back_to_insights

// INSIGHTS · CYBER & OPERATIONAL RESILIENCE

The false confidence of resilience.

You can pass a resilience assessment without being able to recover. The governance artefacts are largely in place across financial services. Evidence that someone has watched a critical service come back, and timed it, is harder to find.

IMAGE: PHOTO BY MJH SHIKDER ON UNSPLASH

The paperwork has got much better. Across financial services the governance artefacts are now largely in place: policies, a named owner for each important business service, an impact tolerance signed off, a maturity score moving in the right direction. What is harder to find is evidence that someone has watched a critical service come back and timed it.

// 01Why the paperwork improved

Two things drove the improvement. Firms have been on the hook since 31 March 2025 for staying within impact tolerances for each important business service, and boards have been paying closer attention since the 2025 retail attacks.

The Cyber Security and Resilience Bill, now through second reading in the Lords, will put comparable expectations on data centres, managed service providers and the IT suppliers behind regulated firms — part of why resilience is now a board-level issue.

The result is a great deal more evidence. Whether it is evidence of the right thing is a separate question, and the FCA has already answered it.

// 02What the evidence usually proves

The FCA published its findings a year on from the deadline in March. One line stands out: some firms state in their self-assessments that there is no scenario they would not be able to recover from, but include no evidence of having tested this using sufficiently severe scenarios.

That claim is worth sitting with before the question of testing even arises, because no scenario at all is a remarkable thing to put in writing. It takes in the ransomware that reaches the backup estate as readily as the key supplier going dark for a fortnight. It holds for every important business service, on any day of the year, with whoever is available. Little a firm could say about itself claims more, and the FCA's point is that it usually arrives with nothing behind it.

In practice the confidence comes from failures that have already been rehearsed: a lost data centre, a failed node, a supplier with a contractual alternative ready. It gets stretched to cover the ones nobody has rehearsed, which is what the FCA's phrase "sufficiently severe" is doing. The regulator's good practice asks firms to widen scenario testing and to write down their assumptions and the recovery times claimed. Those assumptions are where the confidence sits, and most have never been written down.

// 03What maturity scoring rewards

Maturity scoring against NCSC CAF or NIST CSF rewards what is present and documented: a policy exists, an owner is named, the recovery procedure is written down and under version control. All of that is real work, and none of it tells you the service comes back. We found the same pattern in alerting on an alert management maturity review: strong tooling, weak ownership, output nobody trusted.

// PLANS VERSUS RECOVERY

Among UK large businesses, 76% now hold a formal incident response plan. In At-Bay's analysis of US ransomware insurance claims, 92% of the businesses hit had a backup solution — and only 63% of those got their data back.

// 04Testing what you have already claimed

None of this argues against assessment. There is a case for treating the self-assessment as a starting point, because the sentence that matters is a narrow one: whether this named service can be restored by the people who happen to be on shift, inside the tolerance the board signed off.

That is harder to evidence, and it runs through more than technology. The FCA found the same seam from the other side. Mapping, it noted, has been largely focused on the technology supporting important business services, when it also needs to cover facilities, people, processes, information and third-party resilience — the transparency business architecture is built to provide. The restore path runs through all of those, and so does the incident.

Nobody is being dishonest here. Each part is usually done properly in isolation, and what tends to be missing is the exercise that tests them together: one important business service, worked backwards from its impact tolerance through the technology, the people on shift at three in the morning and the third parties in the chain, then run against a scenario nobody wrote the answers to first.

// 05What good evidence looks like

Evidence that answers it is unglamorous: a date, the service tested, the scenario, who was in the room, the point it was genuinely usable again, and a list of what had to be improvised. That last item is the useful one.

"A test that produced no improvisation was probably not severe enough."

TOM HURST · PRINCIPAL CYBER CONSULTANT

Our new Operational and Cyber Resilience service is built around that gap, and it does more than mark the homework. We map the services that have to keep running, trace them to the technology, people and third parties underneath, build the plans and playbooks that protect them, then exercise the lot until it holds. What comes out is evidence a board and a regulator can both use, and a named owner to keep it current.

// SOURCESReferences

// PRODUCT · AXIOSECURE

Know your real exposure, not just your maturity score.

AxioSECURE is a comprehensive cyber risk and resilience assessment, typically four to six weeks, built with Precursor Security. It assesses your exposure to the threats that matter — ransomware, insider threat, supply chain attacks — and how well placed you are to withstand and recover from them.

It looks across people, process, technology and your extended ecosystem, informed by targeted threat intelligence, with deep dives into key controls to establish whether they work rather than simply exist. You leave with a prioritised risk reduction roadmap, assessments against NCSC CAF and NIST CSF, and technical findings your engineers can act on. Real-world testing and simulation exercises are available as an option.

WHAT THE ASSESSMENT COVERS

01
Maturity assessment

Cyber and resilience maturity against NIST CSF and NCSC CAF.

02
Threat exposure

Ransomware, supply chain attacks and critical partner disruption.

03
Controls validation

Deep dives into key controls to prove they work, not just exist.

04
Attack surface mapping

External exposure, internal controls and targeted threat intelligence.

05
Optional red team

Real-world testing, social engineering and simulation exercises.

06
A prioritised proposal

Ranked actions, with where we and Precursor can support you next.