.

Strengthening Operational Resilience at GCash: An Enterprise Implementation Guide
BB OR [B] 11

[OR] [GCash] [E2] [P3] [C14] Five Stages of the "Sustain" Phase

[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash

The Sustain phase ensures that Operational Resilience at GCash remains effective after the initial planning and implementation activities are complete.

x eBook Cover [OR] [GCash] [E2] [2D]Operational Resilience cannot be treated as a one-time project because the organisation’s products, technology, customer expectations, cyber threats, third-party relationships and regulatory requirements continue to evolve.

New call-to-actionThe Sustain phase therefore focuses on embedding resilience into organisational culture, maintaining clear communication, building staff capability, assessing whether the framework remains effective and subjecting the programme to independent review.

For a highly digital financial services organisation such as GCash, sustaining resilience is especially important because weaknesses can emerge quickly as operating conditions, technology architectures, and external dependencies change.

Sustain Phase

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner

Sustain Phase

Introduction to GCash’s “Sustain” Phase of the Operational Resilience Planning Methodology

Introduction

New call-to-action[OR] [GCash] [E2] [P1] [S1-S5] [C14] Five Stages of the Sustain Phase

The Sustain phase ensures that Operational Resilience at GCash remains effective after the initial planning and implementation activities are complete.

Operational Resilience cannot be treated as a one-time project because the organisation’s products, technology, customer expectations, cyber threats, third-party relationships and regulatory requirements continue to evolve.

The Sustain phase therefore focuses on embedding resilience into organisational culture, maintaining clear communication, building staff capability, assessing whether the framework remains effective and subjecting the programme to independent review.

For a highly digital financial services organisation such as GCash, sustaining resilience is especially important because weaknesses can emerge quickly as operating conditions, technology architectures, and external dependencies change.

 

Purpose of the Chapter

[OR] [PM] [P3] How the Five Sustain Stages Work TogetherThe purpose of this chapter is to introduce the reader to the Sustain phase of GCash’s Operational Resilience Planning Methodology and explain how its five stages help preserve and strengthen resilience capabilities over time.

While the Plan phase establishes direction and governance, and the Implement phase applies resilience requirements to Critical Operations, the Sustain phase ensures that the programme remains embedded, understood, measured, challenged and continuously improved.

It provides the mechanisms required to prevent Operational Resilience from becoming outdated, fragmented or reduced to a periodic compliance exercise.

By the end of this chapter, the reader should understand the purpose and sequence of the five Sustain stages—Introduce Cultural Change, Develop Communication Strategy, Implement Training and Awareness, Provide Self-assessment, and Conduct Independent Quality Review—and how each stage contributes to long-term Operational Resilience at GCash.

The reader should also recognise how these stages support ongoing governance, accountability, organisational learning, regulatory readiness and continuous improvement across Critical Operations.

 

Introduction to GCash’s Operational Resilience Planning Methodology

New call-to-actionGCash’s Operational Resilience Planning Methodology can be viewed as a three-phase lifecycle:

 

  • The Plan phase establishes the strategic foundation.

  • The Implement phase builds and tests resilience capabilities.

  • The Sustain phase ensures that those capabilities remain effective over time.

Together, the three phases create a continuous resilience lifecycle rather than a linear project.

The Sustain phase answers five important questions:

  • Is Operational Resilience embedded into organisational behaviour?
  • Are resilience expectations communicated clearly?
  • Do employees understand their responsibilities?
  • Does management periodically assess whether the programme remains effective?
  • Is the programme independently challenged and assured?

These questions correspond to five stages:

Phase 3: Sustain

New call-to-action

The objective of the Sustain phase is to embed Operational Resilience into GCash's normal management and operating practices.

This means ensuring that resilience is not dependent upon:

  • a single programme team;
  • a regulatory deadline;
  • one annual exercise;
  • one executive sponsor; or
  • one set of documents.

Instead, resilience should become part of:

  • organisational culture;
  • risk management;
  • technology management;
  • business decision-making;
  • product development;
  • supplier management;
  • incident response;
  • governance;
  • performance measurement; and
  • continuous improvement.

The Sustain phase therefore converts Operational Resilience from an implementation programme into an enduring organisational capability.

New call-to-action

Stage 1: Introduce Cultural Change

[Sustain Phase – Stage 1]

The first stage is to introduce cultural change.

Operational Resilience cannot be sustained through policies and procedures alone.

Employees and management must understand that resilience is part of normal business responsibility.

The objective of cultural change is to establish behaviours where employees:

  • understand the importance of Critical Operations;
  • recognise vulnerabilities;
  • escalate concerns promptly;
  • consider resilience when making decisions;
  • participate actively in exercises;
  • learn from incidents;
  • challenge unsafe assumptions; and
  • take ownership of resilience outcomes.

For GCash, cultural change is particularly important because resilience spans multiple functions such as:

  • Business Operations;
  • Technology;
  • Cybersecurity;
  • Operational Risk;
  • BCM;
  • Customer Operations;
  • Third-Party Risk;
  • Compliance; and
  • Product Management.

A strong culture of resilience reduces the risk that each function manages its responsibilities in isolation.

Example for GCash

Suppose a new digital payment feature is being developed.

Without an Operational Resilience culture, teams may focus primarily on:

  • functionality;
  • customer experience;
  • speed to market; and
  • commercial performance.

With a strong resilience culture, the project should also consider:

  • whether the new feature supports a Critical Operation;
  • technology dependencies;
  • third-party concentration;
  • recovery arrangements;
  • transaction integrity;
  • potential customer harm; and
  • whether existing Tolerance for Disruption remains appropriate.

This demonstrates that resilience has become embedded into day-to-day decision-making.

Key Output

The outputs may include:

  • Operational Resilience culture objectives;
  • leadership messages;
  • behavioural expectations;
  • resilience values;
  • performance-management criteria; and
  • culture assessment results.

 

Leadership and Cultural Change

Leadership plays a critical role in sustaining Operational Resilience.

Senior management should consistently reinforce that Operational Resilience is:

  • an enterprise responsibility;
  • connected to customer outcomes;
  • part of risk management;
  • relevant to strategic decisions; and
  • expected across all levels of the organisation.

Leadership actions may include:

  • communicating resilience priorities;
  • reviewing scenario-test results;
  • challenging overdue remediation;
  • recognising resilience improvements;
  • including resilience in management objectives; and
  • requiring resilience considerations within major business changes.

The tone set by senior management will strongly influence how seriously the organisation treats resilience.

New call-to-actionStage 2: Develop Communication Strategy

[Sustain Phase – Stage 2]

The second stage is to develop a communication strategy.

Operational Resilience depends upon accurate and timely communication before, during and after disruption.

The communication strategy should therefore cover both:

Routine resilience communication

and

Incident-related communication

Routine communication helps employees understand:

  • resilience priorities;
  • Critical Operations;
  • responsibilities;
  • regulatory expectations;
  • changes in resilience arrangements; and
  • lessons from incidents and tests.

Incident communication supports:

  • escalation;
  • decision-making;
  • customer notification;
  • regulatory reporting;
  • employee instructions;
  • third-party coordination; and
  • public communication.
Example for GCash

During a significant digital-wallet disruption, GCash may need coordinated communication across:

 

Incident Management Team

Executive Management

Customer Support

Technology and Cybersecurity

External Providers

Customers and Merchants

Bangko Sentral ng Pilipinas

 

Without an established communication strategy, different teams may provide inconsistent messages.

A predefined communication framework helps ensure that information is:

  • accurate;
  • approved;
  • timely;
  • coordinated; and
  • appropriate for each audience.
Key Output

The outputs should include:

  • Operational Resilience Communication Strategy;
  • stakeholder communication matrix;
  • escalation procedures;
  • crisis communication protocols;
  • regulatory notification procedures;
  • message templates; and
  • communication testing arrangements.

Stakeholders in the Communication Strategy

The communication strategy should identify all relevant stakeholder groups.

For GCash, these may include:

 

Stakeholder

Communication Requirement

Board and Senior Management

Strategic resilience status and material concerns

Business Units

Operational responsibilities and vulnerabilities

Technology Teams

Recovery priorities and service impacts

Cybersecurity

Cyber threat and response information

BCM and Crisis Management

Incident coordination and continuity arrangements

Customers

Service availability and appropriate actions

Merchants

Payment or settlement impact

Employees

Operating instructions and escalation

Third Parties

Recovery coordination and dependency status

BSP

Required regulatory notifications and reporting

Internal Audit

Evidence supporting independent assurance

Different stakeholders require different levels of information.

Communication should therefore be designed according to both audience and purpose.

New call-to-actionStage 3: Implement Training and Awareness

[Sustain Phase – Stage 3]

The third stage is to Implement Training and Awareness.

Training develops the knowledge and skills required to perform specific resilience responsibilities.

Awareness ensures that the wider organisation understands the importance of resilience.

The programme should therefore include both:

General awareness

and

Role-specific training

General awareness may cover:

  • Operational Resilience concepts;
  • Critical Operations;
  • escalation;
  • incident reporting;
  • continuity responsibilities;
  • cyber awareness; and
  • customer impact.

Role-specific training should be more detailed.

Example for GCash

Different groups may require different training.

Board and Senior Management

  • governance;
  • risk appetite;
  • Tolerance for Disruption;
  • scenario-testing oversight;
  • regulatory expectations.

Critical Operation Owners

  • dependency mapping;
  • tolerance setting;
  • scenario testing;
  • remediation.

Technology Teams

  • technology resilience;
  • failover;
  • recovery;
  • monitoring.

Customer Operations

  • incident communication;
  • customer harm;
  • alternate procedures.

Third-Party Risk Teams

  • provider resilience;
  • concentration risk;
  • contractual requirements.

This ensures that training is linked directly to responsibilities.

Key Output

The outputs should include:

  • training strategy;
  • annual training plan;
  • role-based curriculum;
  • attendance records;
  • competency assessments;
  • exercise participation records; and
  • awareness materials.

 

Testing Knowledge Through Exercises

Training should not be limited to classroom or online learning.

Exercises are an important way to confirm whether employees can apply their knowledge during disruption.

GCash may use:

  • tabletop exercises;
  • simulation exercises;
  • cyber incident exercises;
  • technology failover exercises;
  • crisis-management exercises;
  • third-party exercises; and
  • full end-to-end scenario tests.

For example, a tabletop exercise involving a prolonged payment outage may test whether participants understand:

  • escalation thresholds;
  • decision authority;
  • Tolerance for Disruption;
  • regulatory reporting;
  • customer communication; and
  • recovery prioritisation.

The results should feed back into the training programme.

New call-to-action

Stage 4: Provide Self-Assessment

[Sustain Phase – Stage 4]

The fourth stage is to Provide Self-assessment.

Self-assessment allows GCash to periodically evaluate whether its Operational Resilience Framework remains effective.

The purpose is not merely to confirm compliance.

It should determine:

  • whether Critical Operations remain correctly identified;
  • whether Tolerance for Disruption remains appropriate;
  • whether dependency maps are current;
  • whether Severe but Plausible Scenarios remain relevant;
  • whether scenario testing is effective;
  • whether third-party risks are understood;
  • whether lessons are being implemented;
  • whether governance remains effective; and
  • whether resilience capability is improving.

Self-assessment should therefore be evidence-based.

Example for GCash

An annual self-assessment may identify that:

  • Digital Wallet Operations remain a Critical Operation;
  • dependency maps are current;
  • the Tolerance for Disruption remains appropriate;
  • scenario tests were completed;
  • several vulnerabilities were identified;
  • most remediation actions were completed;
  • one high-priority third-party issue remains overdue.

The self-assessment should then explain:

Current Status

Evidence

Gap

Risk

Required Action

This gives management a structured view of programme effectiveness.

Key Output

The principal output should be an:

Operational Resilience Self-Assessment Report

 

Recommended Self-Assessment Areas

The assessment may cover:

 

Assessment Area

Example Question

Governance

Are roles and accountabilities current?

Critical Operations

Are all significant operations identified?

Tolerance for Disruption

Are thresholds approved and still appropriate?

Dependency Mapping

Are internal and external dependencies current?

Scenario Testing

Have tests challenged Severe but Plausible Scenarios?

BCM

Are continuity strategies aligned to Critical Operations?

ICT Resilience

Are recovery capabilities validated?

Cyber Resilience

Are cyber scenarios integrated into testing?

Third-Party Risk

Are critical providers assessed and tested?

Incident Management

Are escalation and recovery arrangements effective?

Training

Are responsible personnel competent?

Remediation

Are findings closed within agreed timelines?

Reporting

Does management receive sufficient resilience information?

The self-assessment should be supported by evidence rather than subjective opinion.

Evidence for Self-Assessment

Evidence may include:

  • policies;
  • governance minutes;
  • Critical Operation registers;
  • dependency maps;
  • Tolerance for Disruption approvals;
  • test reports;
  • incident records;
  • risk assessments;
  • training records;
  • third-party reviews;
  • remediation registers;
  • management reports; and
  • audit findings.

This enables management to demonstrate the basis for its assessment.

New call-to-actionStage 5: Conduct an Independent Quality Review

[Sustain Phase – Stage 5]

The final stage of the Sustain phase is to conduct an Independent Quality Review.

Self-assessment provides management's view of resilience.

Independent review provides objective challenge.

The purpose is to determine whether:

  • the Operational Resilience Framework is appropriately designed;
  • governance is effective;
  • methodology is being applied consistently;
  • resilience evidence is reliable;
  • vulnerabilities are appropriately managed;
  • testing is sufficiently challenging; and
  • management's assessment is reasonable.

Independent review should be conducted by parties sufficiently removed from the programme's operational implementation.

This may include:

  • Internal Audit;
  • independent risk assurance;
  • external specialists; or
  • other qualified assurance functions.
Example for GCash

Suppose GCash's self-assessment concludes that its Digital Wallet Operations can remain within the approved Tolerance for Disruption.

An independent review may examine:

  • dependency maps;
  • scenario-test evidence;
  • failover performance;
  • third-party participation;
  • data-integrity results;
  • recovery times;
  • management decisions; and
  • open remediation actions.

The reviewer may conclude that:

Management Assessment: Satisfactory

but identify:

Independent Observation: Recovery assumptions depend heavily on a critical third-party provider that has not participated in an end-to-end test.

This creates valuable independent challenge.

Key Output

The principal output should be an:

Independent Operational Resilience Quality Review Report

 

Role of Internal Audit

Internal Audit should provide an important element of independent assurance.

Its review may cover:

  • governance;
  • Critical Operation identification;
  • Tolerance for Disruption;
  • dependency mapping;
  • scenario-testing quality;
  • third-party resilience;
  • ICT resilience;
  • cyber resilience;
  • remediation management;
  • management reporting; and
  • regulatory compliance.

Internal Audit should remain independent from the teams responsible for designing and operating the Operational Resilience programme.

 

How the Five Sustain Stages Work Together

The Sustain phase can be understood as a continuous reinforcing cycle.

 

Stage 1

Introduce Cultural Change

Ensures resilience becomes part of organisational behaviour.

Stage 2

Develop Communication Strategy

Ensures resilience information reaches the right stakeholders.

Stage 3

Implement Training and Awareness

Ensures people have the required knowledge and capability.

Stage 4

Provide Self-assessment

Determines whether the framework remains effective.

Stage 5

Conduct Independent Quality Review

Provides objective assurance and challenge.

Continuous Improvement

The results then feed back into culture, communication, training and programme improvement.

 

Example Sustain Phase for GCash

 

Sustain Stage

Core Question

Example Application to GCash

Key Output

Stage 1 – Introduce Cultural Change

Is resilience embedded into behaviour?

Include resilience considerations in product, technology and risk decisions

Culture Programme

Stage 2 – Develop Communication Strategy

Is resilience information communicated effectively?

Establish customer, management, employee and BSP communication protocols

Communication Strategy

Stage 3 – Implement Training and Awareness

Do people understand their responsibilities?

Provide role-based resilience training for management, Critical Operations owners and technical teams

Training Programme

Stage 4 – Provide Self-assessment

Is the framework still effective?

Conduct annual assessment of Critical Operations, tolerances, tests and remediation

Self-Assessment Report

Stage 5 – Conduct Independent Quality Review

Has the programme been independently challenged?

Internal Audit or independent specialists review resilience capability

Independent Review Report

 

Relationship Between the Three Phases

GCash's complete Operational Resilience methodology can now be viewed as:

New call-to-action

This produces a complete Operational Resilience lifecycle.

Integration with Business Continuity Management

The Sustain phase should also reinforce GCash's BCM programme.

Examples include:

 

Sustain Activity

BCM Connection

Cultural Change

Continuity responsibility becomes embedded

Communication Strategy

Crisis communication is strengthened

Training and Awareness

BCP roles and responsibilities remain understood

Self-assessment

BCM effectiveness is periodically reviewed

Independent Review

BCM receives objective assurance

Operational Resilience, therefore, strengthens BCM by situating continuity capabilities within a broader enterprise resilience framework.

 

Sustaining Technology and Cyber Resilience

For GCash, technology and cyber resilience require continuous attention.

The Sustain phase should ensure that:

  • technology dependencies remain current;
  • cyber threats are reassessed;
  • recovery procedures are updated;
  • failover capabilities are tested;
  • capacity remains adequate;
  • changes are assessed for resilience impact;
  • vulnerabilities are remediated; and
  • lessons are incorporated into technical architecture.

A system that was resilient twelve months ago may no longer remain resilient after:

  • architecture changes;
  • new integrations;
  • increased transaction volumes; or
  • new cyber threats.

Sustainment therefore requires continual reassessment.

 

Sustaining Third-Party Resilience

Third-party relationships also change over time.

GCash should periodically reassess:

  • critical provider status;
  • concentration risk;
  • subcontractors;
  • recovery capability;
  • service performance;
  • incident history;
  • contractual resilience obligations; and
  • exit arrangements.

Critical providers should also participate in relevant scenario-testing activities where feasible.

This helps ensure that external dependencies remain aligned with GCash's resilience requirements.

 

Sustaining Resilience Through Metrics

The Sustain phase should include measurable indicators.

Possible measures include:

  • percentage of Critical Operations assessed annually;
  • percentage of dependency maps updated;
  • percentage of scenario tests completed;
  • percentage of personnel trained;
  • percentage of high-risk remediation actions completed on time;
  • number of Critical Operations breaching Tolerance for Disruption;
  • number of material incidents;
  • number of overdue third-party resilience actions;
  • number of repeat findings; and
  • number of unresolved independent assurance findings.

These indicators allow management to determine whether Operational Resilience is improving or deteriorating.

 

Continuous Improvement Cycle

The Sustain phase should operate as an improvement cycle:

 

Culture

Communication

Training

Assessment

Independent Review

Lesson Identified

Remediation

Improved Capability

Reassessment

This ensures that Operational Resilience evolves continuously.

 

[Banner] [Summing] [OR] [E2] [C14] Five Stages of the _Sustain_ Phase

The Sustain phase ensures that GCash's Operational Resilience programme remains effective after the initial Plan and Implement activities are complete.

Its five stages—Introduce Cultural Change, Develop Communication Strategy, Implement Training and Awareness, Provide Self-assessment, and Conduct Independent Quality Review—create the organisational mechanisms required to embed resilience, maintain employee capability, communicate effectively, assess programme effectiveness and provide independent assurance.

Together, these activities transform Operational Resilience from a project into an enduring management capability.

For GCash, sustainment is especially important because the digital financial services environment is constantly evolving.

Technology architectures evolve, transaction volumes grow, cyber threats develop, third-party relationships change, and customer expectations increase.

Operational Resilience must therefore be regularly reassessed and improved.

When the Sustain phase operates effectively alongside the Plan and Implement phases, GCash can maintain a continuous lifecycle of planning, implementation, testing, learning, assurance and improvement, strengthening its ability to protect customers and continue Critical Operations through severe disruption.

BL-OR-3-5 Blog Under Construction

Blogs marked [x] are under construction

[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash

C1 C2 C8 C14      
[OR] [GCash] [E2] [C1] OR Planning Methodology [OR] [GCash] [E2] [P1] [S1-S5] [C2] Five Stages of the Plan Phase [OR] [GCash] [E2] [P1] [S1-S5] [C8] Five Stages of the Implement Phase [OR] [GCash] [E2] [P1] [S1-S5] [C14] Five Stages of the Sustain Phase
"Sustain" Phase of the Operational Resilience Planning Methodology
C14 [x] C15 [x] C16 [x] C17 [x] C18 [x] C19 [x]
[OR] [GEN] [E2] [P3] [C14] The Five Stages of the Sustain Phase [OR] [GEN] [E2] [P3] [S1] [C15] Introducing Cultural Change Management [OR] [GEN] [E2] [P3] [S2] [C16] Developing a Communication Strategy [OR] [GEN] [E2] [P3] [S3] C17] Implementing Training and Awareness [OR] [GEN] [E2] [P3] [S4] [C18] Providing Self-Assessment [OR] [GEN] [E2] [P3] [S5] [C19] Conducting Independent Quality Reviews
 

Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM