Skip to content

Operational resilience as the new board agenda for financial institutions

This is the second article in a four-part series inspired by the inaugural NCR Atleos and Trellix Cyber Security Summit, held earlier this year at the Cyber Quarter in Dundee. The event brought together financial institutions, cybersecurity specialists, law enforcement representatives and academic experts to explore how the industry can stay ahead of an increasingly complex threat landscape. Building on the first article focused on the convergence of physical and digital security risks, this piece examines why operational resilience has become a board-level priority for financial institutions operating in a more connected, fast-moving risk environment.

Resilience has become a strategic priority

For financial institutions, operational resilience has moved from a technical discipline to a strategic business priority. The modern banking ecosystem is now shaped by a convergence of:

  • Cyber threats
  • Third-party dependency
  • Physical risk
  • AI-enabled fraud
  • Regulatory scrutiny
  • Rising customer expectations

As services become more digital, interconnected and dependent on external providers, the ability to maintain critical operations during disruption is no longer simply an IT concern. It is a measure of institutional strength, customer trust and market confidence.

Recent discussions across the financial services sector highlight a clear shift in expectations. Regulators increasingly want demonstrable evidence that firms can prevent, withstand, respond to and recover from severe but plausible disruption. In the UK, firms in scope of operational resilience requirements were expected to remain within impact tolerances for important business services by March 2025, with continuing focus on mapping, testing, remediation and investment. Executive leadership can no longer claim their resiliency based on asserted policy but must prove it in practice.

Beyond recovery: proving continuity under pressure

This represents a significant evolution from traditional disaster recovery. Historically, disaster recovery often focused on restoring systems after an outage. Today, the bar is higher. Financial institutions must understand which services matter most to customers, how those services are delivered, where dependencies exist and what level of disruption can be tolerated before consumer harm, market disruption or reputational damage occurs. Resilience is therefore not only about recovery speed; it is about continuity of service, accountability and confidence under pressure.

Closing the gap between plans and reality

One of the most common weaknesses remains the gap between documented plans and operational reality. Many crisis plans are created to satisfy governance or audit requirements, but are not tested against the complexity of real-world disruption. A plan that exists only as a digital document may be inaccessible during a technology outage. A supplier contact list may be incomplete when communication systems fail. A crisis management platform may itself become a point of vulnerability if access controls, identity verification and segmentation have not been properly designed.

The implication for senior leaders is that resilience needs a more disciplined operating model. Tabletop exercises, cross-functional simulations and supplier drills should be embedded into the rhythm of the business. These exercises must go beyond technical recovery and test decision-making, communications, escalation routes, customer impact and employee safety. The objective is to expose weaknesses before an actual incident does.

Managing resilience across the supply chain

Supply-chain security has become equally central to banking resilience. Financial institutions now rely on complex ecosystems of technology providers, cloud platforms, software vendors, specialist service partners and smaller suppliers that may support critical operational flows. This interconnected model delivers innovation and scale, but it also introduces concentration risk and visibility challenges. A weakness in one supplier can quickly become a disruption across many institutions, particularly where the same provider supports multiple firms or critical services.

Traditional supplier assurance is no longer sufficient. Annual questionnaires and static accreditation reviews can create a false sense of control, especially when responses are difficult to validate or compare. Business executives should be asking the following questions:

  • Which third parties are essential to business services?
  • Where is the concentration risk?
  • How quickly would you know if a supplier incident affected you?
  • Do your suppliers share the same understanding of acceptable risk?

A more mature approach is risk-tiered and evidence-led. Suppliers that support critical services should be subject to deeper assurance, including joint incident exercises, contractual incident reporting obligations, visibility of sub-supplier dependencies and clear remediation expectations. Smaller but critical suppliers may need support as well as scrutiny. Where an SME provides a business-critical component or specialist capability, financial institutions should consider sponsor-and-uplift models that help those partners meet baseline controls for authentication, logging, vulnerability management and response participation.

The human dimension of operational resilience

The human dimension of resilience also deserves greater executive attention. Operational resilience is often framed around technology architecture, systems redundancy and cyber controls. Yet prolonged incidents place significant pressure on employees, particularly where incident response or business continuity duties sit alongside primary roles.

Field teams may face physical risk, coercion, severe weather or customer tension during periods of disruption. A credible resilience strategy should therefore include fatigue management, rota-based response coverage, safe-arrival checks, duress procedures and role-specific training.

A board-level agenda for connected risk

For boards and executive committees, the strategic challenge is to connect these disciplines into a single resilience agenda. Cybersecurity, operational resilience, third-party risk, fraud prevention, crisis communications and customer protection cannot operate as separate workstreams. AI-enabled social engineering, ransomware, cloud dependency, supply-chain compromise and physical threats do not respect organizational boundaries. The response must be integrated, governed and measurable.

This requires a shift in executive dialogue from asking for a disaster recovery plan and suppliers to completed assurance questionnaires, towards ensuring the institution can continue providing its most important services within agreed impact tolerances, has real-time visibility of dependencies and effective levers to act during an incident. Instead of treating resilience as a cost, executives should view it as a foundation for trust, competitiveness and long-term customer confidence.

The financial institutions that lead on resilience will be those that move beyond compliance and build a culture of preparedness. They will test realistically, learn continuously, invest proportionately and collaborate across their ecosystems. Most importantly, they will recognize that resilience is not achieved by technology alone. It depends on people, partners, governance and the ability to make sound decisions when conditions are uncertain.

Call to action

Financial institutions should act now to assess whether their resilience strategies are fit for a more connected, fast-moving threat environment. That means:

  • Confirm board-level ownership of critical business services and impact tolerances
  • Challenge supplier dependency, concentration risk and ecosystem visibility
  • Test crisis governance, executive decision-making and communications under realistic disruption scenarios
  • Ensure people, processes and partners can act with speed, clarity and accountability during disruption

The opportunity is not simply to meet regulatory expectations, but to build a more trusted, adaptive and resilient banking ecosystem ready for disruption, which is inevitable. The priority is to design, test and govern organizations that can continue to serve customers, protect employees and sustain trust when the ecosystem around them is under pressure.

Related resources

Let’s explore what’s possible for your business. Our team is ready to connect and discuss tailored solutions that meet your goals.

Thank you.

Thank you for reaching out. A member of our team will be in touch shortly to continue the conversation.