Treating ransomware risk to core banking services
A UK retail bank decides how to treat ransomware risk to its important business services: accept, mitigate, transfer through cyber insurance, or mitigate with an isolated recovery environment. Insuran...
The options
The question: How should ransomware risk to core banking services be treated: accept the current control set, mitigate through defence in depth and recoverability, transfer through cyber insurance, or invest in isolated recovery with insurance retained for financial loss only?
Option 1: Accept: continue with the current control set and existing backups
Against
- Risk. The option places the firm outside the impact tolerance it has set and would have to explain to its supervisor. That is a failed constraint rather than a poor score, and it removes the option from consideration whatever its cost advantage.
- Risk. Backups reachable from production are the failure the peer incident turned on. The option's recovery figure assumes off-site copies survive an attacker who has already demonstrated the ability to reach everything the production credentials reach.
Option 2: Mitigate: defence in depth across the estate, with segmentation and hardened backups
For
- Benefit. The mitigation option follows the layered approach the official guidance recommends, so the firm can evidence its control set against a published reference rather than against its own judgement.
- Official guidance. The National Cyber Security Centre's guidance on mitigating malware and ransomware attacks recommends a defence-in-depth approach: layers of defence with several mitigations at each layer, so that there are multiple opportunities to detect and stop malware before it causes harm. The mitigation options below are constructed on that principle rather than on a single control.
Against
- Risk. The regulatory position rests on a recovery time the firm has never demonstrated at full scale. A rehearsal that restores components is not evidence about rebuilding a core platform, and the supervisor is entitled to ask which one was tested.
- Risk. Hardened is not isolated. If an attacker obtains administrative credentials, backups protected by policy rather than by disconnection remain within reach, and the option's recovery figure becomes the accept option's figure.
Option 3: Transfer: purchase cyber insurance covering incident response and business interruption
For
- Benefit. Insurance is the fastest treatment to put in place and brings access to incident response retainers and negotiation expertise the firm does not hold internally.
Against
- Risk. The word transfer flatters this option. What transfers is a share of the financial loss; what does not transfer is the six days without payments, the transactions lost, the supervisory consequence and the customers who leave. For a bank those are most of the harm.
- Risk. The transferable share depends on waiting periods, sub-limits and exclusions in policy wording the firm has not yet reviewed, and on terms that are renegotiated at each renewal. Cover assumed today may not exist on the same terms when it is needed.
- Official guidance. The payment guidance in the previous node was published jointly with the UK insurance associations, which signals that insurers do not want policies to encourage payment. Because payment is excluded here, the relevant uncertainty is the scope of business interruption and incident response cover and its exclusions, which this log treats as a judgement to be confirmed with the broker rather than as a figure.
Option 4: Mitigate with isolated recovery: defence in depth plus an immutable, disconnected recovery environment, with insurance retained for financial loss
For
- Benefit. An immutable, disconnected recovery environment removes the dependency that both the accept and mitigate options carry: that some copy of the data survives an attacker with production credentials.
- Risk. Hardened is not isolated. If an attacker obtains administrative credentials, backups protected by policy rather than by disconnection remain within reach, and the option's recovery figure becomes the accept option's figure.
- Recommendation. That the board risk committee adopt defence in depth with an isolated recovery environment, retaining insurance for the residual financial loss. It is the only option designed to stay within the 72-hour impact tolerance with margin, subject to the full rebuild rehearsal in the first action, and the only one that retires rather than manages the assumption that an attacker reaching production also reaches the backups. It is also the slowest to take effect, so cyber cover is bound at the next renewal as an interim measure. Defence in depth alone is not preferred: its tolerance position depends on hardened backups surviving an attacker with administrative credentials and leaves twelve hours of margin. Insurance alone is rejected: it changes no disruption figure, and tolerance is expressed in disruption. The word transfer describes what happens to part of the money, not to the risk.
Against
- Risk. An isolated environment that is never exercised is an assumption rather than a capability. Its value depends entirely on rehearsal, and rehearsing a full core rebuild is disruptive enough that it tends to be deferred.
- Risk. It is the most expensive option by a wide margin, and the increment over defence in depth alone buys a difference that only materialises in an incident that may not occur. That is a real argument against it and not a presentational one. The retained insurance is not what the increment buys: cover could equally be added to defence in depth alone, so the case rests on the isolated environment.
Criteria and values
| Criterion | Option 1 | Option 2 | Option 3 | Option 4 |
|---|---|---|---|---|
| Annual cost of the treatment | 0 GBP | 2,900,000 GBP | 1,400,000 GBP | 4,600,000 GBP |
| Data loss window | 24 hour | 4 hour | 24 hour | 4 hour |
| Time to restore core services | 144 hour | 60 hour | 144 hour | 24 hour |
| Operational resilience position | outside | marginal | outside | within |
| Residual risk | high | moderate | high | low |
| Time to take effect | — | 18 month | 3 month | 24 month |
| Share of expected loss transferable | 0% | 0% | — | — |
What constrained the decision
- Constraint. The firm must be able to remain within the impact tolerance it has set for each important business service. For retail payments the tolerance is 72 hours of disruption, measured from the onset of disruption. A treatment that cannot be evidenced as keeping the firm within tolerance is not adequate however cheap it is, and the position of each option is therefore a criterion.
- Constraint. Paying a ransom is not an available treatment. It is not endorsed by law enforcement, it does not guarantee that an incident ends or that malicious software is removed, and it would not be defensible to the firm's supervisor. No option below assumes payment.
- Assumption. An attacker who reaches the production environment can also reach any backup reachable from it using the same credentials. This is assumed rather than demonstrated, and it is the assumption that separates the two mitigation options from one another.
- Assumption. Recovery time figures assume the recovery procedure works as documented. The firm has not rehearsed a full core platform rebuild from backup; it has rehearsed component restores. The difference between those two exercises is the main uncertainty in the figures below.
Evidence
- Standard. NIST has published a ransomware community profile of the Cybersecurity Framework 2.0, translating the framework into practical actions for managing and mitigating ransomware risk. It is the reference against which the control set in the mitigation options was assembled and against which coverage gaps were identified.
- Official guidance. The payment guidance in the previous node was published jointly with the UK insurance associations, which signals that insurers do not want policies to encourage payment. Because payment is excluded here, the relevant uncertainty is the scope of business interruption and incident response cover and its exclusions, which this log treats as a judgement to be confirmed with the broker rather than as a figure.