Cyber Attack Tabletop Exercises are critical to business continuity and recovery after cybersecurity incidents. Their importance is regularly reiterated by regulators and insurers across the world who demand proof of consistent cybersecurity incident scenario testing. This is no surprise given the massive rise in a wide range of security incidents, ransomware attacks and breaches of sensitive information. And the implications of such attacks and breaches only magnify in the world of financial services.
With all the talk around the EU DORA that comes into force in January 2025, it’s important to remember that the UK’s Financial Conduct Authority too, requires exacting standards of operational and business continuity. It also mandates demonstration and validation of the same. Financial businesses that seek to be compliant with the UK Financial Conduct Authority (FCA) need to demonstrate their commitment to business continuity with regular 'scenario testing' exercises.
Topics covered in this article:
1. What does Scenario Testing Entail?
2. FCA's Exact Requirements for Scenario Testing
3. How to Conduct a Successful Scenario-based Test?
Incident Response Scenario Testing helps you scrutinise the effectiveness of your existing cyber incident response plans and the key staff members' familiarity with them and their individual roles and responsibilities.
The FCA also focuses on identifying areas for improvement, lessons learned and ultimately creating confidence in the business's security posture. After the testing, firms are expected to review the outcomes diligently and update their cyber resilience plans accordingly. This approach aligns with the FCA's broader objective of ensuring that financial markets function well and that consumers remain protected. However, regular tabletop testing will yield many immediate benefits to your business beyond compliance which we’ll come to later.
In the next few sections, we show you how to fulfil the FCA’s Cyber Security Requirements and how to successfully conduct operational resilience testing with simulations of cyber tabletop exercise scenarios. But first let us understand what the FCA says about regular Cyber Tabletop Exercises.
The Financial Conduct Authority, the conduct regulator for financial firms and financial markets in the UK, places a high degree of importance on tabletop testing as a part of firms' operational resilience strategies.
In the FCA Handbook’s section titled Senior Management Arrangements, Systems and Controls (SYSC), Chapter 15, Rule A.5.3 is dedicated to Scenario Testing. Here is what it says, “A firm must carry out scenario testing, to assess its ability to remain within its impact tolerance for each of its important business services in the event of a severe but plausible disruption of its operations.”
Guidance 15.A.5.2 says that firms must pay attention to the type of scenario being tested, the frequency of testing, how the firm will communicate with important stakeholders about operational disruptions, amongst many other things.
Essentially, the FCA guidelines mandate that regulated financial institutions conduct these tests to examine and validate their business continuity plans, cyber incident response plans, and recovery strategies. These cyber tabletop exercises, when conducted professionally, aim to uncover vulnerabilities in a controlled environment and ensure that all staff members are familiar with procedures to follow during actual operational disruptions.
It is obviously clear now that to maintain adherence to the Financial Conduct Authority (FCA) standards, it is imperative to conduct effective yet comprehensive cyber testing drills.
However, running an effective cyber attack simulation drill can be overwhelming for the average business and their internal security teams.
This is where bringing an expert external facilitator on board, such as Cyber Management Alliance, can be really helpful. We have helped over 300 businesses achieve their cyber resilience goals and compliance with various regulators’ directives through our globally-recognised Cyber Crisis Tabletop Exercises. What makes us stand out in the market is the fact that our scenario testing exercises are designed and often conducted by the world’s most experienced cyber tabletop facilitator.
Some of the ways in which our Cyber Crisis Simulation Drills stand out in the market include: