The “Develop Strategy and Roadmap” stage is a crucial component of the “Plan” phase in AmBank Malaysia’s Operational Resilience Planning Methodology.
This stage ensures that insights from prior assessments—such as business impact analysis (BIA), risk assessment, and dependency mapping—are translated into a structured plan that aligns with AmBank’s strategic goals.
By bridging the gap between the current state and the desired level of operational resilience, this stage creates a practical, actionable roadmap for strengthening AmBank’s ability to withstand disruptions and continue critical business services.
Purpose: Establish clear resilience objectives that align with AmBank’s business strategy, regulatory requirements, and risk appetite.
Implementation:
Example:
If a prior assessment identified real-time payment processing as a critical function vulnerable to cyber threats, the resilience objective might be:
“Ensure that the real-time payment system can recover within 30 minutes of a cyber disruption, meeting regulatory requirements and minimising customer impact.”
Purpose: Establish specific strategies to enhance resilience across critical areas such as people, processes, technology, and third-party dependencies.
Implementation:
Example:
To ensure uninterrupted digital banking services, AmBank might adopt a hybrid cloud strategy, allowing seamless failover to a secondary cloud provider in the event of a primary data center outage.
Purpose: Establish a phased approach to implementing resilience strategies with defined timelines and milestones.
Implementation:
Example:
A short-term goal could be implementing an enhanced incident response framework for cybersecurity threats. A medium-term goal might involve conducting resilience testing for AmBank’s digital banking infrastructure.
Purpose: Ensure that the operational resilience strategy complies with local and international regulations.
Implementation:
Example:
If BNM mandates a maximum recovery time for critical services, AmBank could integrate this requirement into its technology resilience strategy, ensuring compliance through regular testing and audits.
Purpose: Obtain executive approval and ensure adequate resources for successful implementation.
Implementation:
Example:
If AmBank’s executives are concerned about financial impacts, presenting cost-benefit analyses of investing in AI-driven fraud detection or automated incident response can strengthen the case for resilience funding.
Purpose: Ensure resilience strategies remain effective amid evolving threats and business changes.
Implementation:
Example:
AmBank could implement an automated resilience dashboard tracking system to monitor uptime, incident response times, and recovery success rates, ensuring continuous oversight.
The “Develop Strategy and Roadmap” stage transforms assessments into action, creating a structured path toward operational resilience at AmBank Malaysia.
By setting clear objectives, defining strategic priorities, and aligning efforts with regulatory expectations, AmBank can enhance its ability to anticipate, withstand, and recover from disruptions.
This roadmap serves as the foundation for the next phase: Implementation and Testing, where strategies are put into practice and resilience is rigorously validated.
| Operational Resilience Framework: A Case Study of AmBank Malaysia | |||||
| "Plan" Phase of the Operational Resilience Planning Methodology | |||||
| C2 | C3 | C4 | C5 | C6 | C7 |
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|