Treating ransomware risk to core banking services
A UK retail bank decides how to treat ransomware risk to its important business services: accept, mitigate, transfer through cyber insurance, or mitigate with an isolated recovery environment. Insuran...
Published content
- node: Context. The organisation is a mid-sized retail bank in the United Kingdom, subject to the PRA and FCA operational resilience rules, with approximately 1.2 million customers, operating a core banking platform, a payments gateway and a customer channel estate. Two comparable institutions in the same market suffered ransomware incidents in the previous eighteen months, one of which was unable to process payments for six days. The rules have required the firm to be able to remain within its impact tolerances since March 2025, and its latest self-assessment could not evidence that for payments under a severe but plausible ransomware scenario.
- node: How should ransomware risk to core banking services be treated: accept the current control set, mitigate through defence in depth and recoverability, transfer through cyber insurance, or invest in isolated recovery with insurance retained for financial loss only?
- node: Benefit. The mitigation option follows the layered approach the official guidance recommends, so the firm can evidence its control set against a published reference rather than against its own judgement.
- node: Benefit. Insurance is the fastest treatment to put in place and brings access to incident response retainers and negotiation expertise the firm does not hold internally.
- node: Benefit. An immutable, disconnected recovery environment removes the dependency that both the accept and mitigate options carry: that some copy of the data survives an attacker with production credentials.
- node: Decision-maker. The board risk committee, on the recommendation of the Chief Risk Officer and the Chief Information Security Officer. Operational resilience for important business services is reserved to the committee and is not delegated to executive management.
- node: Risk. The option places the firm outside the impact tolerance it has set and would have to explain to its supervisor. That is a failed constraint rather than a poor score, and it removes the option from consideration whatever its cost advantage.
- node: Scope. The decision covers the treatment of ransomware risk to the services identified as important business services. It does not cover the wider security programme, the choice of core platform, or the firm's incident response arrangements, which exist and are exercised separately.
- node: Consulted. Internal audit on the evidence base for the impact tolerance position; the insurance broker on what the market will carry over the next three renewals; technology operations on the feasibility of a full rebuild rehearsal; and the supervisor informally on the adequacy of the intended evidence.
- node: Risk. Backups reachable from production are the failure the peer incident turned on. The option's recovery figure assumes off-site copies survive an attacker who has already demonstrated the ability to reach everything the production credentials reach.
- node: Risk. The regulatory position rests on a recovery time the firm has never demonstrated at full scale. A rehearsal that restores components is not evidence about rebuilding a core platform, and the supervisor is entitled to ask which one was tested.
- node: Risk. The word transfer flatters this option. What transfers is a share of the financial loss; what does not transfer is the six days without payments, the transactions lost, the supervisory consequence and the customers who leave. For a bank those are most of the harm.
- node: Risk. An isolated environment that is never exercised is an assumption rather than a capability. Its value depends entirely on rehearsal, and rehearsing a full core rebuild is disruptive enough that it tends to be deferred.
- node: Action. Rehearse a full core platform rebuild from the isolated environment within six months of it being established, and annually thereafter. The recovery time and the tolerance position both rest on this, and neither is evidenced until it has been done once.
- node: Constraint. The firm must be able to remain within the impact tolerance it has set for each important business service. For retail payments the tolerance is 72 hours of disruption, measured from the onset of disruption. A treatment that cannot be evidenced as keeping the firm within tolerance is not adequate however cheap it is, and the position of each option is therefore a criterion.
- node: Risk. Hardened is not isolated. If an attacker obtains administrative credentials, backups protected by policy rather than by disconnection remain within reach, and the option's recovery figure becomes the accept option's figure.
- node: Risk. The transferable share depends on waiting periods, sub-limits and exclusions in policy wording the firm has not yet reviewed, and on terms that are renegotiated at each renewal. Cover assumed today may not exist on the same terms when it is needed.
- node: Risk. It is the most expensive option by a wide margin, and the increment over defence in depth alone buys a difference that only materialises in an incident that may not occur. That is a real argument against it and not a presentational one. The retained insurance is not what the increment buys: cover could equally be added to defence in depth alone, so the case rests on the isolated environment.
