Financial institutions store large amounts of sensitive data. Banks and other organisations in the financial sector are becoming increasingly popular targets for cybercriminals. This is one of the reasons why the issue of digital resilience is becoming increasingly important for the financial sector. Operational disruptions can quickly lead to significant losses. It makes no difference whether these are triggered by cyber-attacks, physical threats or geopolitical risks – when processes come to a standstill, it becomes costly, and confidence in the financial system is also undermined.
What role do supervisory authorities play in strengthening resilience?
Financial authorities in Europe and beyond are responding with new assessment and testing tools. These are designed to ensure that regulatory requirements are effectively implemented and that institutions’ resilience is robust. So-called cyber resilience stress tests (CRSTs) play a central role in this regard; these have recently gained significant importance both as part of the ECB CRST 2024 and through national resilience exercises.
Essentially, these are scenario-based exercises in which financial institutions must identify the impacts and consequences of a serious threat scenario and assess them using a comprehensive questionnaire. Another key feature is the focus on how effectively the measures actually work in day-to-day operations, as well as an organisation-wide perspective, as all functions must work together in a coordinated manner in the event of an emergency.
How do cyber resilience stress tests work in practice?
These exercises cover all phases of incident management – starting with the detection of the incident right through to the existing response and recovery measures. These measures are activated in the event of an incident to manage a critical cyber security incident and restore service delivery to customers and partners. The findings must then be reported to the supervisory authorities.
Furthermore, the information provided in the scenario and questionnaire must be supported by appropriate evidence to ensure it reflects the organisation’s actual situation. Furthermore, additional requirements are incorporated, such as the test reporting of the incident to the supervisory authority or the conduct of IT disaster recovery tests in accordance with regulatory requirements. As part of the “ECB Cyber Resilience Stress Test”, the exercise for 28 selected banks even involves the actual implementationof response and recovery measures, including an IT disaster recovery test, as part of an on-site inspection.
How do you ensure that your scenarios are realistic and robust?
The fact that the CRST is not a one-off exercise but a new tool for financial supervisory authorities becomes clear when considering further developments: A total of eight national supervisory authorities have been conducting national exercises since 2024, modelled on the ECB’s Cyber Resilience Stress Test, and the German Federal Financial Supervisory Authority (BaFin) also announced in its report on “Risks in the Focus of Supervision”, that it would carry out cross-sector crisis management and emergency exercises involving simulated cyber-attacks. Whilst the focus has so far been on cyber-attacks, current developments – such as the emphasis placed in the ECB’s 2026 stress test – suggest that physical and geopolitical threats are also increasingly coming into focus.
A move towards a Digital Resilience Stress Test to evaluate an organisation’s own digital resilience
Restoring operations following an incident requires, amongst other things, appropriate response and recovery plans. In this regard, DORA requires specific scenarios to be covered, which all financial firms must take into account; these include not only cyber-attacks but also physical and geopolitical risks, such as the failure of operational sites and data centres, widespread power cuts, as well as the insolvency or failure of relevant third-party ICT service providers.
For advanced financial institutions, it is advisable to additionally consider further – and, where appropriate, combined – scenarios based on their own risk profile. In doing so, greater consideration should also be given to scenarios such as long-term service provider failures or the failure of the firm’s own sites and staff. As pure cyber resilience stress tests do not fully cover these comprehensive risks, a move towards a Digital Resilience Stress Test (DRST) is recommended. This approach enables a holistic assessment of an organisation’s own resilience.
To demonstrate regulatory compliance whilst simultaneously testing an organisation’s own capabilities, KPMG recommends including at least one such scenario-based end-to-end test in the resilience test plan.
How KPMG supports you
KPMG possesses extensive specialist expertise in all relevant disciplines relating to CRST and DRST. Our wide-ranging project experience, gained from supporting several EuropeanEuropean banks in the ECB stress test, as well as from client projects involving the implementation of their own exercises, has also provided us with valuable insights and knowledge that help us to better understand our clients’ challenges and requirements. Using our DRST process model, we develop bespoke solutions based on a modular approach.
Is your regulatory authority planning to conduct a cyber or digital resilience stress test, and are you taking part? We would be happy to support you in preparing for and carrying out the exercise. Our services include:
- Raising awareness amongst the Executive Board, the 1st and 2nd lines of business through workshops and by assessing their alignment with previous CRSTs
- Preparing for the stress test by conducting a CRST readiness assessment of the relevant guidelines, processes and evidence
- Support in managing the exercise and coordinating the stakeholders involved
- If required, also the organisation of crisis team&exercises based on the respective scenario, in order to generate appropriate evidence and realistically assess your readiness for actual incidents
We work with you to prepare for the conduct of a stress test. We offer you a selection of predefined scenarios based on the regulatory requirements for scenario-based testing:
- Cyber-attacks involving encryption malware
- Geopolitical instability and the associated failure of critical service providers
- ICT failures resulting from failed changes
- Brown- & blackouts lasting from a few hours to several days
- AI manipulation leading to errors in processes and workflows
Depending on the scenario you choose, you will receive a tailor-made questionnaire that enables you to realistically assess your digital resilience. In addition to a structured overview, you will gain specific insights into your response and recovery capabilities – based on regulatory requirements, current technical standards and tried-and-tested best practices. Supplementary guidance documents and regular consultation forums will help you to address the questions efficiently and ensure a consistent understanding across the organisation.
Once the assessment has been completed, your results will be systematically analysed. You will gain a clear picture of where you stand today, where risks lie and which specific measures will strengthen your resilience – prioritised and ready for immediate implementation.
To continuously improve your organisation’s digital resilience, it is advisable to repeat the tests at regular intervals. This also applies to digital resilience stress tests. To ensure the necessary comparability and scalability of the assessment, we therefore offer to implement a DRST on a leading low-code platform.
As part of the implementation, in addition to the basic questionnaire for the general evaluation of resilience, we integrate, as required, several scenario-specific question profiles which can be filled in depending on the respective scenario, and provide you with the corresponding scenarios. We adopt an adaptive approach that allows the scope of the questionnaire to be adjusted or existing questions to be aligned more closely with your governance requirements.
During implementation, our tool solution enables the questions it contains to be delegated to the relevant roles and departments. Through the integration of relevant reporting functions, you can track current progress and thus maintain an overview of the project’s progress.
As an extension of the DRST, we are also on hand to advise you on identifying further scenarios relevant to you and your organisation and to prepare theseprepare them for use within the framework of a DRST.
In doing so, we support you in identifying current risks and in developing appropriate scenarios and questions. In doing so, we not only take into account the applicable regulations (DORA, NIS2, etc.), but also consider state-of-the-art recommendations based on current norms and standards such as ISO 27001, ISO 22301 and the IT-Grundschutz.
Further interesting content for you
Your contact
Peter Hertlein
Partner, Financial Services, IT Compliance & Cyber resilience
KPMG AG Wirtschaftsprüfungsgesellschaft