eBook OR

[OR] [BDCB] [E3] [CBS] [2] [SbPS] Identify Severe but Plausible Scenarios

Written by Dr Goh Moh Heng | Aug 1, 2026, 12:31:51 PM

CBS-2 Currency Management

Introduction


Identifying Severe but Plausible Scenarios is a core component of the Operational Resilience implementation for CBS-2 Currency Management at Brunei Darussalam Central Bank (BDCB).

The purpose is to determine whether BDCB could continue delivering essential currency services or restore them before unacceptable harm occurs when confronted with disruptions that exceed normal operational incidents and materially challenge existing preventive controls, contingency arrangements, recovery capabilities, and management decision-making.

The scenarios must be linked directly to the end-to-end delivery of Currency Management rather than being framed as isolated threats, individual system outages, or generic business continuity events.

A disruption affecting currency forecasting, production, storage, authentication, distribution, accounting, security, or incident management may propagate through interconnected processes and eventually affect the availability, integrity, security, and public acceptability of Brunei Darussalam’s banknotes and coins.

The assessment must therefore consider how an initiating event develops, how it crosses operational boundaries, and whether the resulting disruption could exceed the approved Impact Tolerance for the Critical Business Service.

The 15 Sub-Critical Business Services provide a detailed, process-level basis for identifying scenarios.

Each Sub-CBS represents a distinct part of the currency lifecycle and exposes BDCB to different combinations of operational, people, facility, information, technology, cyber, supplier, logistics, and external-institution risks.

Assessing scenarios at this level helps reveal where failures may originate, where disruption may accumulate, which dependencies could become unavailable simultaneously, and which operational hand-offs are most likely to create cascading consequences.

Cyber and ICT risks are embedded within the scenarios rather than treated as a separate technical assessment.

Currency Management depends on inventory records, secure access-control systems, surveillance, processing equipment, authentication technology, accounting platforms, operational communications, data interfaces, and monitoring capabilities.

A ransomware attack, privileged access compromise, database corruption, network outage, failed technology change, or disruption to a third-party technology service could trigger a currency incident or intensify an existing physical or operational disruption.

Scenario design must consequently test the interaction between digital failure and the physical custody, processing, accounting, and distribution of currency.

The recommended scenarios below are intended to challenge BDCB’s ability to maintain Currency Management within its defined Impact Tolerance. They cover a balanced range of operational, cyber, ICT, people, facility, third-party, security, geopolitical, and infrastructure disruptions.

Collectively, they provide the foundation for subsequent scenario testing, during which BDCB should assess whether its controls, workarounds, recovery arrangements, resources, communications, and governance structures are sufficient to prevent severe but credible disruptions from creating unacceptable harm.

Table 1 (P1): Severe but Plausible Scenarios

Sub-CBS Code

Name of Sub-CBS

Recommended Severe but Plausible Scenario

Scenario Description

Primary Disruption Trigger

Impact on Sub-CBS

Impact on Critical Business Service

CBS-2.1

Currency Demand Forecasting

Forecasting failure during an exceptional surge in currency demand

A major outage affecting electronic payment channels occurs immediately before a peak period of public demand, prompting financial institutions and the public to increase their demand for physical currency. At the same time, a corrupted data feed causes BDCB’s forecasting model to understate demand for several essential denominations. The data-integrity problem is not detected immediately because the operational monitoring dashboard continues displaying apparently valid results based on incomplete information.

Concurrent electronic-payment disruption and corruption or interruption of critical demand, circulation, or economic data feeds.

Forecasts become materially inaccurate at the point when dependable estimates are most important. Currency planners are unable to establish a trusted demand position, determine required denomination volumes, or distinguish temporary demand from a sustained system-wide requirement. Manual forecasting is slowed by incomplete institutional submissions and limited historical comparability.

BDCB may allocate insufficient currency to financial institutions, deplete contingency reserves, or prioritise the wrong denominations. The resulting shortages could constrain access to cash, place pressure on distribution arrangements, and increase the risk that Currency Management exceeds its Impact Tolerance during the demand surge.

CBS-2.2

Currency Production Planning

Loss of production plans and approval capability before a critical manufacturing window

Shortly before production instructions must be finalised, ransomware affects the planning and document-management environment. Approved production schedules, denomination requirements, technical specifications, and decision records become inaccessible. The recovery copy is available but cannot be trusted immediately because the attack may have gone undetected for several weeks. Key approvers are also unavailable due to a concurrent regional emergency.

Ransomware combined with loss of critical decision-makers and uncertainty over the integrity of recovered production records.

BDCB cannot confirm which production plan is authoritative, complete the required approvals, or communicate validated instructions within the supplier’s production window. Attempts to reconstruct the plan are delayed by conflicting working copies and the absence of key personnel.

Missing the production window could delay replenishment of strategic currency reserves for an extended period. If existing reserves are subsequently reduced by higher-than-expected demand or delayed currency returns, BDCB may face insufficient stock to sustain future Currency Management within tolerance.

CBS-2.3

Currency Procurement and Manufacturing Oversight

Prolonged cross-border currency manufacturing and delivery disruption

A specialist currency manufacturer experiences a destructive cyberattack that disables production control systems and compromises quality assurance records. Recovery is delayed by geopolitical restrictions, cross-border transport disruption, and shortages of specialised production materials. A batch already produced cannot be accepted because BDCB cannot obtain reliable evidence that approved security specifications and quality controls were applied.

Cyberattack on a critical external manufacturer, amplified by geopolitical and cross-border supply chain disruptions.

