Cyber risk stress testing for banks
This report examines cyber risk stress testing for banks, contrasting system-focused and firm-focused approaches. Drawing on exercises by the Bank of England, the Danish Financial Supervisory Authority, and the European Central Bank, it outlines scenario design, operational resilience, and the role of disclosure in establishing best practices.
Please login or join for free to read more.
OVERVIEW
Introduction
In response to the increasing frequency and sophistication of cyber incidents, authorities have adopted various tools to test firms’ preparedness for managing cyber risk. While penetration and red team tests, such as the TIBER-EU and CBEST frameworks, simulate attacks on live systems to identify vulnerabilities, scenario-based stress testing focuses on operational resilience. These stress tests assume that preventative measures have already failed and focus on firms’ incident response and recovery. Although these exercises cannot fully replicate real-life incidents, they provide valuable insights into the effectiveness of response processes and allow both authorities and firms to identify critical arrangements and weaknesses in their strategies. However, experience in conducting these tests remains limited, and disclosure is often restricted to preserve confidentiality and avoid exposing participating firms to malicious attacks.
Defining a cyber stress test
Authorities typically cover cyber risk in stress testing in two ways. The first integrates cyber risk within existing financial stress testing, placing emphasis on financial losses like liquidity shortages stemming from an attack. The second approach, which is the focus of this report, treats cyber risk separately and assesses the operational capability of firms and the financial system at large during a crisis cycle. These exercises are often conducted in a table-top format and differ from traditional solvency tests as they lack a single quantitative indicator to measure impact. Instead, they are viewed as learning opportunities and exploratory exercises rather than pass/fail tests. Moving away from a purely quantitative focus means that system-wide assessments stem from reviewing whether firms have sufficient capabilities to respond and recover from disruptions affecting the broader financial system.
Two approaches to cyber stress testing
The primary decision for an authority is whether to focus on the operational resilience of individual firms or the financial system as a whole. A system-focused exercise assesses how individual firm responses contribute to the resilience of the entire system, helping participants understand the potential financial stability impacts of their service disruptions. This approach is particularly valuable as firms may otherwise prioritise their own recovery without fully accounting for the externalities their decisions impose on the system. Conversely, firm-focused exercises concentrate on detecting deficiencies in specific organisational frameworks and are more likely to involve a formal supervisory relationship. Table 2 highlights that system-focused exercises often involve voluntary participation and cooperative relationships, whereas firm-focused tests are frequently compulsory and conducted at arm’s length.
Planning a cyber stress test
Planning involves determining the appropriate scope and designing a suitable stress scenario. Authorities must strike a balance between comprehensiveness and practicality when selecting a sample of banks. For system-focused tests, including essential nodes like financial market infrastructures (FMIs) and non-financial third-party service providers is crucial to capture shock propagation. In contrast, firm-focused tests often require a larger sample of domestic banks to allow for benchmarking and the identification of outliers. Resource requirements are high, necessitating inter-disciplinary expertise across information technology, legal, and financial stability departments. Scenario design is based on a qualitative narrative of a severe but plausible disruption, though specific details are often withheld from public reports to prevent exposing vulnerabilities to malicious agents.
Conduct and results of a cyber stress test
The active phase begins when firms activate their response plans following a simulated shock. Authorities review the quality of these plans, focusing on the activation of contingency processes and communication with external stakeholders, including the management of reputational risk. Feedback is gathered through questionnaires, which may be more detailed for firm-focused exercises to support prudential assessments. Authorities may use peer benchmarking or dedicated workshops to ensure the reliability of qualitative answers. In the European Central Bank’s exercise, a subsample of 28 banks was subject to on-site inspections to validate their responses. Results can be presented using metrics of operational continuity, such as the time required to restore critical functions. Early findings indicate that banks that had underinvested in cybersecurity prior to the exercises increased their investment significantly following the test.
Follow-up and disclosure
Following the completion of an exercise, authorities provide confidential individual reports to participating firms regarding their performance. In firm-focused tests, outcomes may feed into regular supervisory activities, such as the Supervisory Review and Evaluation Process (SREP), although they may not immediately trigger changes in capital requirements. In system-focused tests, follow-up efforts focus on sector-led initiatives to improve collective resilience. While public disclosure is limited due to the sensitive nature of the data, sharing aggregate findings and general lessons is beneficial for firms that did not participate. For instance, the Danish Financial Supervisory Authority published five key lessons emphasizing the importance of conservative recovery time assumptions and the critical role of ex-ante preparation. Such disclosure helps raise awareness among board members and establishes industry best practices.
Concluding reflections
Cyber risk stress testing is still in its early stages but has emerged as a vital tool for authorities and financial firms to enhance operational resilience. As there is currently no established template for these exercises, authorities should choose the approach that best aligns with their institutional mandates and objectives. Future developments may include repeating tests to improve the quality of firm responses over time and incorporating cross-border or cross-sectoral elements to reflect the interconnected nature of the financial system. Broad participation, including non-bank financial institutions and critical third-party providers, is encouraged to ensure a comprehensive view of systemic vulnerabilities. Ultimately, continued methodological refinement and the transparent disclosure of general findings will help reduce the risk that a “weakest link” endangers the stability of the entire financial system.