Operational resilience of the financial sector

We work to make sure banks and other firms that offer financial services in the UK can overcome disruptions to their services.

Overview

We work to make sure the financial sector in the UK is resilient to any disruptions to its operations. 

The financial sector includes banks, building societies, insurers and financial market infrastructure providers (FMIs). We carry out this work together with the UK’s two other financial authorities: HM Treasury and the Financial Conduct Authority.

Our objectives

  1. To keep retail and wholesale markets open and functioning, except if doing so would threaten UK financial stability. Specifically, we aim to keep payment and settlement systems open to complete the day’s business.
  2. To ensure an orderly and early return to trading if markets fail to remain open – for example by providing a single point of information, effective channels of communication and an effective and coordinated response.
  3. To involve relevant infrastructure providers and market participants when we make decisions affecting markets. 
  4. To facilitate market initiatives that help build operational resilience.

If you work for a firm or an FMI and need more information, please contact your supervisory team.

Operational resilience

Operational resilience is important for maintaining financial stability in the UK. 

By ‘operational resilience’, we mean the ability of firms, and the financial sector as a whole, to absorb and adapt to shocks and disruptions, rather than contribute to them. 

It extends beyond business continuity and disaster recovery. Financial firms and FMIs must have robust plans in place to deliver essential services, no matter what the cause of the disruption. This includes man-made threats such as physical and cyber attacks, IT system outages and third-party supplier failure. And it also includes natural hazards such as fire, flood, severe weather and pandemic.

As a central bank and as a regulator of financial firms and FMIs, we have an important part to play in improving the resilience of the sector.

How we set operational resilience policy

Our Financial Policy Committee (FPC) looks at the resilience of the system as a whole. The committee sets out its priorities twice a year in its Financial Stability Report. The committee’s macroprudential approach to operational resilience is set out in the Financial Stability in Focus.

Our Prudential Regulation Committee (PRC) and Financial Market Infrastructure Board (FMIB) focus on the operational resilience of the firms and FMIs we regulate.

Our approach to operational resilience

To support operational resilience we:

  • supervise individual firms and FMIs; and 
  • engage with the UK sector  and international authorities  to drive collective action.  

We have set out our approach to operational resilience for firms in our policy statements. This work is carried out by the Bank of England and by our Prudential Regulation Authority.

In summary, we ask firms to:

  • identify important business services. Boards and senior management must identify and prioritise services that, if disrupted, would impact our objectives and  the public interest;
  • set impact tolerances. Firms must say to what extent they would be able to continue important business services following severe but plausible disruptions; and
  • ensure they can remain within impact tolerances. Firms must map their important business services and test their capacity to continue them to the agreed extent. Where firms identify vulnerabilities which might stop them from remaining within impact tolerances, these should be addressed.

We have set out our policy on operational resilience of FMIs.

Collective action on operational resilience

The Cross Market Operational Resilience Group (CMORG) leads sector-wide collective action on operational resilience. 

The group is made up of around 25 members, firms across retail, wholesale, FMIs, insurance, the financial authorities and the National Cyber Security Centre. It is co-chaired by senior executives of the Prudential Regulation Authority (PRA) and UK Finance. 

CMORG has three core objectives. These are to:

  • identify risks to the resilience of the financial sector;
  • develop solutions to improve the operational resilience of the sector; and
  • share knowledge.

CMORG is supported by specialist subgroups. These subgroups design, manage, and deliver operational resilience improvements for the sector. The work undertaken by these groups is voluntary. Subgroup chairs meet regularly to discuss CMORG’s activities and identify areas for more collaboration.

CMORG is supported by a Project Management Office (PMO). The PMO is jointly resourced by us and UK Finance. It is developing a website to improve awareness of CMORG activity.

CMORG-endorsed capabilities (including good practice guidance, response frameworks and contingency tools) have been developed collectively by industry to support the operational resilience of the UK financial sector. The financial authorities support the development of these capabilities and collective efforts to improve sector resilience. However, their use is voluntary and they do not constitute regulatory rules or supervisory expectations; as such, they may not necessarily represent formal endorsement by the authorities.

The Financial Services Cyber Collaboration Centre (FSCCC) is a partnership led by CMORG. It aims to help identify, investigate and co-ordinate the response to incidents that have potential consequences for the financial sector. It analyses and distributes information to produce timely outputs for the benefit of the whole sector.

What happens if there is a disruption in the financial sector?

If there is a disruption, individual firms should contact their usual business or supervisory contacts at the Bank of England or the Financial Conduct Authority.

The sector’s response is facilitated by the Sector Response Framework (SRF). This framework sets out how organisations across the sector and government are connected. It also explains how they may respond to incidents individually and together when the impacts of an incident become broader than a single firm or FMI and require a degree of coordination, information sharing or collective action.

Its purpose is to: 

  • enable firms and FMIs, and the sector, to make collective, timely, informed decisions in response to incidents;
  • provide a reference to good practice, contingency tools and plans, which may be invoked as part of a sector response;
  • include both decision makers and subject matter experts;
  • be organised on a modular basis, so that components of the SRF can respond;
  • be recognised by the financial authorities as the principle structure by which the sector will respond to incidents;
  • support collaborative engagement between the sector and the UK financial authorities (see below); and
  • be able to engage with frameworks in other jurisdictions, if required.

The UK’s three financial authorities are the Bank of England (including the Prudential Regulation Authority), the Financial Conduct Authority and His Majesty’s Treasury. 

If disruptions have the potential to impact the sector as whole, the UK’s financial authorities act together. The Authorities Response Framework co-ordinates their response. 

Cyber resilience

To maintain the cyber resilience of the UK financial sector and to support our supervisory oversight, we have developed a number of cyber assessment tools.

Cyber assessment tools include CBEST, STAR-FS and CQUEST.

CBEST

CBEST provides a framework for regulators to work with firms using a simulated cyber attack. This enables firms to explore how an attack on the people, processes and technology of a firm’s cyber security controls may be disrupted. 

The aim of CBEST is to:

  • test a firm’s defences; 
  • assess its threat intelligence capability; and
  • assess its ability to detect and respond to a range of external attackers as well as people on the inside. 

Firms use the assessment to plan how they can strengthen their resilience.

We base the simulated attacks used on current cyber threats. These include the approach a threat actor may take to attack a firm and how they might exploit a firm’s online information.

An accredited service provider carries out the simulation. They act within legal, ethical and moral constraints. They aim to get through a firm’s defences using the cyber kill chain. They also assess if the confidentiality, integrity or availability of systems and processes that deliver a firm’s important business services can be compromised.

STAR-FS

The Bank of England, Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA) are pleased to announce the launch of a new threat-led penetration test assessment for the UK Finance Sector. STAR-FS (Simulated Targeted Attack & Response assessments for Financial Services) is now part of the PRA and FCA supervisory toolkit, which also includes CBEST, to assess the cyber resilience of firms’ important business services. This assessment enables regulators and firms to better understand vulnerabilities and take remedial actions, thereby improving the resilience of individual firms and by extension, the wider financial system. 

STAR-FS promotes a threat-led penetration testing approach that mimics the actions of cyber threat actors’ intent on compromising an organisation’s important business services and the technology assets and people supporting those services.

STAR-FS aims to provide:

  • an outcome-based assessment of financial institutions’ protection, detection and response technical capabilities against cyber-attacks;
  • an approach, conducted through a firm-led delivery model, that can identify cyber resilience vulnerabilities within systems, people and processes;
  • reduced regulatory and firm effort relative to other supervisory technical assessments such as CBEST;
  • levels of independent technical assurance beyond those ordinarily included in firms’ own penetration testing programmes; and 
  • a testing approach accessible by a larger number of financial institutions to experience and learn from.

Here is a short list of STAR-FS unique features:

  • STAR-FS accredited threat intelligence and penetration test service providers are utilised to replicate real world attacks on operational systems.
  • STAR-FS allows for consistent formal reports to be used by firms to provide appropriate information to regulators of the level of technical cyber resilience.
  • STAR-FS can be self-initiated by firms as part of their own cyber programmes, as well as initiated by regulators as part of supervisory oversight, to inform assessments of protection, detection, and response capabilities and uncover vulnerabilities through testing.
  • Self-initiated STAR-FS assessments could be recognised as a supervisory assessment if regulators are notified of the STAR-FS, accept the opportunity to input to the scope, and then receive the relevant requested outputs at the end of the assessment. 

A STAR-FS Implementation Guide and supporting templates are now available. If your firm is interested in conducting a STAR-FS assessment please contact your Supervisor.

CQUEST

Operational disruption to important business services could impact financial stability, threaten the safety and soundness of individual firms and financial market infrastructures (FMIs), and cause harm to consumers and other market participants in the financial system. In this context, firms and FMIs should assess their cyber risk and build adequate resilience capabilities to prepare for, and respond to, cyber events and incidents that could cause operational disruption.

CQUEST forms part of the Bank of England and PRA/FCA’s supervisory toolkit to gauge the cyber risk and resilience capabilities of the financial sector. CQUEST can also be used by other firm(s) as a self-assessment tool to consider their own cyber risk and resilience maturity. The CQUEST questionnaire (below) comprises 50 questions with multiple-choice answers across six domains: Governance and Leadership, Identify, Protect, Detect, Respond, and Recover.

To achieve a reliable outcome, an organisation should identify and direct a competent party with appropriate knowledge and experience of the business and cyber capabilities in the firm(s) to complete the CQUEST questionnaire. 

When CQUEST is used to inform regulatory activities, supervisors might provide additional guidance and/or they could request evidence or clarifying information in response to a firm or FMI’s answers.

CQUEST latest version

The latest version of CQUEST builds upon the previous questionnaire, and encompasses lessons learned from good practice frameworks and feedback from supervisors and firms. The PRA and FCA continue to review the performance of its supervisory tools to achieve its statutory objectives and for the benefit of the sector.

Specific instructions on how to complete the questionnaire is provided in the CQUEST cover sheet.

More information

CBEST Logo
This page was last updated 04 July 2024