Planned currency production is suspended, quality oversight cannot be completed, and secure delivery dates become uncertain. BDCB must determine whether alternate production capacity exists and whether another provider can meet the required security, quality, and delivery conditions within the available reserve-stock horizon.

Strategic reserve replenishment may be delayed beyond the period covered by existing inventory. If the disruption affects a high-demand denomination or coincides with increased withdrawals, BDCB may be unable to maintain adequate currency availability, potentially breaching the Currency Management Impact Tolerance.

CBS-2.4

Currency Inventory and Vault Management

Primary vault inaccessible with corrupted inventory records

A fire and smoke-control failure makes the primary currency vault inaccessible. During emergency response, a simultaneous database corruption event affects the inventory-management platform and its replicated environment. Physical currency remains within the vault, but BDCB cannot safely access it or establish a trusted record of denomination balances, locations, reserved stock, pending movements, and custody status.

Loss of access to the primary vault combined with corruption of the currency inventory database and uncertainty over replicated records.

Vault withdrawals, deposits, stock verification, and release authorisation are suspended. Staff attempt to activate an alternate facility, but the transfer of operations is slowed because the opening stock position cannot be reconciled to the inaccessible primary vault and recent physical movements.

Currency may be physically available but operationally unusable. BDCB may be unable to fulfil replenishment requests, accept returned currency, or confirm its national stock position. Prolonged loss of vault access and inventory integrity could rapidly breach the Impact Tolerance for Currency Management.

CBS-2.5

Currency Distribution and Replenishment

Nationwide secure distribution disruption during peak cash demand

Severe flooding and infrastructure damage block primary transport routes and restrict access to several financial institutions. Telecommunications outages disrupt dispatch coordination, while the principal secure transport provider lacks sufficient personnel and vehicles to operate alternate routes. The disruption occurs during a period of unusually high cash demand due to widespread disruptions to electronic payment services.

Regional infrastructure disruption combined with telecommunications failures, transport capacity constraints, and elevated demand for physical currency.

BDCB cannot receive or confirm all replenishment requests, establish accurate delivery priorities, coordinate secure dispatches, or maintain normal delivery schedules. Available transport capacity must be allocated among institutions whose existing cash holdings and depletion rates are uncertain.

Financial institutions in affected areas may exhaust essential denominations, leading to restrictions on branches and cash services. Failure to establish alternative distribution routes within the required period could result in geographically widespread shortages and breach the Currency Management Impact Tolerance.

CBS-2.6

Currency Receipt and Return Processing

Returned-currency backlog following processing-centre closure

A contamination event forces the closure of the main currency receipt and processing area for several days. Financial institutions continue accumulating returned and surplus currency but cannot deliver consignments through normal channels. When limited receiving operations resume at an alternate location, the receipt-registration system and counting equipment experience capacity failures due to transaction volumes substantially above their tested limits.

Loss of the primary processing facility, followed by capacity exhaustion at the alternate receiving location and supporting technology.

Returned currency cannot be received, registered, counted, reconciled, or transferred for authentication at the required rate. Secure holding areas become congested, consignment handoffs increase, and discrepancies develop between physical items and receipt records.

Fit currency is delayed from re-entering circulation, suspected counterfeit and unfit currency remain unprocessed, and financial institutions face storage constraints. A prolonged backlog may reduce available currency stock and obstruct the end-to-end circulation cycle, contributing to an Impact Tolerance breach.

CBS-2.7

Currency Authentication and Quality Verification

Compromise of currency authentication technology during a counterfeit campaign

A sophisticated counterfeit campaign begins circulating high-quality fraudulent notes through multiple financial institutions. At the same time, malicious software compromises the configuration of automated authentication devices, increasing the false acceptance rate without triggering obvious equipment alarms. Specialist examiners identify inconsistencies, but the scale of suspected currency exceeds the available capacity for manual examination.

Coordinated counterfeit activity combined with compromise or manipulation of automated authentication equipment.

BDCB cannot rely fully on automated authentication results and must suspend or restrict processing while devices are isolated, examined, and recalibrated. Manual verification creates a significant backlog and delays the release of legitimate currency for recirculation.

Counterfeit notes may remain in circulation, while genuine currency is withheld from distribution. If BDCB cannot establish the integrity of its authentication capability, public and institutional confidence in the currency may be affected and the service may exceed its Impact Tolerance even before the maximum disruption duration is reached.

CBS-2.8

Currency Fitness Sorting and Recirculation Management

Common-mode failure of currency sorting equipment

A failed software update is deployed across currency-sorting machines, causing inconsistent fitness classifications. Some fit notes are classified for destruction, while heavily worn notes are marked as suitable for recirculation. Rollback attempts fail because the previous configuration is incompatible with a recently replaced equipment component, and the available manual-sorting capacity is insufficient for normal volumes.

Failed technology change causing a common-mode failure across concentrated currency-sorting equipment.

Automated sorting is suspended because classification results cannot be trusted. Unsorted currency accumulates, recirculation throughput falls sharply, and additional verification is required for batches processed after the software change.

The supply of fit currency for redistribution declines while demand continues. BDCB may rely more heavily on new stock, increase processing backlogs, and risk returning unsuitable notes to circulation. Extended loss of sorting capacity could contribute to a breach of the Currency Management Impact Tolerance.