- node: Action. Record the assumption that an attacker reaching production reaches the backups, and test it deliberately in the next red team exercise. The whole increment over defence in depth is bought to retire that assumption.
- node: Constraint. Paying a ransom is not an available treatment. It is not endorsed by law enforcement, it does not guarantee that an incident ends or that malicious software is removed, and it would not be defensible to the firm's supervisor. No option below assumes payment.
- node: Action. Review the policy wording specifically for what is excluded rather than what is covered, and report the excluded categories to the committee alongside the premium. The transferable share is the least understood figure in this decision and the one most likely to be misread as larger than it is.
- node: Official guidance. The National Cyber Security Centre's guidance on mitigating malware and ransomware attacks recommends a defence-in-depth approach: layers of defence with several mitigations at each layer, so that there are multiple opportunities to detect and stop malware before it causes harm. The mitigation options below are constructed on that principle rather than on a single control.
- node: Action. Bind cyber cover covering incident response and business interruption at the next renewal, ahead of the isolated environment, so that part of the financial consequence is covered during the estimated 24-month build. Review the terms again once the environment is in place, when the premium should fall.
- node: Standard. NIST has published a ransomware community profile of the Cybersecurity Framework 2.0, translating the framework into practical actions for managing and mitigating ransomware risk. It is the reference against which the control set in the mitigation options was assembled and against which coverage gaps were identified.
- node: Official guidance. NCSC guidance for organisations considering payment in ransomware incidents records that law enforcement do not encourage, endorse or condone payment, that payment does not guarantee the end of an incident or the removal of malicious software, and that it provides incentives for further criminal activity. This is the basis for excluding payment as a treatment rather than pricing it as one.
- node: Review trigger. If the first full rebuild rehearsal exceeds the impact tolerance, the tolerance position is not evidenced and the committee must be told before the next supervisory return, not after the next rehearsal.
- node: Official guidance. The payment guidance in the previous node was published jointly with the UK insurance associations, which signals that insurers do not want policies to encourage payment. Because payment is excluded here, the relevant uncertainty is the scope of business interruption and incident response cover and its exclusions, which this log treats as a judgement to be confirmed with the broker rather than as a figure.
- node: Review trigger. If cyber cover narrows materially at renewal, reassess. The recommendation treats insurance as covering a residual; if the residual it covers shrinks, more of the loss returns to the firm and the case for further mitigation strengthens.
- node: Assumption. An attacker who reaches the production environment can also reach any backup reachable from it using the same credentials. This is assumed rather than demonstrated, and it is the assumption that separates the two mitigation options from one another.
- node: Review trigger. If a peer institution suffers an incident in which an isolated recovery environment was itself compromised, reassess the residual risk assessment immediately. The option's low residual rests on that architecture holding.
- node: Assumption. Recovery time figures assume the recovery procedure works as documented. The firm has not rehearsed a full core platform rebuild from backup; it has rehearsed component restores. The difference between those two exercises is the main uncertainty in the figures below.
- node: Accept: continue with the current control set and existing backups
- node: Mitigate: defence in depth across the estate, with segmentation and hardened backups
- node: Transfer: purchase cyber insurance covering incident response and business interruption
- node: Mitigate with isolated recovery: defence in depth plus an immutable, disconnected recovery environment, with insurance retained for financial loss
- node: Recommendation. That the board risk committee adopt defence in depth with an isolated recovery environment, retaining insurance for the residual financial loss. It is the only option designed to stay within the 72-hour impact tolerance with margin, subject to the full rebuild rehearsal in the first action, and the only one that retires rather than manages the assumption that an attacker reaching production also reaches the backups. It is also the slowest to take effect, so cyber cover is bound at the next renewal as an interim measure. Defence in depth alone is not preferred: its tolerance position depends on hardened backups surviving an attacker with administrative credentials and leaves twelve hours of margin. Insurance alone is rejected: it changes no disruption figure, and tolerance is expressed in disruption. The word transfer describes what happens to part of the money, not to the risk.