It's a Tuesday morning. Every computer in your organization is offline. Phones are ringing. The lobby is filling up. Social media is already running ahead of you — speculation, some of it wrong, some of it worse than what's actually happening. Nobody on your team knows when systems will be back. Nobody knows what to say.

Here is the question that determines whether your organization survives this: Did you already decide what your people would do?

Because if you are deciding now, you have already lost.

The financial sector has been playing defense in the cyber arena for years. The adversaries — some of them nation-states — are not standing still. They are investing in their offense and AI tools are making it easier for them to increase pace and scale. We are patching our perimeter. That gap does not close on its own, and it does not close faster than they are widening it.

The military understood something about this a long time ago. You cannot train people to make good decisions under fire. You can train them to execute critical decisions that have already been made. In the US Navy, at the sound of General Quarters everyone gets to their designated station, every role is understood, every action is predetermined and with regular, drills the timing is well understood by all involved. When the alarm sounds, nobody improvises. They execute.

That is what resilience planning is. Not a document. Not a framework to be reviewed annually and filed. A rehearsed response to a known scenario, embedded in the people who have to carry it out.

Enhancement To Your DR/BC Plan

Regulations require that all financial institutions have disaster recovery and business continuity plans. Most of those plans were designed to restore full operations — bring systems back, rebuild networks, recover data. That is the right goal. Eventually.

The assumption embedded in those plans is that you have time. For severe cyber scenarios, you do not.

When depositors see the bank is offline, we have hours — not days — before confidence starts eroding into something you cannot reverse. Withdrawals accelerate in institutions not impacted by the cyber outage. Regulators move. The institution that was debilitated by the attack becomes the institution that failed to survive it. Those are two different failures. Only the second one is fatal.

Cyber Resilience Plans are built entirely around this short window. They trade scope for speed. They do not try to restore everything. They focus on minimum viable operations only. In the case of a retail bank, they are designed to restore two critical business services fast enough to prevent panic:

  • Access to balance information for every account.
  • The ability to transact against those balances.

This is the entire purpose of pre-establishing the big decisions (like the minimum viable bank), and then getting the staff to practice their role through General Quarters drills. Keep the customer from panicking. Buy the time the DR/BC plan needs to bring the organization back to normal. The two plans are not competitors — they are symbiotic. One keeps you alive long enough for the other to finish.

Learning to Think Differently

To conduct a General Quarters drill, you have to start from an assumption that feels extreme: Your systems are gone. Not degraded. Not partially compromised. Gone — and any data still in them is either destroyed or unreliable. Think Mythos — an AI-powered attack tool that finds your vulnerabilities and writes the exploit code simultaneously — unleashed on your organization.

Now what?

Before you can answer that, you have to answer three questions that many organizations have not formally resolved: How will you communicate with customers when your normal channels are part of what's offline? Who makes which decisions, and do they have the authority to make them on short notice without convening a committee? What will you tell the media — and when?

These questions cannot be answered in the middle of an attack. They have to be answered in advance, documented, distributed, and rehearsed until the answers are automatic. That is the discipline. The planning is not the hard part. Getting an entire organization to operate in a fundamentally different mode — immediately, under duress, without their normal systems — is the hard part. The key to answering these questions is part of a proactive approach.

The financial sector's early adopters learned this the direct way. Getting everyone on board requires planning and training across the entire institution, not just the technology team. Becoming resilient is a C-suite responsibility, because the decisions embedded in the plan are C-suite decisions.

What General Quarters Looks Like

Here is a condensed picture of what happens when Bank of X sounds General Quarters.

The executive war room activates. The resilience plan is activated. The bank is now running on the interim platform, providing customers access to their balances and the ability to transact. Leadership has command and control from a designated location, using communication channels that were pre-identified because not all of them will be available.

The branch manager does not call the home office. She already knows how to access the restoration platform, as well as when to expect it to come online. She knows which manual processes apply. She knows the cash distribution limits in effect during the event. Her tellers know how to record transactions manually against accounts if needed. This was rehearsed. The customer standing at the window does not get "I have no idea what's happening." They get a calm, informed explanation and access to their money.

The PR team opens the crisis communications playbook. A pre-approved communication goes to the media immediately — the bank is experiencing a cyber disruption and has activated a rehearsed response plan. It does not speculate. It does not apologize. It has already been approved by Legal for release. Subsequent releases are already written, already approved, and scheduled on a defined timeline, each one providing more specificity as the restoration progresses. The social media team has its own playbook. Nobody is drafting copy during an active attack.

The ATM network requires a specific call. If the network is separate from whatever hit the bank's core systems, it may still be running — these networks are accustomed to operating under stand-in instructions. But they expect an overnight refresh of balances from the production systems. Those systems are gone. Your ATM Network Manager contacts your provider and redirects that refresh to the restoration platform. If that transition was not planned in advance, the ATMs stop working too. One more customer-facing failure, one more accelerant to the panic.

The regulatory conversation is not a surprise. Your designated executive contacts regulators who already know your plan exists. The topics, the cadence, and the timeframes were pre-established. US financial regulators have been explicit on this point: if an institution has a resilience plan, they will allow the institution to execute it with sector support and minimal interference. If there is no plan, they will not have the flexibility to stand back. The presence of a plan changes the regulatory dynamic entirely.

The call center shifts to the cyber outage playbook. Representatives — whether internal staff or a contracted provider — echo the PR communications initially. As the restoration platform brings account information online, call center agents gain new capabilities: they can now verify customer identity and provide account-specific information. They know how to do this on the restoration platform because they have practiced it.

Treasury moves immediately. Funding sources are contacted, including non-standard alternates identified in the plan. Liquidity and funding protocols for this kind of event are already written. Restrictions on withdrawal amounts by customer group may be in effect. None of this is invented during the event.

The Discipline Behind the Drill

For any of this to work, every action above had to be anticipated, planned, designed, negotiated with external parties, tested, and rehearsed until it became automatic.

That word — automatic — is the whole point. Most people do not rise to the occasion under this kind of pressure. They fall to their level of preparation. An organization that has rehearsed this scenario responds with controlled execution. An organization that has not responds with improvisation, confusion, and decisions made by whoever happens to be in the room.

After working with several hundred participating financial institutions, we have learned one thing: Resilience planning that does not have executive ownership does not get implemented. And US financial regulators have confirmed what the data shows — any institution without an established plan for this kind of event will not survive it. The preparation has to happen before the event. There is no other sequence that works.

Resilience - by Design works with institutions to define, develop, and prove their cyber response and recovery capabilities — establishing a baseline for maintaining critical services and building the muscle memory your people need before General Quarters is called for real. The question is not whether your institution will face a devastating cyber outage. The question is when you do, does everyone already know what to do.

← Back to All Insights