. .

Strengthening Operational Resilience at GCash: An Enterprise Implementation Guide
BB OR 6

[OR] [GCash] [E3] [CBS] [1] [SbPS] Identify Severe but Plausible Scenarios

[OR] [GCash] [Full Banner] Strengthening Operational Resilience at GCash

Severe but Plausible Scenarios are a fundamental component of an Operational Resilience programme because they enable an organisation to assess whether a Critical Operation can continue to operate within its defined Impact Tolerance when exposed to significant disruption.

Rather than testing the recovery of individual systems or departments, these scenarios evaluate the resilience of the end-to-end service delivered to customers and other stakeholders.

For GCash's CO-1 Digital Wallet Operations, the scenarios are developed using the previously identified Sub-Critical Business Services (Sub-CBS) as the primary units of analysis.

This approach ensures that every major business process supporting the digital wallet ecosystem is evaluated for operational vulnerabilities, interconnections, and dependencies that could contribute to service disruption.

New call-to-action

Dr Goh Moh Heng
Operational Resilience Planner-Specialist-Expert

[OR] [GCash] [Disclaimer] Legal Disclaimers and Usage of eBook Banner

New call-to-actionIdentify Severe but Plausible Scenarios for CO-1 Digital Wallet Operations

Introduction

New call-to-action

New call-to-action

Severe but Plausible Scenarios are a fundamental component of an Operational Resilience programme because they enable an organisation to assess whether a Critical Operation can continue to operate within its defined Impact Tolerance when exposed to significant disruption.

Rather than testing the recovery of individual systems or departments, these scenarios evaluate the resilience of the end-to-end service delivered to customers and other stakeholders.

For GCash's CO-1 Digital Wallet Operations, the scenarios are developed using the previously identified Sub-Critical Business Services (Sub-CBS) as the primary units of analysis.

This approach ensures that every major business process supporting the digital wallet ecosystem is evaluated for operational vulnerabilities, interconnections, and dependencies that could contribute to service disruption.

The scenarios integrate operational, technology, cyber, ICT, third-party, and people-related risks because Digital Wallet Operations rely upon highly interconnected digital platforms, payment ecosystems, banking interfaces, telecommunications infrastructure, cloud services, and regulatory obligations.

Consequently, cyber incidents, infrastructure failures, operational mistakes, and external disruptions are considered together to provide a realistic assessment of resilience.

The following scenarios are intended to test whether GCash can maintain Digital Wallet Operations within its defined Impact Tolerance while identifying opportunities for strengthening preventive controls, recovery capabilities, governance, and continuous resilience improvement.

Banner [Table] [OR] [E3] Identify Severe but Plausible Scenarios

Table 1 (Part 1): Severe but Plausible Scenarios

Sub-CBS Code

Name of Sub-CBS

Recommended Severe but Plausible Scenario

Scenario Description

Primary Disruption Trigger

Impact on Sub-CBS

Impact on Critical Business Service

CO-1.1

Digital Wallet Registration and Provisioning

Distributed Denial-of-Service (DDoS) attack against customer onboarding platform

A coordinated cyberattack overwhelms customer registration services during a peak onboarding campaign, preventing new customer registrations and delaying wallet provisioning.

External cyberattack

New customer onboarding is interrupted and registration requests accumulate.

Reduced customer acquisition and delayed access to Digital Wallet Operations.

CO-1.2

Customer Identity Verification and Account Validation

National identity verification service unavailable

Connectivity to external identity verification services is disrupted due to a telecommunications outage affecting multiple service providers.

Third-party service disruption

Customer identity verification cannot be completed, preventing account activation.

New customers cannot access Digital Wallet services and regulatory compliance obligations may be affected.

CO-1.3

Wallet Funding and Value Loading

Simultaneous failure of banking connectivity and payment gateway

A major telecommunications disruption affects multiple banking interfaces, preventing customers from loading funds into their wallets.

Telecommunications and network outage

Cash-in transactions fail or remain pending.

Customers cannot fund wallets, reducing transaction volumes and service usability.

CO-1.4

Wallet Balance Management

Database corruption following failed infrastructure update

A failed database software deployment corrupts transaction ledger synchronisation, causing inconsistent wallet balances across replicated databases.

Failed technology change

Wallet balances become unreliable until integrity is restored.

