prorso

Treating ransomware risk to core banking services

By · Published

A UK retail bank decides how to treat ransomware risk to its important business services: accept, mitigate, transfer through cyber insurance, or mitigate with an isolated recovery environment. Insuran...

The options

The question: How should ransomware risk to core banking services be treated: accept the current control set, mitigate through defence in depth and recoverability, transfer through cyber insurance, or invest in isolated recovery with insurance retained for financial loss only?

Option 1: Accept: continue with the current control set and existing backups

Against

  • Risk. The option places the firm outside the impact tolerance it has set and would have to explain to its supervisor. That is a failed constraint rather than a poor score, and it removes the option from consideration whatever its cost advantage.
  • Risk. Backups reachable from production are the failure the peer incident turned on. The option's recovery figure assumes off-site copies survive an attacker who has already demonstrated the ability to reach everything the production credentials reach.

Option 2: Mitigate: defence in depth across the estate, with segmentation and hardened backups

For

  • Benefit. The mitigation option follows the layered approach the official guidance recommends, so the firm can evidence its control set against a published reference rather than against its own judgement.
  • Official guidance. The National Cyber Security Centre's guidance on mitigating malware and ransomware attacks recommends a defence-in-depth approach: layers of defence with several mitigations at each layer, so that there are multiple opportunities to detect and stop malware before it causes harm. The mitigation options below are constructed on that principle rather than on a single control.

Against

  • Risk. The regulatory position rests on a recovery time the firm has never demonstrated at full scale. A rehearsal that restores components is not evidence about rebuilding a core platform, and the supervisor is entitled to ask which one was tested.
  • Risk. Hardened is not isolated. If an attacker obtains administrative credentials, backups protected by policy rather than by disconnection remain within reach, and the option's recovery figure becomes the accept option's figure.

Option 3: Transfer: purchase cyber insurance covering incident response and business interruption

For

  • Benefit. Insurance is the fastest treatment to put in place and brings access to incident response retainers and negotiation expertise the firm does not hold internally.

Against

  • Risk. The word transfer flatters this option. What transfers is a share of the financial loss; what does not transfer is the six days without payments, the transactions lost, the supervisory consequence and the customers who leave. For a bank those are most of the harm.
  • Risk. The transferable share depends on waiting periods, sub-limits and exclusions in policy wording the firm has not yet reviewed, and on terms that are renegotiated at each renewal. Cover assumed today may not exist on the same terms when it is needed.
  • Official guidance. The payment guidance in the previous node was published jointly with the UK insurance associations, which signals that insurers do not want policies to encourage payment. Because payment is excluded here, the relevant uncertainty is the scope of business interruption and incident response cover and its exclusions, which this log treats as a judgement to be confirmed with the broker rather than as a figure.

Option 4: Mitigate with isolated recovery: defence in depth plus an immutable, disconnected recovery environment, with insurance retained for financial loss

For

  • Benefit. An immutable, disconnected recovery environment removes the dependency that both the accept and mitigate options carry: that some copy of the data survives an attacker with production credentials.
  • Risk. Hardened is not isolated. If an attacker obtains administrative credentials, backups protected by policy rather than by disconnection remain within reach, and the option's recovery figure becomes the accept option's figure.
  • Recommendation. That the board risk committee adopt defence in depth with an isolated recovery environment, retaining insurance for the residual financial loss. It is the only option designed to stay within the 72-hour impact tolerance with margin, subject to the full rebuild rehearsal in the first action, and the only one that retires rather than manages the assumption that an attacker reaching production also reaches the backups. It is also the slowest to take effect, so cyber cover is bound at the next renewal as an interim measure. Defence in depth alone is not preferred: its tolerance position depends on hardened backups surviving an attacker with administrative credentials and leaves twelve hours of margin. Insurance alone is rejected: it changes no disruption figure, and tolerance is expressed in disruption. The word transfer describes what happens to part of the money, not to the risk.

Against

  • Risk. An isolated environment that is never exercised is an assumption rather than a capability. Its value depends entirely on rehearsal, and rehearsing a full core rebuild is disruptive enough that it tends to be deferred.
  • Risk. It is the most expensive option by a wide margin, and the increment over defence in depth alone buys a difference that only materialises in an incident that may not occur. That is a real argument against it and not a presentational one. The retained insurance is not what the increment buys: cover could equally be added to defence in depth alone, so the case rests on the isolated environment.

Criteria and values

CriterionOption 1Option 2Option 3Option 4
Annual cost of the treatment (lower is better)0 GBP2,900,000 GBP1,400,000 GBP4,600,000 GBP
Data loss window (lower is better)24 hour4 hour24 hour4 hour
Time to restore core services (lower is better)144 hour60 hour144 hour24 hour
Operational resilience position (higher is better)outsidemarginaloutsidewithin
Residual risk (lower is better)highmoderatehighlow
Time to take effect (lower is better)—18 month3 month24 month
Share of expected loss transferable (higher is better)0%0%——

What constrained the decision

Evidence

Related decisions

Open the interactive log

Spotted an error? Report a problem (ivan@ivanjureta.com). Corrections are listed on the page with their date.