eBook OR

[OR] [MBSB] [E1] [C1] Introducing OR Case Study

Written by Dr Goh Moh Heng | Aug 24, 2026, 7:43:55 AM

eBook 1: Chapter 1

Operational Resilience Case Study for MBSB Bank

Introduction

Operational resilience has become an increasingly important consideration for financial institutions operating in Malaysia.

Digitalisation, interconnected financial infrastructure, reliance on third-party service providers, cyber threats, technology concentration, changing customer expectations, and increasingly complex operating models mean that disruptions can propagate rapidly across an organisation and potentially the wider financial system.

For a financial institution such as MBSB Bank Berhad (MBSB Bank), operational resilience is therefore broader than maintaining conventional business continuity arrangements.

It requires the organisation to understand which services are most important, how those services are delivered, the resources and dependencies that support them, how much disruption it can tolerate, and whether it can continue delivering those services during severe but plausible disruptions.

MBSB Bank is a full-fledged Islamic banking institution regulated by Bank Negara Malaysia (BNM). Its banking activities serve retail, SME and corporate customers through physical and increasingly digital delivery channels.

This combination of banking operations, digital channels, payment infrastructure, customer-facing services, technology platforms and external dependencies provides an appropriate setting for examining Operational Resilience (OR) in practice.

The regulatory context is also evolving. On 19 December 2025, BNM issued its Discussion Paper on Operational Resilience, setting out emerging regulatory considerations for strengthening operational resilience among Malaysian financial institutions.

BNM has emphasised robust operational risk management, resilient technology and cyber capabilities, governance and accountability, and the ability of financial institutions to withstand disruption while continuing to deliver financial services.

This case study applies these principles to MBSB as a practical example. It does not represent MBSB's actual internal Operational Resilience framework unless information is publicly available.

Where internal arrangements are not publicly known, reasonable assumptions are made based on banking industry practices and BNM's emerging expectations.

 

The purpose of this chapter is to establish the organisational context required before developing an Operational Resilience programme for MBSB.

Operational resilience should not begin with technology solutions, recovery plans or scenario exercises. It should begin with an understanding of the organisation and the outcomes that need to be protected.

For MBSB, this means answering several fundamental questions:

  • What services does MBSB provide, and to whom?
  • Which services could cause a significant customer, institutional or financial-system impact if disrupted?
  • What internal and external resources support these services?
  • What dependencies and concentrations could create vulnerabilities?
  • What regulatory expectations influence the resilience programme?
  • Who should be accountable for Operational Resilience?
  • What outcomes should MBSB seek to achieve through its Operational Resilience programme?
  • What assumptions should be established before detailed analysis begins?

These questions create the foundation for the later stages of the Operational Resilience Planning Methodology.

The chapter therefore establishes an initial organisational profile, operating environment, proposed OR team structure, preliminary view of Critical Business Services (CBSs), organisational characteristics and Operational Resilience goals.

 

Understanding Your Organisation: MBSB Bank

Understanding the organisation is one of the most important prerequisites for Operational Resilience.

A financial institution cannot determine what must remain resilient without first understanding what it delivers, who depends upon those services and what consequences could arise if those services become unavailable.

Organisational Context

MBSB Bank operates as an Islamic banking institution in Malaysia and provides Shariah-compliant financial solutions to retail, SME and corporate customers. Its operating model combines conventional customer touchpoints with digital banking and payment capabilities.

Examples of customer-facing capabilities include individual and corporate online banking, fund transfers, DuitNow, JomPAY, financing payments, foreign fund transfers, account enquiries and other transactional services. Corporate banking capabilities also connect customers with payment mechanisms, including RENTAS and SWIFT.

From an Operational Resilience perspective, this means that MBSB should not be viewed simply as a collection of departments or systems.

It should be viewed as a network of services.

For example:

Customer → Digital Channel → Authentication → Core Banking → Payment Processing → External Payment Infrastructure → Beneficiary

A disruption at any point in this chain may affect the customer's ability to complete the required banking activity.

This service-oriented perspective is fundamental to Operational Resilience.

 

MBSB's Operating Environment in Malaysia

MBSB operates within a highly regulated financial services environment where the availability, integrity and security of banking services can directly affect customers, businesses and confidence in the financial system.

Regulatory Environment

The primary regulator considered for this case study is Bank Negara Malaysia.

represents an important development in Malaysia's approach to Operational Resilience. It considers lessons from operational disruptions, international developments, existing Malaysian regulatory requirements and the governance and accountability arrangements needed to strengthen resilience across financial institutions.

BNM's subsequent assessment of operational risk developments has highlighted practical resilience concerns, including:

  • recovery capabilities for critical technology;
  • modernisation of core banking systems;
  • governance and accountability;
  • identification of single points of failure;
  • dependencies affecting online banking, ATMs and call centres;
  • joint business continuity testing involving critical third-party service providers; and
  • scenario-specific preparedness for cyber incidents, power failures and critical IT infrastructure disruptions.

These considerations provide useful reference points for the MBSB case study.

Digital Dependency

Banking has become increasingly dependent upon technology.

MBSB provides digital banking capabilities for individual and corporate customers. Its corporate services include payment and transfer capabilities such as DuitNow, IBG, RENTAS and SWIFT, while its retail services similarly depend on electronic channels and interconnected financial infrastructure.

This creates a resilience challenge.

A customer may perceive a service as simple—for example, transferring money—but delivery may depend on:

Application → Network → Identity Service → Core Banking → Database → Payment Gateway → External Payment Network → Recipient Institution

Consequently, resilience cannot be assessed only at the application or departmental level.

Third-Party and Ecosystem Dependencies

Modern banks rely upon external organisations for technology, telecommunications, cloud services, payment processing, software, security, facilities and specialist services.

The failure of a third party can therefore become an operational disruption for MBSB even where MBSB's own infrastructure remains operational.

An effective OR programme should consequently extend dependency analysis beyond the organisational boundary.

Cyber Risk

Cyber incidents represent another important operating consideration.

Ransomware, distributed denial-of-service attacks, credential compromise, data breaches, malicious insiders and attacks against service providers can affect the confidentiality, integrity or availability of banking services.

Operational Resilience therefore, asks a different question from cybersecurity alone:

If a successful cyberattack occurs despite preventive controls, can MBSB continue delivering its most important services within acceptable limits?

That distinction is important. Operational Resilience assumes that not every disruption can be prevented.

 

Composition of an Operational Resilience Team for MBSB

Operational Resilience should not be owned exclusively by Business Continuity Management, Operational Risk or Technology.

It is inherently cross-functional.

For this case study, MBSB should establish an Operational Resilience Steering Committee, supported by an Operational Resilience Working Team.

Proposed Operational Resilience Team

 

Function

Primary OR Responsibility

Senior Management Sponsor

Executive sponsorship and strategic direction

Operational Risk

Risk framework integration and challenge

Business Continuity Management

Continuity and recovery capability

Technology / IT

Technology resilience and recovery

Cybersecurity

Cyber resilience and incident preparedness

Business Service Owners

Accountability for CBS resilience

Operations

Process and operational dependency analysis

Enterprise Risk Management

Integration with enterprise risks

Third-Party / Vendor Management

External dependency resilience

Compliance

Regulatory alignment

Shariah-related governance functions

Consider relevant Shariah governance implications

Legal

Legal and contractual considerations

Customer Service

Customer impact and disruption management

Corporate Communications

Internal and external crisis communications

Human Resources

Workforce resilience and competency

Facilities / Security

Workplace and physical resilience

Data Management

Data availability, integrity and recovery

The purpose of this structure is not to create another isolated resilience function.

Its purpose is to connect existing capabilities around the delivery of critical services.

This reflects the direction highlighted by BNM, particularly the importance of governance, accountability and coordinated resilience across increasingly complex dependencies.

 

Critical Business Services of MBSB: Key Considerations for Operational Resilience

One of the most important distinctions in Operational Resilience is between a business function and a business service.

Traditional BCM programmes frequently begin with departments, processes or applications.

Operational Resilience begins with the outcome delivered to the customer or another important stakeholder.

For example:

The IT Department is a function.

Core Banking System is a technology resource.

DuitNow is a payment mechanism.

But:

Enabling customers to access and transfer funds may represent a customer-facing business service.

This distinction becomes important when identifying MBSB's Critical Business Services.

 

Illustrative Critical Business Services

The following represents an initial case-study view rather than MBSB's formally approved CBS inventory.

 

Potential Critical Business Service

Why It May Be Important

Access to customer deposits and accounts

Customers depend upon access to their funds and account information

Domestic funds transfer

Customers and businesses depend upon the timely movement of funds

Digital banking services

Significant customer transactions increasingly depend upon digital access

Cash withdrawal and deposit services

Provides customers with access to and placement of physical cash

Financing, servicing and repayment

Supports customers' ongoing financing obligations

Corporate payment services

Businesses depend upon payment, payroll and treasury transactions

Interbank and high-value payment services

Supports transactions involving other financial institutions and financial infrastructure

Customer authentication and transaction authorisation

Enables secure access to multiple customer-facing services

MBSB's actual CBS determination would require a formal assessment.

Relevant criteria could include:

Customer impact

How many customers could be affected?

Financial impact

Could customers lose access to funds or suffer significant financial loss?

Duration

How quickly would disruption become unacceptable?

Market impact

Could disruption affect other institutions or financial infrastructure?

Regulatory impact

Would prolonged disruption interfere with regulatory obligations?

Reputational impact

Could disruption materially reduce customer confidence?

Systemic considerations

Could disruption propagate beyond MBSB?

This approach is consistent with the broader emphasis in BNM's Operational Resilience direction on maintaining the continued delivery of important financial services during disruption. 

 

Key Characteristics of MBSB Bank

Several organisational characteristics should influence the design of MBSB's Operational Resilience programme.

Islamic Banking Operating Model

MBSB Bank operates as an Islamic banking institution.

Resilience arrangements, therefore, need to recognise both conventional banking operational requirements and relevant Shariah governance considerations.

Diverse Customer Segments

MBSB serves retail, SME and corporate customers.

Different customer groups may experience disruption differently.

For example, temporary unavailability of corporate payment services could affect payroll or supplier payments, while retail banking disruption could prevent individuals from accessing funds.

Increasing Digitalisation

Digital banking increases convenience but also concentrates dependency upon technology, telecommunications, cybersecurity and data.

Digital resilience, therefore, becomes inseparable from Operational Resilience.

Interconnected Payment Environment

Services involving DuitNow, IBG, RENTAS, SWIFT and other payment mechanisms illustrate the interconnected nature of banking operations.

Resilience consequently depends not only upon MBSB but upon external financial infrastructure and participating institutions.

Multiple Delivery Channels

Customers may interact with the bank through branches, digital banking, self-service banking and other channels. MBSB's self-service facilities, for example, support withdrawals, deposits, balance enquiries, financing payments, bill payments and transfers.

Channel diversity can improve resilience where genuine alternatives exist, but only when the alternative channel does not depend upon the same underlying point of failure.

Regulatory Dependency

As a regulated financial institution, MBSB must align resilience capabilities with BNM's evolving expectations and related requirements concerning BCM, technology risk, operational risk and financial services.

Operational Resilience should therefore complement existing regulatory programmes rather than create an entirely separate control environment.

 

Establishing Organisational Goals for MBSB's Operational Resilience

An Operational Resilience programme requires clearly defined organisational goals.

The goal should not simply be:

"Prevent all disruptions"

That is neither realistic nor consistent with the fundamental concept of Operational Resilience.

Disruptions will occur

The objective is to ensure that the organisation can anticipate, withstand, respond to, recover from and learn from disruption while protecting the continued delivery of its most important services.

For this case study, MBSB could establish the following overarching goal:

To strengthen MBSB's ability to continue delivering Critical Business Services to customers and other stakeholders during severe but plausible operational disruptions, while limiting customer harm, protecting the institution and supporting confidence in Malaysia's financial system.

This can be translated into eight supporting objectives.

Objective 1 — Identify Critical Business Services

Establish a consistent methodology for identifying the services whose disruption could create unacceptable consequences.

Objective 2 — Understand End-to-End Dependencies

Map the people, processes, technology, information, facilities, and third parties supporting each CBS.

Objective 3 — Establish Impact Tolerances

Determine the maximum level of disruption that MBSB is prepared to tolerate for each CBS before the consequences become unacceptable.

Objective 4 — Identify Vulnerabilities

Use service mapping and risk analysis to identify:

  • single points of failure;
  • concentration risks;
  • inadequate capacity;
  • technology weaknesses;
  • workforce dependencies;
  • third-party vulnerabilities; and
  • insufficient recovery capability.
Objective 5 — Validate Resilience Through Scenario Testing

Conduct severe but plausible scenarios that challenge the end-to-end delivery of CBSs.

Examples could include:

Scenario A — Major Cyberattack

Ransomware compromises critical technology supporting digital banking.

Scenario B — Core Banking Failure

A technology failure prevents customers from accessing accounts and completing transactions.

Scenario C — Payment Infrastructure Disruption

Connectivity with an important payment infrastructure becomes unavailable.

Scenario D — Critical Third-Party Failure

A major service provider suffers an extended outage.

Scenario E — Telecommunications Failure

Connectivity affecting branches, customer channels or data centres is disrupted.

Scenario F — Major Data Integrity Incident

Transaction or account information becomes unavailable or unreliable.

These examples also reflect concerns identified in BNM's observations concerning cyber threats, critical IT failures, power outages, third-party dependencies and single points of failure. (Bank Negara Malaysia)

Objective 6 — Strengthen Governance and Accountability

Assign clear accountability for the resilience of Critical Business Services and establish appropriate escalation and reporting mechanisms.

Objective 7 — Integrate Existing Disciplines

Operational Resilience should integrate rather than replace:

Operational Risk Management + BCM + IT Disaster Recovery + Cybersecurity + Crisis Management + Third-Party Risk Management + Incident Management

The common point of integration should be the Critical Business Service.