Customers lose confidence, payment processing becomes unreliable, and financial integrity is threatened.

CO-1.5

Payment Transaction Processing

Ransomware attack on payment processing environment

Malware encrypts critical transaction processing servers, forcing payment processing to fail while recovery procedures are initiated.

Cyberattack (Ransomware)

Payment processing becomes unavailable.

Widespread inability to complete digital payments, affecting customers and merchants nationwide.

CO-1.6

Funds Transfer and Settlement Processing

Interbank settlement network disruption

A failure within national payment infrastructure delays settlement processing across participating financial institutions.

External financial infrastructure disruption

Funds transfers remain incomplete and settlement queues increase.

Delayed customer transfers and growing settlement backlog impact service confidence.

CO-1.7

Transaction Authorisation and Risk Controls

Authentication platform compromise

Privileged credentials are compromised, requiring emergency suspension of authentication services while security controls are restored.

Cybersecurity breach

Transaction authorisation is restricted or suspended.

Legitimate transactions are delayed while fraud prevention measures remain effective.

CO-1.8

Merchant Payment Enablement

QR payment platform capacity exhaustion

Peak transaction demand exceeds platform capacity following a major promotional campaign, causing widespread merchant payment failures.

Capacity and performance degradation

Merchant payment acceptance slows significantly.

Customers experience payment failures across large merchant networks.

 

Table 1 (Part 2): Severe but Plausible Scenarios

Sub-CBS Code

Name of Sub-CBS

Recommended Severe but Plausible Scenario

Scenario Description

Primary Disruption Trigger

Impact on Sub-CBS

Impact on Critical Business Service

CO-1.9

Digital Wallet Service Integration Management

Enterprise API Gateway Failure Combined with Cloud Connectivity Degradation

A software defect introduced during a routine infrastructure change causes the enterprise API gateway to fail while cloud connectivity simultaneously becomes unstable, interrupting communications between Digital Wallet Operations and multiple banking, merchant and payment ecosystem interfaces.

Failed technology change combined with cloud infrastructure degradation

Integration services become unavailable, preventing real-time communication between internal and external services.

Multiple Sub-CBS fail simultaneously, causing widespread disruption across Digital Wallet Operations and significantly increasing the likelihood of exceeding the Impact Tolerance.

CO-1.10

Customer Transaction Notification and Communication

Nationwide Telecommunications Service Disruption

A regional telecommunications outage affects SMS, push notification and mobile data services, preventing timely customer notifications despite successful transaction processing.

Telecommunications infrastructure failure

Customers do not receive transaction confirmations, fraud alerts or account notifications.

Customer confidence declines, enquiries increase, fraud detection by customers is delayed and contact centre volumes rise significantly.

CO-1.11

Transaction Monitoring and Operational Surveillance

Simultaneous Failure of Monitoring Platform and Security Event Collection

A monitoring software failure coincides with a logging infrastructure fault, preventing operational teams from detecting deteriorating service conditions and cyber events.

ICT monitoring platform failure

Service degradation remains undetected, delaying operational response and incident escalation.

Minor operational issues escalate into major service disruptions because corrective action is delayed.

CO-1.12

Exception Handling and Transaction Resolution

Surge in Failed Transactions Following Payment Network Disruption

A prolonged payment network outage generates an unusually high volume of failed and duplicate transactions, overwhelming investigation and customer resolution teams.

External payment network disruption

Investigation backlogs increase significantly and customer cases remain unresolved for extended periods.

Customer dissatisfaction increases while unresolved transactions undermine confidence in Digital Wallet Operations.

CO-1.13

Financial Reconciliation and Operational Reporting

Data Integrity Failure During End-of-Day Reconciliation

Corrupted settlement files received from external payment channels prevent automated reconciliation and require extensive manual investigation.

Data corruption

Financial reconciliation cannot be completed accurately within operational deadlines.

Regulatory reporting may be delayed, financial records become unreliable and operational risk increases.

CO-1.14

Operational Incident Management

Major Cyber Incident Combined with Failure of Incident Escalation Procedures

A ransomware attack affects operational systems while automated incident notification workflows fail, delaying escalation to executive management and crisis teams.

Cyberattack combined with process failure

Incident coordination becomes fragmented, delaying decision-making and recovery activities.

Service disruption is prolonged, increasing customer impact and the probability of exceeding the Impact Tolerance.

CO-1.15

Service Recovery and Operational Restoration

Simultaneous Failure of Primary and Disaster Recovery Environments

A regional power disruption combined with storage replication failure renders both the primary production environment and recovery environment temporarily unavailable.

Regional infrastructure disruption combined with disaster recovery failure

Recovery activities cannot proceed according to planned recovery procedures.

Digital Wallet Operations remain unavailable beyond acceptable limits, resulting in unacceptable customer, regulatory and operational harm.

 

Table 2 (Part 2): Scenario Assessment and Resilience Testing

Sub-CBS Code

Name of Sub-CBS

Interconnections and Interdependencies Challenged

Cyber and ICT Risk Linkage

Potential Impact Tolerance Breach

Proactive Risk Management Action

Evidence of Proactive Risk Management

Scenario Testing Objective

CO-1.1

Digital Wallet Registration and Provisioning

Customer onboarding, identity verification, CRM integration

DDoS attack, API disruption

Low-Medium

Deploy DDoS mitigation, API redundancy and scalable onboarding architecture

DDoS testing reports, API resilience testing, onboarding failover exercises

Validate customer onboarding resilience during cyber disruption.

CO-1.2

Customer Identity Verification and Account Validation

Identity providers, compliance operations, fraud management

Third-party ICT failure, identity platform outage

Medium

Diversify identity verification providers and strengthen contingency verification procedures

Third-party assurance reports, KYC resilience tests, supplier continuity reviews

Assess resilience when external identity verification services become unavailable.

CO-1.3

Wallet Funding and Value Loading

Banking connectivity, payment gateways, settlement services

Network outage, API failure

High

Implement multiple banking connections and resilient payment routing

Banking interface testing, network resilience reports, payment failover tests

Validate continuity of customer funding under banking connectivity failures.

CO-1.4

Wallet Balance Management

Transaction processing, financial reconciliation, customer services

Database corruption, ransomware

Very High

Strengthen database resilience, immutable backups and integrity validation

Database recovery exercises, integrity testing, disaster recovery reports

Demonstrate restoration of accurate customer balances following data corruption.

CO-1.5

Payment Transaction Processing

Merchant ecosystem, payment gateways, fraud controls

Ransomware, application failure, DDoS

Very High

Implement active-active processing, cyber resilience and capacity scaling

Penetration tests, cyber exercises, transaction performance testing

Assess whether critical payments remain within Impact Tolerance during cyber disruption.

CO-1.6

Funds Transfer and Settlement Processing

Banking institutions, clearing networks, treasury operations

Settlement platform outage, third-party ICT disruption

Very High

Maintain contingency settlement procedures and alternative processing arrangements

Settlement exercises, reconciliation testing, third-party assurance reports

Validate settlement resilience during major banking network disruption.

CO-1.7

Transaction Authorisation and Risk Controls

Authentication services, fraud monitoring, cybersecurity operations

Privileged access compromise, authentication failure

Very High

Strengthen privileged access management, adaptive authentication and SOC monitoring

Security monitoring reports, authentication testing, cyber simulation exercises

Evaluate fraud prevention and customer authentication resilience during cyber compromise.

CO-1.8

Merchant Payment Enablement

Merchant platforms, payment APIs, acquiring partners

API overload, capacity exhaustion

High

Enhance capacity planning, merchant API resilience and transaction load balancing

Capacity testing, merchant integration reports, performance monitoring

Assess merchant payment continuity during peak transaction demand.

CO-1.9

Digital Wallet Service Integration Management

Enterprise integration platform, banking APIs, payment ecosystem

API gateway failure, cloud outage, technology concentration risk

Very High

Diversify integration architecture, implement resilient APIs and continuous interface monitoring

Architecture reviews, cloud resilience testing, API failover reports

Validate end-to-end service continuity when multiple integration services fail simultaneously.

CO-1.10

Customer Transaction Notification and Communication

Telecommunications providers, notification platforms, customer support

SMS gateway failure, telecommunications disruption

Medium

Implement multi-channel communications and resilient notification services

Communication resilience tests, notification delivery reports

Assess customer communication effectiveness during telecommunications disruption.