CBS-2.9

Counterfeit Currency Investigation and Reporting

Loss of counterfeit intelligence during a multi-location incident

Multiple financial institutions report suspected counterfeit notes sharing previously unseen characteristics. Before the pattern can be analysed, a cyber intrusion compromises the counterfeit case-management environment and secure communication channel used to exchange evidence. Investigators cannot confirm whether case records have been altered or exfiltrated, and external stakeholders receive inconsistent guidance through informal channels.

Cyber intrusion affecting counterfeit intelligence, case integrity, and secure inter-agency communication during an active counterfeit incident.

Case correlation, forensic prioritisation, intelligence assessment, and official reporting are delayed. BDCB cannot establish a reliable consolidated view of affected denominations, geographic spread, or points of introduction, while sensitive investigative data may have been exposed.

Delayed alerts and inconsistent instructions may allow counterfeit currency to circulate more widely. The event can also undermine confidence in currency authenticity and weaken coordination with financial institutions and enforcement bodies, potentially pushing Currency Management beyond tolerance.

CBS-2.10

Currency Destruction and Disposal Management

Destruction-control failure creates uncertainty over destroyed currency

During a high-volume destruction cycle, the destruction-control application fails and recorded batch quantities no longer reconcile with physical input records. Surveillance footage from part of the process is unavailable because the video storage platform reached capacity, while a privileged user account shows unexplained activity. It is unclear whether the event reflects equipment failure, record corruption, insider action, or a coordinated cyber-physical incident.

Simultaneous destruction-system failure, loss of surveillance evidence, and suspected privileged-access compromise.

Destruction activities are suspended. BDCB cannot demonstrate conclusively that all authorised currency was completely destroyed or that no unauthorised batches were introduced. Unfit currency begins accumulating in secure storage while a detailed investigation and physical reconciliation are undertaken.

Although short-term postponement may be manageable, unresolved discrepancies in destruction could affect currency accounting, security, custody integrity, and public confidence. If secure storage capacity becomes constrained or material currency remains unaccounted for, the incident could breach the service’s Impact Tolerance.

CBS-2.11

Currency Accounting and Reconciliation

Corruption of currency accounting and movement records

A failed database change corrupts transaction sequencing across the currency inventory, vault movement, dispatch, receipt, and general ledger interfaces. The inconsistency is discovered during end-of-day reconciliation after a large number of physical movements have already occurred. Backups exist, but restoring them would remove several hours of confirmed activity, and some manual source records are incomplete.

Failed technology change causing data corruption across integrated accounting and currency-movement records.

BDCB cannot establish a reliable balance for currency held, issued, returned, in transit, or awaiting destruction. Further movements are restricted to avoid increasing uncertainty, while teams attempt to reconstruct records from physical documents, system logs, surveillance evidence, and confirmations from financial institutions.

Currency distribution and receipt may be suspended despite physical stock availability. Failure to restore a trusted accounting and custody position within the tolerance period could prevent service continuation, conceal loss or error, and create an immediate threat to Currency Management integrity.

CBS-2.12

Currency Security and Custody Management

Coordinated cyber-physical attack on currency facilities and transport

Threat actors compromise the physical access-control and surveillance environment while simultaneously launching a telecommunications disruption that affects security communications. False alarms are generated at one facility to divert personnel, while sensitive transport schedules are accessed using a compromised privileged account. BDCB cannot determine whether the attack is intended to facilitate theft, sabotage, unauthorised entry, or disruption.

Coordinated cyberattack against physical-security systems, privileged-access compromise, and telecommunications disruption.

Vault access, currency processing, and scheduled transport movements are suspended or restricted until physical safety and control integrity can be confirmed. Manual guards and independent control procedures are activated, but security resources are stretched across multiple facilities and movements.

Because security and custody support nearly every Currency Management process, the disruption can rapidly halt receipt, storage, processing, destruction, and distribution. Any confirmed currency loss, uncontrolled access, or inability to maintain safe custody could constitute an immediate Impact Tolerance breach.

CBS-2.13

Currency Information and Operational Monitoring

Loss of end-to-end situational awareness during concurrent disruptions

The central operational monitoring platform fails during a period when several financial institutions are requesting urgent replenishment and processing equipment is operating below capacity. Local systems remain partially available, but their data cannot be consolidated due to network routing failures and time synchronisation errors. Conflicting reports are received on stock levels, distribution status, processing backlogs, and expected cash depletion.

Failure of central monitoring, network routing, and time synchronisation during concurrent operational degradation.

BDCB management cannot obtain a validated end-to-end service position or determine which reported information is current. Alerts are delayed, thresholds cannot be monitored reliably, and scarce resources may be directed to lower-priority problems.

A manageable disruption may escalate because BDCB cannot identify emerging shortages, processing constraints, or failed deliveries early enough to intervene. Loss of situational awareness could cause the service to cross its Impact Tolerance without timely detection or management escalation.

CBS-2.14

Currency Incident Management and Service Recovery

Failure of incident command during a multi-site Currency Management crisis

A major incident simultaneously affects a currency facility, the inventory platform, and secure distribution. The primary incident-management platform and staff notification service are unavailable due to the same infrastructure outage. Several designated crisis leaders cannot reach the emergency command location, and different teams activate conflicting recovery priorities using outdated copies of response procedures.

A multi-site infrastructure outage is combined with unavailable incident-management technology, loss of key decision-makers, and inconsistent recovery documentation.

Incident declaration, escalation, command activation, stakeholder communication, and resource prioritisation are delayed. Operational teams act independently, duplicate work, and compete for limited security, technology, and transport resources. Recovery milestones are not linked consistently to the Currency Management Impact Tolerance.

