defined decision rights covering questions such as whether to shut down systems, isolate parts of the network, switch to backup systems, and so on.
  • Cyber specific playbook: Banks need to cover a range of scenarios such as ransomware, destructive malware, denial-of-service attacks, compromised privileged credentials, and data corruption.
  • Communications: Banks should have access to alternative channels and pre-agreed communication protocols. A serious cyber event requires simultaneous communication with management, staff, customers, regulators, payment systems, counter parties, technology suppliers, law enforcement, and sometimes the media.
  • Recovery priorities: As not everything should be restored simultaneously, banks should progress recovery according to the importance of business services rather than technical convenience.

Get the latest finance news delivered directly to your inbox

Subscribe to our Financial Newsletter

newsletter image

Third-party dependency assumes greater role

Modern banks depend increasingly upon a range of third parties such as cloud computing companies, software-as-a-service providers, payment processers, and specialist FinTech providers.

This means that while a bank may be technically secure internally; it remains operationally vulnerable if a critical external supplier is compromised.

Hence, banks need to be alive to concentration risk among third part vendors and prioritize diversification.

This may appear relatively straightforward, but requires detailed due diligence.

While separate banking systems may appear diversified because they come from various vendors, these may share common infrastructure. They could, for example, operate through the same cloud region, identity-management platform or network provider, which means the bank may have a major single point of failure.

And regulators have drawn attention to the fact that the issue can become systemic. As many different financial institutions may depend upon the same handful of technology providers, the failure of one provider could therefore affect numerous banks simultaneously – one reason why the Digital Operational Resilience Act (DORA) introduced direct European oversight of designated critical ICT third-party providers.

Operational resilience therefore extends beyond the bank itself to the technology providers and infrastructure supporting its critical services.

Intuition Know-How has a number of tutorials relevant to the content of this article:

  • Operational Resilience
  • Operational Risk – An Introduction
  • Operational risk management – developments & emerging risks
  • Operational risk management – Tools & techniques
  • Operational Risk – Management
  • DORA
  • Digital Banking – An Introduction
intuition - text logo_ black
Intuition Know-How is the complete learning library for financial services

Frequently Asked Questions

What does operational resilience mean for bank cybersecurity?

Operational resilience means preparing for the possibility that a cyberattack or other disruption may affect critical banking services. The focus extends beyond preventing unauthorized access, malware, data loss, or system compromise. Banks also need to consider whether customers can continue accessing payments, deposits, lending, trading, and other important services when parts of their technology environment have been disrupted.

Why does operational resilience prioritize services over systems?

Operational resilience starts with the critical business services a bank needs to maintain rather than the technical importance of individual servers or applications. Banks work backward from those services to understand what supports them and determine how much disruption can be tolerated. This shifts the focus from protecting individual systems toward maintaining services that matter to customers and the wider operation of the bank.

How should banks prepare for a serious cyber incident?

Banks should have clear response arrangements in place before a cyber incident occurs. This includes knowing when an incident should be escalated, who has authority to make critical decisions, how different cyber scenarios will be handled, which communication channels will be used, and which business services should be restored first. Preparing these arrangements in advance helps banks respond more effectively during disruption.

What capabilities support effective cyber incident preparedness?

Effective incident preparedness includes detection and escalation criteria, clear crisis command arrangements, cyber-specific playbooks, communication protocols, and recovery priorities. Banks may need to decide whether to shut down systems, isolate parts of a network, switch to backup systems, or communicate with customers, regulators, suppliers, and law enforcement. Recovery should then prioritize important business services rather than technical convenience.

Why do third-party technology providers create operational resilience risk?

Banks increasingly depend on cloud providers, software-as-a-service companies, payment processors, and specialist FinTech providers. Even where a bank is technically secure internally, it can remain operationally vulnerable if a critical supplier is compromised. Different vendors may also rely on the same cloud region, identity-management platform, or network provider, creating hidden dependencies and potential single points of failure.

Why can third-party concentration risk become systemic?

Third-party concentration risk can become systemic when many financial institutions depend on the same small group of technology providers. A failure at one critical provider could therefore affect multiple banks at the same time. This is one reason the Digital Operational Resilience Act introduced direct European oversight of designated critical ICT third-party providers and why operational resilience increasingly extends beyond the bank itself.