Building Operational Resilience for Financial Services: Is Your Ship Seaworthy?
Shelby Flora recently asked several non-executive directors on U.S. and UK financial services boards a simple question.
Had any of their institutions come to the board asking for money to test recovery environments more often or to improve visibility across their networks?
Every one of them said no.
Flora, a managing director and the UKIA financial services security lead at Accenture Security, shared the exchange near the end of a recent Security Awareness Special Interest Group (SASIG) webinar for financial services security leaders. She’d also asked the directors whether they were worried about how fast the threat landscape is changing. Each one said yes. When she asked if they’d back a resilience initiative led by the chief operating officer, they said yes again.
That exchange captures where much of the financial sector sits today. Banks and insurers have spent years building operational resilience frameworks, and at least some of their boards appear ready to fund the next step. What’s missing is the request, backed by proof that those plans will hold once an attacker is inside. That proof comes from three habits: mapping dependencies well enough to contain an attack, running cyber resilience testing as a routine drill, and bringing the board a clear plan with the chief operating officer (COO) behind it.
Good documentation doesn’t keep banks afloat
Documentation matters. It’s the foundation for every framework banks answer to, from threat-led testing to the Prudential Regulation Authority’s (PRA) expectations for important business services.
The trouble is that documents describe the environment someone designed, while attackers move through the environment that exists today.
Those two pictures drift apart over time. Most banking environments have grown through decades of projects, acquisitions, and workarounds, and every change adds complexity.
Complexity creates seams, and seams are where attackers find ways to move up or across environments. The Bank of England’s CBEST thematic findings have highlighted the same weak spots year after year, a pattern Illumio unpacked in its analysis of the 2025 CBEST report.
Complexity also shapes what happens on the worst day. During a live incident, teams work in a "fog of war" where dependencies aren’t fully understood, visibility is partial, and the runbook may not match what’s on the network. That uncertainty breeds hesitation where responders worry that a containment action could cause more disruption than the attack itself.
In calm hindsight, the right call often looks obvious. In the moment, a delay can give an attacker the time they need to spread.
A seaworthy framework for financial services cyber resilience
When the moderator asked which investments should come first, Flora reached back to her childhood in Missouri, when weekends meant boating on the lake. Learning to drive a boat, she said, starts with safety checks and never really ends, because a good captain keeps inspecting, repairing, and upgrading the vessel.
Her analogy doubles as a checklist for CISOs.
Run the safety checks before you leave the dock
Every trip begins with a look for obvious leaks. In security terms, that means strong core controls and steady patching, with no high or critical vulnerabilities left open. It also means holding a firm line on end-of-life technology.
Flora noted that attackers still lean heavily on older flaws in legacy software, because old, unpatched flaws are easier to exploit than new ones. Any unsupported system should have a funded plan for retirement.
Inspect the hull for hidden leaks
Good maintenance starts with knowing where the weak spots are. That means mapping which systems talk to each other and what depends on what. The critical systems are usually well known, but surprising dependencies often sit behind them.
Third parties deserve the same scrutiny. When you know what access a supplier has, where that access lands, and what depends on those systems, you can model the blast radius of a supplier compromise before it happens. That same map shows what normal traffic looks like, so teams can spot lateral movement early.
Plug the holes with modern materials
Duct tape only holds a hull together for so long. Many banks built segmentation around network topology, forcing traffic through firewalls placed between zones. Firewalls still play a valuable role at key boundaries, yet stretching them into broad internal segmentation drives capital and operating costs up quickly.
Microsegmentation applies policy where it’s needed, close to the workloads themselves, which makes it practical to limit how far an attacker can travel. It also suits modern development. Teams can write segmentation policy as code and deploy it through their CI/CD pipelines, so new applications launch with security built in from day one.
Replace the rotting wood with steel
Some repairs call for a rebuild. The Bank of England spent several years renewing its real-time gross settlement service, which settles high-value sterling payments. It shows what a deliberate upgrade to core infrastructure looks like.
Projects like that take time and money, and they leave the whole system stronger. Each institution must decide which aging platforms behind its core transactions are ready for the same treatment.
Practice using the lifeboat until it’s second nature
Even a well-kept boat can take on water, so the lifeboat has to work. For banks, lifeboats are recovery environments, and they only help if they start up quickly after sitting dormant.
This is where cyber resilience testing earns its keep. Flora described advising a large multinational institution to test containment and recovery every two weeks, when the institution had asked about testing every two months.
Her reasoning was simple: the technology estate changes every day, and the threat landscape changes with it. She also estimated that the time from spotting a new vulnerability to its first confirmed exploit has shrunk from more than two years in 2018 to a matter of days.
Testing that often sounds heavy, but much of it can be automated. Checks that confirm controls fire when they should can run on their own, which frees people to rehearse the decisions.
Those rehearsals should reach beyond the security team to executives and, more and more, to board members who want a seat at scenario exercises. The goal is muscle memory, so nobody is reading the incident response plan for the first time on the worst day of the year.
Decide who steers when the water rises
Automated containment, where a system isolates critical assets without waiting for approval, is an appealing goal.
AI-driven recommendations keep improving, and confidence scores help responders make faster, better-informed choices. But for now, a human in the loop still matters, especially in a sector where one bad day can ripple across the economy.
Moving toward automation takes work on two fronts:
- The technical work. Containment can only happen where you have policy control. Environments assembled through acquisitions often lack enforcement points in the right places.
- The governance work. The chief operating officer, chief risk officer, risk committees, and regulators should agree ahead of time on what response is appropriate and who makes the call.
It helps to start from an assume-breach mindset, too. As Russell Goodwin, a distinguished solutions architect at Illumio, said, even a critical system can be compromised, so every plan should account for where an attacker could go next.
In Flora’s experience, the institutions moving fastest to prepare for AI-accelerated attacks are the ones where the COO leads the effort. COOs oversee risk, technology, and security together, so they can clear a path for CIOs, CTOs, CISOs, and communications leaders to work as one team.
Flora added that there’s no such thing as overcommunication during an incident. The worst outcomes usually trace back to confusion about which decisions need to be made and who owns them.
Pragmatism keeps that team moving. Start with your important business services, then add a threat-led view of how criminal groups and nation-state actors are most likely to strike.
Architecture teams can be cautious about a new approach, so a pilot in a limited environment lets them validate controls and obligations before scaling up. Trying to protect everything at once is how programs stall in analysis paralysis.
Operational resilience won’t wait for calmer water
Frontier AI models are changing the economics of cyberattacks. The time and skill it takes to find and exploit a weakness keep dropping, so intrusions will move faster. Recovery at machine speed is quickly becoming the standard financial institutions will be held to.
The directors Flora spoke with are already worried, and they’re ready to back a COO-led plan. They’re waiting for someone to ask. CISOs who bring a clear map of their dependencies and a record of frequent, realistic testing can make that request with evidence in hand. The sooner they do, the sooner a plan on paper becomes a ship that stays afloat when the water starts coming in.
視聴 full SASIG webinar on demand. Learn how financial institutions can contain breaches and strengthen operational resilience with Illumio.
.webp)