CO-1.11

Transaction Monitoring and Operational Surveillance

Monitoring platforms, SOC, operational dashboards

Monitoring platform outage, logging failure

High

Implement redundant monitoring infrastructure and independent alerting mechanisms

SOC monitoring reports, monitoring failover exercises

Validate timely detection of operational degradation despite monitoring failures.

CO-1.12

Exception Handling and Transaction Resolution

Customer support, payment operations, reconciliation

Case management failure, operational overload

High

Expand surge capacity, automate case prioritisation and strengthen contingency workflows

Operational readiness reviews, workflow testing, customer service exercise reports

Evaluate organisational ability to manage high volumes of failed transactions.

CO-1.13

Financial Reconciliation and Operational Reporting

Finance, accounting, banking partners, regulators

Data corruption, reporting platform failure

High

Strengthen reconciliation automation, integrity controls and backup reporting capabilities

Financial control testing, reconciliation audits, reporting validation

Assess maintenance of financial integrity during reconciliation disruption.

CO-1.14

Operational Incident Management

Crisis management, executive management, technology operations

Cyber incident, communication platform failure

Very High

Conduct integrated cyber-crisis exercises and strengthen escalation governance

Crisis exercise reports, management review minutes, incident playbooks

Validate executive decision-making and coordinated response during major cyber incidents.

CO-1.15

Service Recovery and Operational Restoration

Disaster Recovery, cloud services, infrastructure providers

Disaster Recovery failure, regional infrastructure outage

Very High

Perform regular end-to-end recovery exercises, diversify recovery infrastructure and validate recovery governance

Disaster recovery test reports, failover exercises, independent assurance findings

Demonstrate the ability to restore Digital Wallet Operations within the approved Impact Tolerance following a catastrophic disruption.

 
Banner [Summing] [OR] [E3] Identify Severe but Plausible Scenarios

The Severe but Plausible Scenarios developed for CO-1 Digital Wallet Operations provide GCash with a structured framework for evaluating whether its most critical digital financial service can continue operating within its approved Impact Tolerance under conditions of significant operational stress.

By analysing each Sub-Critical Business Service individually while considering the interconnections across the entire service chain, the scenarios test the resilience of the complete Digital Wallet Operations ecosystem rather than isolated technology components.

The scenarios deliberately encompass a balanced range of disruption events, including cyberattacks, ICT infrastructure failures, cloud service disruptions, third-party outages, operational process failures, telecommunications interruptions, data integrity issues, capacity constraints, and regional infrastructure events.

This diversity ensures that scenario testing exercises challenge not only technical recovery capabilities but also governance, operational coordination, crisis management, third-party oversight, and customer service continuity.

Integrating Cyber and ICT risks throughout each scenario reflects the reality that modern digital financial services rely on highly interconnected technology platforms and external service providers. The scenarios demonstrate how cyber incidents or ICT failures can trigger cascading disruptions across multiple Sub-CBS processes, potentially resulting in breaches of the Impact Tolerance if preventive, detective, response, and recovery controls are ineffective.

This integrated approach aligns operational resilience with cyber resilience and ICT risk management, reinforcing the need for coordinated governance across business, technology, and risk functions.

Finally, these scenarios provide the foundation for a mature Operational Resilience testing programme. The outcomes of scenario testing should be used to identify resilience gaps, validate impact tolerances, strengthen recovery capabilities, prioritise investment decisions, enhance third-party risk management, and drive continuous improvement.

Regular review and refinement of these scenarios will help GCash maintain a resilient Digital Wallet Operations capability that can adapt to evolving threats, technology changes, and regulatory expectations while continuing to provide reliable financial services to its customers.

 

[OR] [GCash] [3/4 Banner] Strengthening Operational Resilience at GCash

eBook 3: Starting Your OR Implementation
CBS-1 Insurance Policy Application and Issuance
CBS-1 DP CBS-1 MII CBS-1 ITo CBS-1 SbPS CBS-1 ST
[OR] [GCash] [PH] [E3] [CO] [1] [DP] Digital Wallet Operations [OR] [GCash] [PH] [E3] [CO] [1] [MD] Digital Wallet Operations [OR] [GCash] [PH] [E3] [CO] [1] [ITo] Digital Wallet Operations New call-to-action [OR] [GCash] [PH] [E3] [CO] [1] [ST] Digital Wallet Operations

New call-to-actionNew call-to-action

 Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Your Comments Here:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM