The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.

Moving beyond the checklist

For years, operational resilience centred heavily on documentation, standards, and audits. However, static, internally focused compliance struggles to match the speed and complexity of the modern risk landscape. The broader operating environment highlights why a fresh approach is needed:

  • Financial impact: A single ransomware attack in 2025 erased roughly a third of a major UK retailer's annual operating profit. 
  • Supply chain vulnerabilities: Third-party involvement in breaches doubled year-on-year to 30%, according to Verizon's 2025 Data Breach Investigations Report. 
  • Volume of threats: A record 48,000 Common Vulnerabilities and Exposures (CVEs) were published recently, yet fewer than a third were fully analysed. 

Technical incidents require flexible recovery options

When a technical disruption occurs, the impact rarely stays confined to the IT department. Because every incident is unique, financial services firms benefit from having a variety of recovery plan options available to maintain operations.

True resilience relies on flexibility rather than a single, rigid path to recovery. Some scenarios require targeted recovery at the application level, focusing on restoring specific databases, software stacks, or technical infrastructure. Other scenarios demand a broader response at the business-service level, protecting the end-to-end customer outcome, regulatory reporting, and executive decision-making regardless of the underlying tech.

Operational excellence isn't about choosing one approach over the other; it is about having the capability to seamlessly deploy the right strategy at the right time.

Third-party risk management

Third-party risk remains one of the greatest resilience challenges across the sector. While most firms understand their immediate tier-one suppliers, gaining meaningful visibility deeper into the supply chain, and knowing exactly who retains access to systems and data, is increasingly critical.

Proactive governance plays a key role here. Reviewing supplier contracts to ensure they include robust security obligations, rapid notification requirements, and enforceable remediation timelines helps mitigate exposure. Furthermore, addressing the growing dependence on a small number of cloud and logistics providers is vital for managing systemic concentration risk across the financial sector. 

Capability beats compliance

Perhaps the clearest takeaway from the conference was the distinction between compliance and capability. Compliance provides valuable evidence at a single point in time. Capability, however, is demonstrated continuously through regular exercising, measurement, and ongoing improvement.

The value of active testing is significant:

  • The testing gap: One FTSE 100 organisation reported that more than half of its critical suppliers had not participated in a resilience exercise during the previous year. 
  • Value protected: Conversely, another organisation demonstrated that measuring and improving every resilience plan it executes protects more than £10 million in value annually.

Ultimately, what gets measured gets managed. The long-term objective is building organisations that grow stronger through disruption, using every incident, near miss, and exercise to refine their capabilities. Compliance is the essential starting point; dynamic capability is the true competitive advantage. 

The strategic path forward

Closing the gap between compliance and capability requires three shifts:

  1. Unify resilience by connecting cybersecurity, business continuity, and operations around critical business services.
  2. Embed continuous exercising so testing becomes an operational discipline rather than an annual obligation.
  3. Measure business outcomes, complementing simple pass/fail metrics with clear evidence of financial and operational value protected.

This evolution is as much cultural as it is technical. By framing resilience in practical business terms alongside regulatory language, firms can move beyond the baseline checklist and build a lasting operational advantage.

About the Authors: Joleen Engela and Richard Ashby are resilience specialists at CLDigital, a leading provider of connected risk and resilience software.

Tags: