Financial services might be conducting cyber simulations, but they’re not testing cyber skills

Financial services might be conducting cyber simulations, but they’re not testing cyber skills

Financial services are being encouraged to carry out cyber simulations to ensure organisations are prepared for cyberattacks. Dan Potter, Senior Director of Operational Resilience at Immersive, outlines the challenges which arise with regards to cyber simulations and what can be done to improve resilience.

The Bank of England has urged financial services firms to have robust plans in place to deliver important business services, no matter the disruption, including in the event of a cyberattack.

To bolster operational resilience, the Bank of England is calling for organisations to conduct severe-but-plausible scenario exercises with growing levels of sophistication. The focus is firmly on cyber-risks, especially across supply chains and the wider financial ecosystem.

Cyber exercises must assess response capabilities, overall preparedness and business-wide resilience to minimise harm to recipients of important services. This demands a new approach to exercising.

However, research by Immersive shows that financial services firms have only made incremental improvements in their response times when taking part in cyber simulation exercises.

Dan Potter, Senior Director of Operational Resilience at Immersive, explains why organisations are struggling to improve their response times and what can be done to make financial services more resilient.

Where are organisations struggling exactly when it comes to cyber simulations?

Cybersecurity is more prominent and more proactively governed today than ever before. Boards, business leaders and P&L owners are more informed and aware of the risk than ever before, and organisations across the globe are investing at record scale.

Cybersecurity’s improved visibility, however, isn’t translating into financial services organisations being ready to deal with a cyberattack.

Our research, which includes data from 151 financial services organisations using Immersive’s simulations and exercises, found that teams achieved a dismal 22% accuracy and took 29 hours to contain incidents. Tellingly, only 31% of organisations actually completed the entire simulation.

Ultimately, effort and investment alone aren’t translating into faster or more effective responses. Response plans and cyber crisis playbooks are falling short. Under pressure, most teams didn’t fail due to a lack of knowledge; they failed due to a lack of practised coordination.

Yet despite the clear issues revealed in simulated cyber incidents, we find most organisations still believe they are ready for a real crisis. In fact, 94% of companies told us they are confident they could effectively detect, respond to and recover from a major incident.

Why is there a disconnect between cyber simulation results and leaders’ mindsets?

The reason for the disconnect across financial services is that organisations are measuring resilience incorrectly.

True resilience comes from continuously testing and improving readiness at every level of the business, so that when a real crisis hits, confidence is based on evidence, not assumption.

Instead, many organisations still overly rely on metrics such as awareness-training completion rates, tabletop-exercise attendance and policy-adherence scores. While these indicators may, on one level, satisfy a compliance requirement for boards, executives and cyber insurance carriers, they do not reflect actual crisis performance. Indeed, more mature organisations realise this and know that something more than an annual ‘tick box’ measurement is required.

Yet these metrics are of little value when it comes to assessing real-world readiness. In a genuine cyber crisis, the skills that matter are communication, decision-making and the ability to perform under pressure; not simply completing a test.

Moreover, by focusing only on completion, no one in the organisation can accurately predict how quickly a team could contain a ransomware outbreak or restore operations following a breach.

How is this all affecting readiness in dealing with cyberattacks?

Financial services are not struggling with readiness due to a lack of will. In fact, 78% of boards and senior leaders consider cybersecurity a major business priority. The challenge lies in execution.

Organisations that are genuinely improving their cyber-readiness should see significantly reduced response times. Yet within financial services, response times have improved only marginally.

Part of this stagnation is a continued overemphasis on training for outdated threats. We found that 60% of training exercises focus on vulnerabilities more than two years old, and four of the five most-practised CVEs stem from legacy issues. Teams are preparing for attacks that adversaries have already moved beyond.

As a result, organisations develop superficial preparedness for past threats, leaving themselves vulnerable to novel attack vectors, reduced adaptability and growing exposure to emerging risks. With the threat landscape constantly evolving, you can’t keep re-running last year’s battle; you need to evolve your skills and agility.

Moreover, many organisations remain stuck at beginner-level readiness, never progressing toward true maturity or resilience. Without advancing beyond the basics, teams fail to develop deeper judgement, tactical agility or the ability to respond to multi-stage, novel attacks, leading to weak defences when stress and uncertainty collide.

How should financial services conduct simulations correctly?

For a cyber simulation to be effective, it must be tailored and built around clear objectives. Security and resilience leaders should first define what they want to achieve and the cyber skills they want to improve.

Without clear goals, exercises risk becoming box-ticking tasks with little practical value. Scenarios should reflect the types of attacks most likely to target the organisation. Threats vary widely by industry, so running irrelevant simulations wastes time and offers little benefit.

Cybersecurity is a business-wide issue, so simulations should involve non-technical decision-makers such as HR, legal and PR. Organisations only include roles outside of IT and security 41% of the time, meaning that critical decision-making interfaces go untested.

After each exercise, a thorough review should capture lessons learned and highlight skill gaps. Simulations should also be run regularly. While full organisation-wide drills may be infrequent, smaller, focused exercises help teams build the muscle memory needed to perform under pressure during a real cyber incident.

Organisations that use cyber simulations to develop cyber skills actively will turn a perception gap among boards and leaders into true resilience.

Browse our latest issue

Intelligent Fin.tech

View Magazine Archive