The underlying disruption is prolonged by ineffective coordination. Failure to establish command, allocate currency reserves, approve emergency procedures, and communicate with financial institutions could turn multiple recoverable failures into an end-to-end breach of the service tolerance.

CBS-2.15

Regulatory Reporting and Continuous Service Improvement

Suppression of incident evidence and failure to address recurring resilience weaknesses

Following several near misses involving inventory, security, and distribution controls, a cyber compromise affects the document repository and remediation-tracking platform. Incident records, control-test evidence, and management actions are incomplete or inaccessible. Because prior weaknesses cannot be reliably reconstructed, management underestimates the risk of recurrence and postpones remediation. A similar disruption subsequently occurs during a period of higher operational demand.

Compromise or loss of incident, assurance, and remediation information, combined with ineffective governance follow-through.

BDCB cannot prepare complete incident reports, demonstrate the status of corrective actions, or identify whether previously agreed improvements were implemented. Risk acceptance decisions and overdue remediation cannot be verified, weakening management oversight.

The immediate disruption may not stop Currency Management, but the failure to learn and remediate allows known vulnerabilities to persist. A repeated incident involving the same unresolved weaknesses may have a greater probability of breaching the Impact Tolerance and may undermine regulatory and governance confidence.

 

Table 2 P2: Severe but Plausible Scenarios
Sub-CBS Code Name of Sub-CBS Interconnections and Interdependencies Challenged Cyber and ICT Risk Linkage Potential Impact Tolerance Breach Proactive Risk Management Action Evidence of Proactive Risk Management Scenario Testing Objective
CBS-2.1 Currency Demand Forecasting Challenges the flow of transaction, circulation, economic, seasonal-demand, and financial-institution data into the forecasting process. It also tests dependencies on CBS-2.2 Currency Production Planning, CBS-2.4 Currency Inventory and Vault Management, CBS-2.5 Currency Distribution and Replenishment, commercial banks, economic analysis functions, data owners, and management approval. The critical hand-off is the conversion of validated demand information into production, stock-allocation, and replenishment decisions. Corrupted or interrupted data feeds, database failures, ransomware, unauthorised model changes, failed analytical platform changes, or compromised user access may trigger the scenario. A monitoring failure may amplify the disruption by allowing apparently valid but incomplete forecasts to remain undetected. Technology concentration in a single forecasting platform or data repository could prolong the inability to establish a trusted demand position. Potentially Yes. The tolerance may be breached if inaccurate forecasts cause BDCB to allocate insufficient currency, exhaust essential denominations, or fail to respond to widespread demand within the approved service-duration and institutional-scope thresholds. The risk increases when the disruption coincides with electronic payment outages or peak public demand. Establish independent validation of critical data feeds; introduce forecast reasonableness thresholds; maintain controlled offline forecasting models; retain historical demand datasets; implement model version control and maker-checker approval; define minimum reserve triggers by denomination; and establish direct confirmation channels with financial institutions during exceptional demand. Approved forecasting risk assessment; model-validation reports; forecast-variance analysis; data-quality dashboards; source-to-model reconciliation results; privileged-access reviews; backup and restoration tests; records of manual forecasting exercises; management approval of demand assumptions and reserve thresholds. Validate whether BDCB can detect unreliable forecasts, establish a trusted demand position using alternate information, prioritise essential denominations, and initiate production or distribution decisions before shortages threaten the Currency Management Impact Tolerance. Management should evaluate detection speed, quality of manual estimates, decision authority, reserve adequacy, and communication with financial institutions.
CBS-2.2 Currency Production Planning Challenges dependencies on CBS-2.1 Currency Demand Forecasting, CBS-2.3 Currency Procurement and Manufacturing Oversight, inventory information from CBS-2.4, procurement, finance, senior approvers, document management, technical specialists, and external manufacturers. It tests whether validated plans, specifications, approvals, and production deadlines can be reconstructed and communicated when normal workflows are unavailable. Ransomware, document corruption, workflow failure, identity and access management disruption, unauthorised plan alteration, loss of electronic approvals, or uncertainty about backup integrity may trigger or prolong the disruption. ICT failure may prevent BDCB from determining which schedule or specification is authoritative. Potentially Yes, generally through delayed effect. Missing a critical manufacturing window may not immediately interrupt distribution, but it could reduce strategic reserve coverage below approved thresholds. The tolerance could be breached later if demand rises, existing stock deteriorates, or another supply disruption occurs before replacement currency becomes available. Maintain securely controlled offline copies of approved plans and specifications; define delegated approval authorities; implement digital integrity verification; test alternative communication channels with manufacturers; document production decision deadlines; cross-train planners; and maintain contingency plans for accelerated or alternative production. Approved production-continuity procedures; offline-plan verification records; workflow and approval audit logs; segregation-of-duties reviews; alternate-communication tests; backup-restoration results; cross-training records; production-window contingency exercises; management decision logs. Determine whether BDCB can reconstruct and approve a trusted production plan, communicate validated instructions, and protect future currency availability when planning technology and key personnel are unavailable. Management should evaluate document integrity, delegated authority, supplier communication, decision timeliness, and projected reserve coverage.
CBS-2.3 Currency Procurement and Manufacturing Oversight Challenges reliance on external currency printers or mints, specialist materials, secure cross-border logistics, quality-assurance records, procurement, legal and contract management, CBS-2.2 production plans, CBS-2.4 reserve stock, customs and border processes, and secure information exchange. It tests concentration risk where production capacity or specialist capability is limited to a small number of providers. A cyberattack on the manufacturer may disrupt production-control systems, corrupt quality records, expose currency specifications, or disable secure communications. Third-party ICT disruption, data integrity failure, compromised file transfer, and geopolitical restrictions may amplify the event and prevent acceptance of the completed currency. Yes, if prolonged. The breach occurs when delayed manufacturing or delivery reduces reserve-stock coverage to the point that BDCB cannot meet essential replenishment demand or maintain required denomination availability. Currency-security or specification compromise may create an immediate integrity concern even before stock is depleted. Conduct supplier operational and cyber resilience assessments; require timely incident notification and recovery commitments; protect currency specifications through encryption and access controls; maintain independent quality verification; assess alternate manufacturers and transport routes; define reserve-stock triggers; and test emergency procurement and acceptance arrangements. Third-party risk assessments; contractual resilience clauses; supplier business continuity and cyber-assurance reports; independent quality-test results; secure-transfer logs; alternate-supplier assessments; concentration-risk reviews; supply-chain exercise reports; remediation registers; management committee minutes. Assess whether BDCB can determine the effect of a prolonged manufacturer failure, preserve specification integrity, use reserve stock effectively, activate alternative supply options, and remain within tolerance. Management should evaluate supplier transparency, alternate capacity, quality assurance, geopolitical constraints, transport options, and the lead time before reserve depletion.
CBS-2.4 Currency Inventory and Vault Management Challenges the interdependence between physical vault access, inventory records, custody controls, CBS-2.5 distribution, CBS-2.6 receipt processing, CBS-2.11 accounting, CBS-2.12 security, facilities management, power, environmental controls, authorised custodians, and alternate storage arrangements. The scenario tests whether physical stock can be used when the primary facility and authoritative inventory position are both unavailable. Database corruption, ransomware, failed replication, access-control outage, surveillance failure, privileged-access compromise, network disruption, or loss of time synchronisation may accompany the facility event. A common technology dependency between primary and recovery environments may prevent reliable failover. Highly Likely. The tolerance may be breached if essential currency cannot be accessed or released within the approved duration, if inventory cannot be verified, or if BDCB cannot establish an alternate vault position. Any unresolved custody discrepancy or uncontrolled access may constitute an immediate breach regardless of duration. Maintain geographically separated and operationally usable vault capacity; preserve immutable movement records; implement strong privileged-access controls; retain controlled manual vault registers; provide independent access and surveillance resilience; test alternate-vault activation; perform frequent physical-to-system reconciliation; and predefine emergency release procedures. Alternate-vault exercise reports; inventory failover tests; physical-count and reconciliation results; access-control and surveillance test records; privileged-access reviews; immutable-log verification; backup-power tests; manual-register exercises; internal audit reports; remediation tracking. Demonstrate whether BDCB can establish a trusted stock position, activate an alternate vault, maintain custody controls, and release essential currency before the tolerance is exceeded. Management should evaluate stock visibility, data integrity, alternate-site readiness, security coverage, staffing, authorisation, and reconciliation speed.
CBS-2.5 Currency Distribution and Replenishment Challenges dependencies on CBS-2.4 vault operations, financial-institution requests, secure transport providers, route availability, telecommunications, dispatch scheduling, security escorts, CBS-2.12 custody controls, CBS-2.13 monitoring, and incident prioritisation. It also tests the critical hand-offs between BDCB, transport personnel, and receiving financial institutions. Telecommunications failure, denial-of-service attack, order-management outage, compromise of transport schedules, network disruption, dispatch-system failure, or loss of mobile communications may initiate or intensify the event. A technology failure may obscure institutional cash positions and prevent the secure confirmation of orders or deliveries. Highly Likely. A breach may occur if nationwide replenishment initiation is unavailable beyond the approved threshold, more than the accepted proportion of financial institutions cannot receive essential currency, or an affected geographic area approaches cash depletion without an executable contingency route. Maintain authenticated alternate ordering channels; establish offline dispatch and prioritisation procedures; contract or pre-arrange alternate secure transport capacity; identify alternate routes and distribution points; provide redundant communications; validate high-value requests independently; maintain institutional cash-depletion indicators; and test emergency distribution at realistic scale. Distribution continuity-plan tests; alternate-order-channel records; secure transport assurance reports; route-risk assessments; communication-resilience tests; dispatch audit trails; financial-institution contact tests; emergency distribution exercise reports; capacity analyses; Board or management reporting. Test whether BDCB can receive and prioritise urgent requests, allocate scarce denominations, coordinate secure alternate deliveries, and prevent widespread cash shortages during infrastructure and technology disruption. Management should evaluate request visibility, routing, transport capacity, security, delivery confirmation, and time remaining before institutional cash depletion.
CBS-2.6 Currency Receipt and Return Processing Challenges dependencies on financial institutions, secure transport, receiving facilities, counting and registration equipment, CBS-2.7 authentication, CBS-2.8 sorting, CBS-2.4 vault capacity, CBS-2.11 reconciliation, and custody hand-offs. It tests whether the currency return cycle can continue when the primary processing location is unavailable and alternate capacity is constrained. Receipt-system failure, tracking or barcode outage, counting-equipment capacity failure, ransomware, network interruption, or corrupted consignment records may amplify the facility disruption. ICT limitations at the alternate site may prevent accurate recording and reconciliation of high volumes. Potentially Yes. The tolerance may be breached if the backlog consumes secure storage, prevents financial institutions from returning currency, materially reduces fit currency available for recirculation, or creates unresolved custody differences. The risk grows as processing delays propagate to authentication, sorting, and distribution. Establish alternate receiving locations; maintain manual consignment and custody procedures; provide portable or redundant counting capability; define backlog and secure-capacity triggers; prioritise high-value or high-risk consignments; test end-to-end traceability; and pre-agree staggered return arrangements with financial institutions. Alternate-site activation reports; manual-receipt exercise results; equipment capacity tests; consignment traceability audits; custody reconciliation records; backlog monitoring reports; secure storage assessments; financial-institution coordination records; remediation actions. Determine whether BDCB can maintain traceable receipt, secure custody, and sufficient processing throughput after losing the primary facility. Management should evaluate backlog growth, record accuracy, alternate-site capacity, custody integrity, financial-institution coordination, and the effect on fit-currency availability.
CBS-2.7 Currency Authentication and Quality Verification Challenges automated authentication devices, specialist examiners, reference data, forensic capability, CBS-2.6 receipt processing, CBS-2.8 sorting, CBS-2.9 counterfeit investigation, financial institutions, law enforcement, and management decision-making on whether currency may be recirculated. It also tests concentration risk in common authentication equipment and software. Malware, unauthorised configuration changes, compromised detection thresholds, obsolete signatures, failed software updates, reference-database corruption, network compromise, or common-mode device failure may trigger the event. Cyber compromise may remain concealed by producing plausible but inaccurate authentication results. Highly Likely and potentially immediate. The tolerance may be breached if BDCB cannot establish currency authenticity, if counterfeit notes are released, or if legitimate currency is withheld long enough to affect distribution. Integrity failure may create unacceptable harm before the maximum disruption duration is reached. Implement layered authentication using multiple methods; segregate devices from unnecessary networks; validate configuration and software integrity; maintain manual examination capability; monitor false acceptance and rejection rates; preserve offline reference information; maintain spare equipment; and establish rapid counterfeit-escalation and public-stakeholder communication protocols. Device certification and calibration records; software-integrity checks; vulnerability assessments; penetration-test reports; sample accuracy tests; examiner competency records; false-acceptance analysis; equipment recovery exercises; counterfeit-response exercise reports; independent assurance. Validate whether BDCB can detect compromised authentication technology, isolate affected equipment, continue controlled verification, manage processing backlogs, and protect currency integrity. Management should assess detection effectiveness, manual capacity, decision thresholds, communications, forensic support, and whether any currency was released under uncertain conditions.
