Operational resilience policy
Our Financial Policy Committee (FPC) looks at the entire system. Our Prudential Regulation Committee (PRC) and Financial Market Infrastructure Committee (FMIC) focus on the firms and FMIs we regulate.
In summary, we ask firms to:
- identify important business services: boards and senior management must prioritise services that, if disrupted, would affect our objectives and the public interest;
- set impact tolerances: firms must say to what extent they could continue important business services after severe but plausible disruptions; and
- make sure they can stay within impact tolerances: firms must map their important business services and test their capacity to continue to the agreed extent – they should address any vulnerabilities they have identified.
The operational resilience policy SS1/21 requires firms to prepare a written operational resilience self-assessment of compliance. The aim is to document a firms’ resilience journey, identifying risks that could prevent them from delivering important business services within tolerances in severe but plausible scenarios. It helps the firms’ boards and senior management make informed investment decisions to address resilience gaps.
We assess the status of a firm’s implementation of our policy. This includes reviewing:
- their important business services, impact tolerances and additional metrics
- scenario testing details, results and assurance that the firm can remain within impact tolerances in severe but plausible scenarios
- firms’ identification of risks, threats, and vulnerabilities through mapping, testing and live incidents
- response and recovery actions, remediation plans and timelines
Self-assessments allow us to identify good practices at an individual firm level while also facilitating thematic comparisons, helping us build a clearer picture of the wider systemic operational resilience picture across the industry.
Incident management and reporting
The PRA has published a policy that details requirements for reporting certain operational incidents, and notification and reporting of material third-party arrangements. It sets out expectations for regulatory reporting, which aim to enhance the PRA’s understanding of firm and sector threats and vulnerabilities.
Third-party management
The PRA’s current policy is set out primarily in Supervisory Statement (SS) 2/21: Outsourcing and third party risk management, which was published in March 2021. The Bank has a near-identical set of policies for FMIs, such as clearing houses and payment systems.
Operational risk framework
Our role is to assess whether a firm's operational risk management framework allows them to effectively identify, assess, monitor, report and manage material operational risks to which it is or might be exposed, in line with board-approved strategy and risk appetite.
We are also responsible for assessing whether firms hold sufficient capital to mitigate the impact when operational risks crystallise.
This supports the Internal Capital Adequacy Assessment Rules, which require us to assess whether firms’ own funds and internal capital is adequate to cover the level of the risks to which it is or might be exposed and is reflective of the firm’s operational risk profile.
Cyber resilience
Firms and FMIs should assess their cyber risk and build adequate resilience capabilities to prepare for, and respond to, potentially disruptive cyber incidents. To maintain the financial sector's cyber resilience and to support our supervisory oversight, we have developed cyber assessment tools. They include CBEST, STAR-FS and CQUEST.
CBEST
This provides a framework for regulators to work with firms using a simulated cyberattack. This allows firms to explore how to counteract an attack on the people, processes and technology of cyber security controls. We base the simulated attacks on present threats.
The aim is to test:
- a firm's defences
- its threat intelligence capability
- its ability to detect and respond to external and internal attackers
Firms use the assessment to plan how they can strengthen their resilience.
An accredited service provider carries out the simulation, acting within legal, ethical and moral constraints. It aims to get through a firm's defences using the cyber kill chain. They also assess if the confidentiality, integrity or availability of systems and processes that deliver a firm's important business services can be compromised.
CBEST thematic review
The annual CBEST thematic is intended to inform the sector on the findings and lessons learned from our CBEST programme, which assesses the cyber resilience of key financial institutions through security testing performed in ‘live’ corporate environments.
STAR-FS
STAR-FS (simulated targeted attack and response assessments for financial services) is part of the PRA and FCA supervisory toolkit, to assess the cyber resilience of firms' important business services. This allows regulators and firms to better understand vulnerabilities and take remedial actions, thereby improving their resilience and, by extension, the wider financial system.
It promotes a threat-led penetration testing approach that mimics the actions of actors' intent on compromising an organisation's important business services as well as the technology assets and people supporting them.
An implementation guide and supporting templates are available. If your firm is interested in conducting a STAR-FS please contact your supervisor. It aims to provide:
- an outcome-based assessment of financial institutions' protection, detection and response technical capabilities against cyber-attacks;
- an approach, conducted through a firm-led delivery model, that can identify cyber resilience vulnerabilities within systems, people and processes;
- reduced regulatory and firm effort relative to other supervisory technical assessments such as CBEST;
- levels of independent technical assurance beyond those ordinarily included in firms' own penetration testing programmes; and
- a testing approach accessible by a larger number of financial institutions to experience and learn from.