Severe but Plausible Scenarios are a fundamental component of an Operational Resilience programme because they enable an organisation to assess whether a Critical Operation can continue to operate within its defined Impact Tolerance when exposed to significant disruption.
Rather than testing the recovery of individual systems or departments, these scenarios evaluate the resilience of the end-to-end service delivered to customers and other stakeholders.
For GCash's CO-1 Digital Wallet Operations, the scenarios are developed using the previously identified Sub-Critical Business Services (Sub-CBS) as the primary units of analysis.
This approach ensures that every major business process supporting the digital wallet ecosystem is evaluated for operational vulnerabilities, interconnections, and dependencies that could contribute to service disruption.
The scenarios integrate operational, technology, cyber, ICT, third-party, and people-related risks because Digital Wallet Operations rely upon highly interconnected digital platforms, payment ecosystems, banking interfaces, telecommunications infrastructure, cloud services, and regulatory obligations.
Consequently, cyber incidents, infrastructure failures, operational mistakes, and external disruptions are considered together to provide a realistic assessment of resilience.
The following scenarios are intended to test whether GCash can maintain Digital Wallet Operations within its defined Impact Tolerance while identifying opportunities for strengthening preventive controls, recovery capabilities, governance, and continuous resilience improvement.
Table 1 (Part 1): Severe but Plausible Scenarios
|
Sub-CBS Code |
Name of Sub-CBS |
Recommended Severe but Plausible Scenario |
Scenario Description |
Primary Disruption Trigger |
Impact on Sub-CBS |
Impact on Critical Business Service |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
Distributed Denial-of-Service (DDoS) attack against customer onboarding platform |
A coordinated cyberattack overwhelms customer registration services during a peak onboarding campaign, preventing new customer registrations and delaying wallet provisioning. |
External cyberattack |
New customer onboarding is interrupted and registration requests accumulate. |
Reduced customer acquisition and delayed access to Digital Wallet Operations. |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
National identity verification service unavailable |
Connectivity to external identity verification services is disrupted due to a telecommunications outage affecting multiple service providers. |
Third-party service disruption |
Customer identity verification cannot be completed, preventing account activation. |
New customers cannot access Digital Wallet services and regulatory compliance obligations may be affected. |
|
CO-1.3 |
Wallet Funding and Value Loading |
Simultaneous failure of banking connectivity and payment gateway |
A major telecommunications disruption affects multiple banking interfaces, preventing customers from loading funds into their wallets. |
Telecommunications and network outage |
Cash-in transactions fail or remain pending. |
Customers cannot fund wallets, reducing transaction volumes and service usability. |
|
CO-1.4 |
Wallet Balance Management |
Database corruption following failed infrastructure update |
A failed database software deployment corrupts transaction ledger synchronisation, causing inconsistent wallet balances across replicated databases. |
Failed technology change |
Wallet balances become unreliable until integrity is restored. |
Customers lose confidence, payment processing becomes unreliable, and financial integrity is threatened. |
|
CO-1.5 |
Payment Transaction Processing |
Ransomware attack on payment processing environment |
Malware encrypts critical transaction processing servers, forcing payment processing to fail while recovery procedures are initiated. |
Cyberattack (Ransomware) |
Payment processing becomes unavailable. |
Widespread inability to complete digital payments, affecting customers and merchants nationwide. |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
Interbank settlement network disruption |
A failure within national payment infrastructure delays settlement processing across participating financial institutions. |
External financial infrastructure disruption |
Funds transfers remain incomplete and settlement queues increase. |
Delayed customer transfers and growing settlement backlog impact service confidence. |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication platform compromise |
Privileged credentials are compromised, requiring emergency suspension of authentication services while security controls are restored. |
Cybersecurity breach |
Transaction authorisation is restricted or suspended. |
Legitimate transactions are delayed while fraud prevention measures remain effective. |
|
CO-1.8 |
Merchant Payment Enablement |
QR payment platform capacity exhaustion |
Peak transaction demand exceeds platform capacity following a major promotional campaign, causing widespread merchant payment failures. |
Capacity and performance degradation |
Merchant payment acceptance slows significantly. |
Customers experience payment failures across large merchant networks. |
Table 1 (Part 2): Severe but Plausible Scenarios
|
Sub-CBS Code |
Name of Sub-CBS |
Recommended Severe but Plausible Scenario |
Scenario Description |
Primary Disruption Trigger |
Impact on Sub-CBS |
Impact on Critical Business Service |
|
CO-1.9 |
Digital Wallet Service Integration Management |
Enterprise API Gateway Failure Combined with Cloud Connectivity Degradation |
A software defect introduced during a routine infrastructure change causes the enterprise API gateway to fail while cloud connectivity simultaneously becomes unstable, interrupting communications between Digital Wallet Operations and multiple banking, merchant and payment ecosystem interfaces. |
Failed technology change combined with cloud infrastructure degradation |
Integration services become unavailable, preventing real-time communication between internal and external services. |
Multiple Sub-CBS fail simultaneously, causing widespread disruption across Digital Wallet Operations and significantly increasing the likelihood of exceeding the Impact Tolerance. |
|
CO-1.10 |
Customer Transaction Notification and Communication |
Nationwide Telecommunications Service Disruption |
A regional telecommunications outage affects SMS, push notification and mobile data services, preventing timely customer notifications despite successful transaction processing. |
Telecommunications infrastructure failure |
Customers do not receive transaction confirmations, fraud alerts or account notifications. |
Customer confidence declines, enquiries increase, fraud detection by customers is delayed and contact centre volumes rise significantly. |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Simultaneous Failure of Monitoring Platform and Security Event Collection |
A monitoring software failure coincides with a logging infrastructure fault, preventing operational teams from detecting deteriorating service conditions and cyber events. |
ICT monitoring platform failure |
Service degradation remains undetected, delaying operational response and incident escalation. |
Minor operational issues escalate into major service disruptions because corrective action is delayed. |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Surge in Failed Transactions Following Payment Network Disruption |
A prolonged payment network outage generates an unusually high volume of failed and duplicate transactions, overwhelming investigation and customer resolution teams. |
External payment network disruption |
Investigation backlogs increase significantly and customer cases remain unresolved for extended periods. |
Customer dissatisfaction increases while unresolved transactions undermine confidence in Digital Wallet Operations. |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Data Integrity Failure During End-of-Day Reconciliation |
Corrupted settlement files received from external payment channels prevent automated reconciliation and require extensive manual investigation. |
Data corruption |
Financial reconciliation cannot be completed accurately within operational deadlines. |
Regulatory reporting may be delayed, financial records become unreliable and operational risk increases. |
|
CO-1.14 |
Operational Incident Management |
Major Cyber Incident Combined with Failure of Incident Escalation Procedures |
A ransomware attack affects operational systems while automated incident notification workflows fail, delaying escalation to executive management and crisis teams. |
Cyberattack combined with process failure |
Incident coordination becomes fragmented, delaying decision-making and recovery activities. |
Service disruption is prolonged, increasing customer impact and the probability of exceeding the Impact Tolerance. |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Simultaneous Failure of Primary and Disaster Recovery Environments |
A regional power disruption combined with storage replication failure renders both the primary production environment and recovery environment temporarily unavailable. |
Regional infrastructure disruption combined with disaster recovery failure |
Recovery activities cannot proceed according to planned recovery procedures. |
Digital Wallet Operations remain unavailable beyond acceptable limits, resulting in unacceptable customer, regulatory and operational harm. |
Table 2 (Part 2): Scenario Assessment and Resilience Testing
|
Sub-CBS Code |
Name of Sub-CBS |
Interconnections and Interdependencies Challenged |
Cyber and ICT Risk Linkage |
Potential Impact Tolerance Breach |
Proactive Risk Management Action |
Evidence of Proactive Risk Management |
Scenario Testing Objective |
|
CO-1.1 |
Digital Wallet Registration and Provisioning |
Customer onboarding, identity verification, CRM integration |
DDoS attack, API disruption |
Low-Medium |
Deploy DDoS mitigation, API redundancy and scalable onboarding architecture |
DDoS testing reports, API resilience testing, onboarding failover exercises |
Validate customer onboarding resilience during cyber disruption. |
|
CO-1.2 |
Customer Identity Verification and Account Validation |
Identity providers, compliance operations, fraud management |
Third-party ICT failure, identity platform outage |
Medium |
Diversify identity verification providers and strengthen contingency verification procedures |
Third-party assurance reports, KYC resilience tests, supplier continuity reviews |
Assess resilience when external identity verification services become unavailable. |
|
CO-1.3 |
Wallet Funding and Value Loading |
Banking connectivity, payment gateways, settlement services |
Network outage, API failure |
High |
Implement multiple banking connections and resilient payment routing |
Banking interface testing, network resilience reports, payment failover tests |
Validate continuity of customer funding under banking connectivity failures. |
|
CO-1.4 |
Wallet Balance Management |
Transaction processing, financial reconciliation, customer services |
Database corruption, ransomware |
Very High |
Strengthen database resilience, immutable backups and integrity validation |
Database recovery exercises, integrity testing, disaster recovery reports |
Demonstrate restoration of accurate customer balances following data corruption. |
|
CO-1.5 |
Payment Transaction Processing |
Merchant ecosystem, payment gateways, fraud controls |
Ransomware, application failure, DDoS |
Very High |
Implement active-active processing, cyber resilience and capacity scaling |
Penetration tests, cyber exercises, transaction performance testing |
Assess whether critical payments remain within Impact Tolerance during cyber disruption. |
|
CO-1.6 |
Funds Transfer and Settlement Processing |
Banking institutions, clearing networks, treasury operations |
Settlement platform outage, third-party ICT disruption |
Very High |
Maintain contingency settlement procedures and alternative processing arrangements |
Settlement exercises, reconciliation testing, third-party assurance reports |
Validate settlement resilience during major banking network disruption. |
|
CO-1.7 |
Transaction Authorisation and Risk Controls |
Authentication services, fraud monitoring, cybersecurity operations |
Privileged access compromise, authentication failure |
Very High |
Strengthen privileged access management, adaptive authentication and SOC monitoring |
Security monitoring reports, authentication testing, cyber simulation exercises |
Evaluate fraud prevention and customer authentication resilience during cyber compromise. |
|
CO-1.8 |
Merchant Payment Enablement |
Merchant platforms, payment APIs, acquiring partners |
API overload, capacity exhaustion |
High |
Enhance capacity planning, merchant API resilience and transaction load balancing |
Capacity testing, merchant integration reports, performance monitoring |
Assess merchant payment continuity during peak transaction demand. |
|
CO-1.9 |
Digital Wallet Service Integration Management |
Enterprise integration platform, banking APIs, payment ecosystem |
API gateway failure, cloud outage, technology concentration risk |
Very High |
Diversify integration architecture, implement resilient APIs and continuous interface monitoring |
Architecture reviews, cloud resilience testing, API failover reports |
Validate end-to-end service continuity when multiple integration services fail simultaneously. |
|
CO-1.10 |
Customer Transaction Notification and Communication |
Telecommunications providers, notification platforms, customer support |
SMS gateway failure, telecommunications disruption |
Medium |
Implement multi-channel communications and resilient notification services |
Communication resilience tests, notification delivery reports |
Assess customer communication effectiveness during telecommunications disruption. |
|
CO-1.11 |
Transaction Monitoring and Operational Surveillance |
Monitoring platforms, SOC, operational dashboards |
Monitoring platform outage, logging failure |
High |
Implement redundant monitoring infrastructure and independent alerting mechanisms |
SOC monitoring reports, monitoring failover exercises |
Validate timely detection of operational degradation despite monitoring failures. |
|
CO-1.12 |
Exception Handling and Transaction Resolution |
Customer support, payment operations, reconciliation |
Case management failure, operational overload |
High |
Expand surge capacity, automate case prioritisation and strengthen contingency workflows |
Operational readiness reviews, workflow testing, customer service exercise reports |
Evaluate organisational ability to manage high volumes of failed transactions. |
|
CO-1.13 |
Financial Reconciliation and Operational Reporting |
Finance, accounting, banking partners, regulators |
Data corruption, reporting platform failure |
High |
Strengthen reconciliation automation, integrity controls and backup reporting capabilities |
Financial control testing, reconciliation audits, reporting validation |
Assess maintenance of financial integrity during reconciliation disruption. |
|
CO-1.14 |
Operational Incident Management |
Crisis management, executive management, technology operations |
Cyber incident, communication platform failure |
Very High |
Conduct integrated cyber-crisis exercises and strengthen escalation governance |
Crisis exercise reports, management review minutes, incident playbooks |
Validate executive decision-making and coordinated response during major cyber incidents. |
|
CO-1.15 |
Service Recovery and Operational Restoration |
Disaster Recovery, cloud services, infrastructure providers |
Disaster Recovery failure, regional infrastructure outage |
Very High |
Perform regular end-to-end recovery exercises, diversify recovery infrastructure and validate recovery governance |
Disaster recovery test reports, failover exercises, independent assurance findings |
Demonstrate the ability to restore Digital Wallet Operations within the approved Impact Tolerance following a catastrophic disruption. |
The Severe but Plausible Scenarios developed for CO-1 Digital Wallet Operations provide GCash with a structured framework for evaluating whether its most critical digital financial service can continue operating within its approved Impact Tolerance under conditions of significant operational stress.
By analysing each Sub-Critical Business Service individually while considering the interconnections across the entire service chain, the scenarios test the resilience of the complete Digital Wallet Operations ecosystem rather than isolated technology components.
The scenarios deliberately encompass a balanced range of disruption events, including cyberattacks, ICT infrastructure failures, cloud service disruptions, third-party outages, operational process failures, telecommunications interruptions, data integrity issues, capacity constraints, and regional infrastructure events.
This diversity ensures that scenario testing exercises challenge not only technical recovery capabilities but also governance, operational coordination, crisis management, third-party oversight, and customer service continuity.
Integrating Cyber and ICT risks throughout each scenario reflects the reality that modern digital financial services rely on highly interconnected technology platforms and external service providers. The scenarios demonstrate how cyber incidents or ICT failures can trigger cascading disruptions across multiple Sub-CBS processes, potentially resulting in breaches of the Impact Tolerance if preventive, detective, response, and recovery controls are ineffective.
This integrated approach aligns operational resilience with cyber resilience and ICT risk management, reinforcing the need for coordinated governance across business, technology, and risk functions.
Finally, these scenarios provide the foundation for a mature Operational Resilience testing programme. The outcomes of scenario testing should be used to identify resilience gaps, validate impact tolerances, strengthen recovery capabilities, prioritise investment decisions, enhance third-party risk management, and drive continuous improvement.
Regular review and refinement of these scenarios will help GCash maintain a resilient Digital Wallet Operations capability that can adapt to evolving threats, technology changes, and regulatory expectations while continuing to provide reliable financial services to its customers.
| eBook 3: Starting Your OR Implementation |
||||
| CBS-1 Insurance Policy Application and Issuance | ||||
| CBS-1 DP | CBS-1 MII | CBS-1 ITo | CBS-1 SbPS | CBS-1 ST |
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|