CBS-2.8 Currency Fitness Sorting and Recirculation Management Challenges sorting machines, software configurations, maintenance support, operators, spare parts, CBS-2.7 authentication results, CBS-2.10 destruction, CBS-2.4 inventory, and CBS-2.5 distribution. It tests the concentration of common-mode technology and the balance between recirculating fit currency and consuming new stock. Failed software deployment, configuration corruption, common-component defect, malware, database failure, equipment-capacity degradation, or unsuccessful rollback may initiate the event. Technology concentration may disable all machines simultaneously and prolong recovery. Potentially Yes. The tolerance may be breached when reduced sorting capacity prevents sufficient fit currency from returning to circulation, creates unsafe backlogs, or causes incorrect destruction or recirculation decisions. The breach risk is higher where new-stock reserves are limited. Diversify processing capacity where feasible; stage and independently test software changes; maintain rollback capability; monitor classification error rates; retain manual or semi-automated sorting procedures; hold critical spare parts; establish alternate processing arrangements; and define throughput and backlog escalation thresholds. Change-risk assessments; pre-production test results; rollback-test records; machine availability and performance reports; sorting-quality samples; spare-parts inventories; alternate-processing agreements; capacity stress tests; maintenance records; internal audit findings. Test whether BDCB can identify inaccurate sorting, contain affected batches, activate fallback capacity, and maintain sufficient fit-currency supply. Management should evaluate change governance, error detection, rollback effectiveness, manual throughput, backlog trajectory, destruction controls, and reserve-stock consumption.
CBS-2.9 Counterfeit Currency Investigation and Reporting Challenges case-management records, forensic evidence, secure communications, CBS-2.7 authentication, financial institutions, law-enforcement bodies, government stakeholders, specialist investigators, and public or industry alerts. The scenario tests timely intelligence sharing and maintenance of chain of custody across multiple entities. Cyber intrusion, data exfiltration, case alteration, secure-channel failure, forensic-tool outage, ransomware, or compromised user credentials may initiate or amplify the disruption. Loss of case integrity may prevent BDCB from distinguishing genuine intelligence from manipulated information. Potentially Yes. A breach may occur if counterfeit circulation expands materially, BDCB cannot issue reliable warnings, or confidence in affected denominations deteriorates. The tolerance may also be threatened where authentication and investigative failures occur simultaneously. Segment and encrypt case-management environments; enforce role-based access; preserve forensic evidence offline; maintain alternate secure communication channels; implement case-integrity checks; conduct joint protocols with financial institutions and enforcement agencies; and maintain pre-approved counterfeit escalation and communication procedures. Cyber threat assessments; access-control reviews; secure-channel tests; forensic chain-of-custody audits; data-loss-prevention records; case backup and restoration tests; inter-agency exercise reports; incident-response playbooks; communication approvals; remediation registers. Assess whether BDCB can establish a trusted counterfeit picture, preserve evidence, coordinate external stakeholders, and issue consistent guidance despite compromised systems. Management should evaluate case integrity, information-sharing speed, investigative prioritisation, public-confidence considerations, and the ability to contain wider circulation.
CBS-2.10 Currency Destruction and Disposal Management Challenges destruction equipment, batch records, surveillance, access control, CBS-2.8 sorting, CBS-2.11 accounting, CBS-2.12 security, internal audit, authorised witnesses, secure storage capacity, and any external disposal support. It tests whether BDCB can prove complete, authorised, and accurately reconciled destruction. Destruction, system failure, privileged access compromise, record manipulation, surveillance storage failure, sensor outage, ransomware, or a coordinated cyber-physical act may trigger the scenario. Loss of digital evidence may prevent reconstruction of the sequence of destruction. Potentially Yes. A short suspension may remain within tolerance, but a material unexplained discrepancy, unauthorised destruction, unaccounted currency, or exhaustion of secure storage could create an immediate integrity and security breach. Enforce dual control and independent witnessing; separate destruction authorisation from accounting; retain tamper-resistant evidence; provide redundant surveillance storage; reconcile pre- and post-destruction quantities; monitor privileged activity; establish secure backlog capacity; and test manual shutdown and investigation procedures. Destruction certificates; independent reconciliation reports; surveillance-retention tests; privileged-access logs; witnessed control-test results; cyber-physical exercise reports; storage-capacity assessments; internal audit reports; incident-investigation records; remediation evidence. Validate whether BDCB can suspend destruction safely, preserve evidence, reconcile affected batches, investigate suspected compromise, and maintain secure storage. Management should evaluate accountability, evidential completeness, custody status, storage capacity, insider-risk controls, and the time required to restore trusted operations.
CBS-2.11 Currency Accounting and Reconciliation Challenges interfaces among inventory, vault, dispatch, receipt, destruction, and general-ledger records. It also tests dependencies on CBS-2.4, CBS-2.5, CBS-2.6, CBS-2.10, finance personnel, source documents, financial-institution confirmations, system logs, and approval controls. The critical issue is whether BDCB can maintain an authoritative currency position after data corruption. Failed database change, interface corruption, ransomware, unauthorised journal entries, time-sequence errors, replication failure, backup gaps, or incomplete audit logs may trigger the event. A technology change may propagate inconsistent data across several platforms before detection. Highly Likely. The tolerance may be breached if BDCB cannot verify currency held, issued, returned, destroyed, or in transit within the required period. Continued movement using untrusted records could create unacceptable custody and financial-integrity risks even if systems are technically available. Implement near-real-time reconciliation for critical movements; retain immutable source journals; use maker-checker approval; strengthen change and database controls; test point-in-time restoration; maintain manual source records; define suspension criteria; and prepare a structured data reconstruction procedure that uses multiple independent sources. Change-control records; data-integrity test results; disaster recovery and point-in-time restoration reports; reconciliation break reports; journal-access reviews; interface-monitoring logs; manual-record exercises; independent assurance findings; management review of material variances. Determine whether BDCB can detect cross-system corruption, stop further exposure, reconstruct a trusted currency position, and resume controlled movements before tolerance is exceeded. Management should evaluate detection time, completeness of source evidence, reconciliation speed, decision authority, data-loss exposure, and confidence in restored balances.
