Formerly known as Global Research & Risk Solutions
Playbook for polycrisis
Ways banks can shore up resilience and mitigate overlapping disruptions
In the interwoven global financial environment, a disruption for a bank can spiral into loss of customer confidence and a market crisis. To mitigate this risk, banks require a practical resilience playbook with a focus on safeguarding customer outcomes through well-defined governance, mapped critical services and dependencies, realistic simulations and a resilient technology architecture that maintains service continuity within established tolerance thresholds.
The polycrisis threat
Banks are operating in a polycrisis environment, with a convergence of multiple, interconnected disruptions increasing risks and challenging traditional business models. A single disruption, such as a payment systems failure, can lead to a surge in customer service inquiries, or a vendor-related issue can cascade into liquidity concerns expressed on social media platforms while a cybersecurity breach can erode customer trust. The repercussions can be far-reaching, as illustrated by the November 2023 ransomware attack on the Industrial and Commercial Bank of China's arm in the United States (US), which necessitated manual processing and disrupted US Treasury settlements, turning an operational incident into a market and confidence crisis.
Why resilience matters
What the banks require is resilience—the ability to withstand stress, sustain operations within set limits and recover without improvisation. Regulatory bodies expect banks to identify important business services (the services customers depend on most), establish impact tolerance levels and evaluate performance in realistic scenarios. The focus is on outcomes with business continuity, ensuring customers can access these critical services even during disruptions.
Customer experience at risk
A United Kingdom (UK) Treasury Committee report on information technology outages stated nine major UK banks and building societies recorded at least 803 hours (33+ days) of unplanned technological and systems outages between calendar years 2023 and 2025, leaving customers unable to access accounts or make transactions.
Customers experience outages as:
- “I can’t make a payment.”
- “My card keeps getting declined.”
- “I can’t log in.”
- “The branch can’t process cash.”
Resilience should be built around these important business functions, such as payment processing, card services, cash access and digital channels. Mapping dependencies (people, procedures, applications, infrastructure, data, third parties and facilities) helps identify the critical links that determine whether a customer service survives a crisis.
How effective governance frameworks can make or break a bank’s crisis response
During the first hour of an outlier incident, the response quality often hinges on a fundamental question: do teams across the banks know who has the authority to make decisions, and how can they take action promptly?
The US Federal Reserve’s investigation into the March 2023 bank failures shed light on the importance of effective governance and risk management. In the case of Silicon Valley Bank, the rapid expansion had led to a “less effective board and management”, resulting in delayed responses to escalating vulnerabilities (i.e., more surprises, slower decisions).
Effective governance is not about proliferating committees. Rather, it requires clarity on decision rights (for incident commanders, business owners, technology owners and communications lead) and demands pre-defined escalation triggers tied to customer impact and Board visibility for material service disruptions. Supervisory authorities have been explicit that operational resilience is about management outcomes and accountability and not simply having policies in place.
Preparedness for compound shocks through rehearsals and simulations
Banks often focus on preparing for single, well-defined events, but real-world disruptions often defy such simplicity. The Bank of England and Prudential Regulation Authority have observed incidents such as cyberattacks rarely cause isolated problems—they trigger multiple, concurrent impacts (data breaches, service outages and fraud).
A practical exercise that consistently improves preparedness is the two-shock simulation:
- A cyber event that restricts privileged access, while a key third-party service degrades (payment processing, identity verification, messaging services and market data)
- Customer volumes spike even as a regulator requests an update within a tight deadline
Effective preparedness is not about identifying individual shortcomings, but rather about cultivating the muscle memory needed for seamless cross-functional coordination. This requires close collaboration across multiple disciplines, including risk management, operations, IT, treasury, legal, compliance, customer experience and communications working together. In response, banks are actively investing in these five areas—business continuity planning, third-party risk management, scenario planning, technology resilience and recovery and incident management.
Beyond recovery speed with technology resilience
The financial sector has suffered more than 20,000 cyberattacks and $12 billion in losses (International Monetary Fund, 2004–2023). While recovery-time objectives and metrics matter, resilience is about maintaining service within impact tolerances even when parts of the ecosystem are impaired. This raises a critical question: Can the bank continue to deliver its services within its impact tolerance while parts of its ecosystem are impaired?
Key strategies include:
- Graceful degradation: Deliver a ‘payments-lite’ experience during stress
- Manual workarounds: Train teams for manual and semi-manual processes
- Alternate routing: Ensure critical messages get through
- Segmented access: Limit reliance on a few experts
Third-party risk management: Know your critical suppliers
In 2025, SituAMC, a US-based mortgage services vendor, suffered a cyber breach that exposed loan-related data linked to major banks such as JPMorgan Chase and Citigroup. The banks demonstrated resilience by keeping core operations fully functional, rapidly assessing exposure with forensic teams, notifying regulators and customers, and tightening third-party risk controls to prevent recurrence.
To be resilient during such disruptions, banks must classify suppliers by service criticality, not just by expenditure or risk:
- If this vendor fails, which customer service fails first?
- How quickly would customers notice?
- What is the credible workaround?
- When was it last tested end-to-end?
Supervisory guidance increasingly highlights third-party dependency management as central to operational resilience.
A simple checklist for a resilience-focused approach that has a significant impact involves the following:
- Pick three to five important business services (payments, cards, cash, digital channels, trade)
- Map dependencies to identify true break points (people, systems, third parties)
- Establish tolerance levels for impacts that align with customer outcomes and regulatory expectations
- Run a two-shock exercise, including communications and third-party participation
- Fund two to three fixes to remove bottlenecks (monitoring gaps, access procedures, failover steps, communications templates), and then re-evaluate the results
The final takeaway
In today’s interconnected crisis environment, banks encounter multiple disruptions that can escalate from operational incidents into market crises and loss of confidence. Developing resilience requires a fundamental shift from reactive crisis management to proactive design focused on customer needs.
Banks must transition beyond traditional thinking centered on single points of failure to manage compound risks through well-defined governance frameworks, realistic multi-shock simulations and technology architectures designed for graceful degradation while maintaining service within impact tolerances.
The future course requires three essential steps: designing resilience based on customer outcomes rather than technical metrics, operationalising cross-functional capabilities to manage cascading disruptions and transforming third-party relationships into partnerships that enhance resilience.
Banks that can maintain service quality during disruptions—starting with identifying three-five critical business services, testing compound scenarios and funding targeted fixes—will gain a competitive edge in an era where operational resilience determines not just regulatory compliance but also market survival and customer confidence.
Explore Crisil, a company of S&P Global