Objective 8 — Establish Continuous Improvement

Lessons from incidents, exercises, near misses, risk assessments and regulatory reviews should be converted into measurable resilience improvements.

Initial Operational Resilience Assumptions

Before proceeding with detailed analysis, several working assumptions are useful for this case study.

These assumptions will be validated or refined as the Operational Resilience programme progresses.

 

Assumption

OR Implication

Digital banking will continue to increase in importance

Technology and cyber resilience become critical

Customers increasingly expect continuous access to banking services

Service availability expectations will remain high

MBSB depends upon external service providers

Third-party resilience must form part of CBS assessment

Critical services depend upon interconnected systems

End-to-end mapping is necessary

Not all disruptions can be prevented

Recovery and adaptation capabilities must be developed

Some disruptions may affect several services simultaneously

Scenario testing should consider correlated failures

Customer impact increases with disruption duration

Impact tolerance should incorporate time

Alternative channels may share common infrastructure

Substitution arrangements must be validated rather than assumed

Regulatory expectations will continue to develop

The OR framework should be adaptable

These assumptions encourage MBSB to move from a recovery-centric mindset toward a service-resilience mindset.

From Business Continuity to Operational Resilience

MBSB would not be starting its resilience journey from zero.

Like other regulated Malaysian financial institutions, existing capabilities in areas such as BCM, technology risk, cybersecurity, incident management and operational risk provide important foundations.

Operational Resilience builds upon these capabilities.

A useful distinction is:

This shifts attention from organisational components to service outcomes.

Consider a hypothetical MBSB digital banking disruption.

Recovering the application server within the documented Recovery Time Objective would not necessarily demonstrate resilience if customers remained unable to transact because authentication, telecommunications, or an external payment connection remained unavailable.

Operational Resilience, therefore, requires an end-to-end perspective.

This is particularly relevant given BNM's observations concerning dependency complexity and single points of failure affecting channels such as online banking, ATMs and call centres.

 

Illustrative Operational Resilience Foundation for MBSB

The initial foundation established in this chapter can be summarised as follows:

 

Foundation Element

MBSB Case Study Position

Organisation

MBSB Bank Berhad

Sector

Financial Services / Islamic Banking

Jurisdiction

Malaysia

Primary Regulator

Bank Negara Malaysia

Primary Stakeholders

Retail, SME and corporate customers

Resilience Focus

Continued delivery of Critical Business Services

Primary Drivers

Customer protection, regulatory expectations, digital dependency and financial-system confidence

Governance

Board and Senior Management oversight with cross-functional OR governance

Core OR Unit of Analysis

Critical Business Service

Primary Dependencies

People, process, technology, information, facilities and third parties

Key Threat Areas

Cyberattack, technology failure, third-party disruption, payment-system disruption, telecommunications failure and operational failure

Existing Capabilities to Integrate

BCM, Operational Risk, Technology Risk, Cybersecurity, Crisis Management, Incident Management and Third-Party Risk

Desired Outcome

Critical services remain within defined impact tolerances during severe but plausible disruptions

 

This chapter has established the organisational foundation for the MBSB Operational Resilience case study.

MBSB operates within an increasingly digital and interconnected Malaysian financial services environment.

Its ability to provide banking services depends upon combinations of people, processes, technology, data, facilities, payment infrastructure and third-party organisations.

This complexity means that resilience cannot be achieved by managing individual risks or recovery plans independently.

The focus must move toward the continued delivery of Critical Business Services.

The 2025 BNM Discussion Paper reinforces this direction by positioning Operational Resilience around the ability of financial institutions to withstand disruption, supported by strong operational risk management, technology and cyber resilience, governance and accountability.

BNM's subsequent observations also highlight practical priorities such as recovery capability, single points of failure and joint testing with critical third-party service providers.

For MBSB, this chapter establishes four important foundations:

  • First, Operational Resilience should be governed as an enterprise-wide responsibility rather than as an isolated BCM or technology initiative.

  • Second, MBSB should identify its Critical Business Services from the perspective of outcomes delivered to customers and other stakeholders.

  • Third, resilience should be assessed across the entire service delivery chain, including internal and external dependencies.

  • Fourth, the objective is not to eliminate every disruption. The objective is to ensure that disruption does not exceed the organisation's ability to continue delivering its most important services within acceptable limits.

With the organisational context established, the next step is to examine MBSB's operating environment in greater depth—including its internal and external context, stakeholder expectations, regulatory drivers, technology dependencies, third-party ecosystem and the disruption landscape that could affect the delivery of its Critical Business Services.

This understanding will provide the basis for developing a structured and organisation-specific Operational Resilience programme for MBSB.

 

 

eBook 1: Understanding Your Organisation: MBSB Bank
C1 C2 C3 C4
C5 C6 C7 C8
 

For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.