CBS-2.12 Currency Security and Custody Management Challenges physical access control, surveillance, alarms, guards, transport security, identity management, telecommunications, facilities, CBS-2.4 vault operations, CBS-2.5 distribution, CBS-2.10 destruction, specialist security personnel, and law-enforcement support. It tests the shared security dependency across almost every Currency Management process. A privileged-access compromise, a cyberattack against security systems, a telecommunications disruption, false alarms, a surveillance outage, access-control manipulation, data leakage involving transport schedules, or a coordinated cyber-physical attack may trigger the event. Yes, potentially immediate. Confirmed or suspected uncontrolled access, theft, unaccounted currency, unsafe transport, or inability to maintain custody could breach the tolerance regardless of elapsed time. Suspension of security-dependent processes could also cause a rapid service-wide disruption. Segregate physical-security networks; implement independent alarm and surveillance channels; enforce privileged-access monitoring; protect transport information; provide backup power and communications; maintain enhanced manual guarding; test cyber-physical incident procedures; establish alternate secure routes and facilities; and coordinate with relevant authorities. Physical-security architecture reviews; penetration-test reports; access recertification; privileged-session monitoring; alarm and surveillance tests; backup-power reports; cyber-physical simulation results; transport-security assessments; law-enforcement coordination records; remediation tracking. Assess whether BDCB can detect and contain a coordinated attack, distinguish false from genuine events, maintain safe custody, protect personnel, and continue or suspend operations in a controlled manner. Management should evaluate command decisions, manual controls, security resource allocation, information protection, and service-wide consequences.
CBS-2.13 Currency Information and Operational Monitoring Challenges data feeds from inventory, distribution, processing, accounting, security, and financial institutions. It also tests network connectivity, time synchronisation, dashboard integrity, CBS-2.14 incident management, operational managers, and the accuracy of local status reporting. The scenario examines whether BDCB can operate without a central consolidated view. Monitoring platform outage, network routing failure, alert suppression, data feed interruption, dashboard corruption, denial-of-service attack, identity service failure, or time synchronisation errors may initiate or prolong the event. Conflicting timestamps can obscure the actual sequence and status of currency movements. Highly Likely if prolonged or concurrent with other failures. The service may cross its tolerance because management cannot detect shortages, failed dispatches, backlog escalation, or security-control degradation in time to intervene. The breach may go unnoticed. Implement independent monitoring paths for critical indicators; preserve local reporting capability; maintain manual situation-report templates; use redundant communications; validate dashboards against source records; protect time synchronisation; define mandatory reporting intervals; and test decision-making under degraded information. Monitoring availability reports; alert-test results; data-feed reconciliation; network resilience tests; time-synchronisation monitoring; manual status-report exercises; capacity tests; incident-detection metrics; management review records; independent assurance findings. Determine whether BDCB can establish an accurate operational picture, prioritise conflicting reports, and make tolerance-based decisions without the central monitoring platform. Management should evaluate data validation, reporting frequency, escalation discipline, uncertainty management, and the ability to identify approaching tolerance boundaries.
CBS-2.14 Currency Incident Management and Service Recovery Challenges incident command, crisis communications, alternate command facilities, staff notification, response plans, senior decision-makers, operational teams, ICT recovery, security, transport, financial institutions, and all affected CBS-2 Sub-CBS. It tests whether several simultaneous disruptions can be managed as a single end-to-end service incident rather than as separate technical events. An infrastructure outage, loss of the incident-management platform, telecommunications failure, inaccessible recovery documentation, unavailable contact data, a cyberattack, or reliance on a common identity or hosting service may amplify the disruption. Loss of key personnel further weakens decision-making. Highly Likely. Ineffective command may allow otherwise recoverable failures to exceed the service tolerance due to delayed declaration, conflicting priorities, slow stakeholder communication, or failure to activate alternative arrangements. Maintain offline response plans and contact lists; provide out-of-band communications; establish alternate command facilities; pre-authorise emergency decisions; nominate deputies; cross-train critical roles; align recovery milestones to the Impact Tolerance; conduct integrated multi-site and cyber-physical exercises; and track lessons to closure. Crisis-management exercise reports; call-tree tests; alternate-command-site activation records; role and deputy matrices; offline-plan verification; out-of-band communication tests; incident-response metrics; committee minutes; lessons-learned reports; remediation closure evidence. Validate whether BDCB can establish command rapidly, obtain a trusted service picture, prioritise resources, communicate with financial institutions, and restore essential Currency Management within tolerance. Management should evaluate leadership, escalation time, decision quality, coordination, stakeholder communications, tolerance tracking, and recovery sequencing.
CBS-2.15 Regulatory Reporting and Continuous Service Improvement Challenges incident reporting, risk management, audit, remediation tracking, document repositories, management committees, service owners, technology owners, CBS-2.13 monitoring, CBS-2.14 incident management, and Board or Board Risk Committee oversight. It tests whether lessons and unresolved weaknesses remain visible and actionable after an incident. Document-management compromise, ransomware, unauthorised alteration, loss of audit evidence, reporting-platform failure, incomplete incident data, or remediation-system outage may trigger the scenario. Cyber disruption may conceal whether previously identified controls were implemented effectively. Potentially Yes through recurrence and governance failure. The initial reporting disruption may not stop Currency Management, but a failure to identify and remedy known weaknesses can lead to a recurrence that breaches tolerance. Material loss or suppression of incident evidence may also undermine governance and regulatory confidence. Maintain controlled, resilient evidence repositories; protect report integrity through access and version controls; retain offline copies of material records; reconcile reports to source evidence; assign accountable remediation owners; escalate overdue, high-risk actions; require independent validation of closure; and report tolerance-related weaknesses to senior management and the Board. Approved incident and scenario reports; repository access logs; document-version histories; management and Board minutes; remediation dashboards; risk acceptance records; independent closure reviews; Internal Audit reports; repeat-finding analysis; subsequent scenario-test results. Assess whether BDCB can preserve evidence, produce an accurate account of the disruption, identify root causes, maintain management oversight, and ensure corrective actions are completed. Management should evaluate evidence integrity, reporting timeliness, ownership, challenge, risk acceptance, repeat vulnerabilities, and whether lessons materially improve resilience.

 

 

 

Identifying severe but plausible scenarios is a cornerstone of an effective Operational Resilience programme.

For the Brunei Darussalam Central Bank (BDCB), these scenarios provide a structured and realistic means of validating whether its Currency Management Critical Business Service can continue to operate within its defined impact tolerances during extreme yet credible disruptions.

Rather than focusing solely on isolated operational incidents, scenario development challenges the resilience of people, processes, technology, facilities, third-party providers, and governance arrangements under conditions that could realistically occur.

By mapping each Currency Management sub-service to representative severe but plausible scenarios, identifying the operational impacts, defining proactive risk management actions, and explicitly integrating Cyber and ICT risks, BDCB adopts a holistic approach to resilience.

This enables management to evaluate not only the effectiveness of preventive controls but also the organisation's ability to make timely decisions, coordinate recovery activities, maintain public confidence, and continue supplying secure and authentic currency to the nation during periods of significant disruption.

Ultimately, severe-but-plausible scenario identification should not be viewed as a regulatory compliance exercise but as a strategic capability that continually strengthens operational resilience.

Regular review, testing, and refinement of these scenarios will enable BDCB to adapt to emerging threats, evolving technologies, changing dependencies, and new operational risks.

By embedding scenario-based resilience into its governance, risk management, and continuous improvement processes, BDCB enhances its ability to protect one of the nation's most essential financial services while aligning with international operational resilience best practices.

 

eBook 3: Starting Your OR Implementation
CBS-2 Currency Management
CBS-2 DP CBS-2 MII CBS-2 ITo CBS-2 SbPS CBS-2 ST


For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

To learn more about the course and schedule, click the buttons below for the [OR-3] OR-300 Operational Resilience Implementer course and the [OR-5] OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.