eBook OR

[OR] [MBSB] [E1] [C2] Understanding Your Organisation

Written by Moh Heng Goh | Aug 24, 2026, 9:34:13 AM

Chapter 2

Understanding Your Organisation: MBSB Bank

Introduction

Operational Resilience (OR) cannot be implemented effectively without first understanding the organisation to which the resilience framework will be applied.

For MBSB Bank (MBSB), this requires an appreciation of its business model, customers, products and services, operating environment, regulatory obligations, technology landscape, delivery channels, third-party relationships and connections with Malaysia's wider financial ecosystem.

These elements determine which disruptions could matter most and where resilience capabilities should ultimately be concentrated.

This organisational understanding is increasingly important as financial services become more digital, interconnected and dependent on external infrastructure.

Bank Negara Malaysia's 2025 Discussion Paper on Operational Resilience identifies rapid digitalisation, cyber threats, deeper third-party dependencies and increasingly severe operational disruptions as important drivers of the need to strengthen the continuity of critical financial services.

BNM also observes that financial institutions must recognise that disruptions are increasingly complex and inevitable and complement prevention with preparedness, adaptability and robust recovery capabilities.

For MBSB, understanding the organisation is therefore not merely an introductory exercise. It establishes the context within which Critical Business Services can subsequently be identified, dependencies mapped, impact tolerances established and severe but plausible scenarios tested.

The purpose of this chapter is to establish a structured understanding of MBSB Bank as an organisation before applying the Operational Resilience Planning Methodology.

The reader should understand why the organisational context—including customers, business activities, digital delivery channels, people, technology, information, facilities, third parties and financial infrastructure—must be understood before resilience priorities are determined.

BNM's emerging direction reinforces this approach by emphasising the identification of operations and services that are critical to consumers and the market, deep visibility over internal and external dependencies, customer-oriented impact tolerances, severe but plausible scenario testing, strong board oversight and continuous learning.

By the end of this chapter, the reader should be able to establish an initial organisational profile for MBSB, identify the characteristics of its operating environment that influence resilience, recognise the principal sources of dependency and disruption, and understand how existing BCM and operational risk capabilities can provide the foundation for a broader OR programme.

The objective is not yet to determine MBSB's Critical Business Services or define detailed resilience solutions.

Rather, it is to establish sufficient organisational context so that those decisions can subsequently be made from an informed, end-to-end and customer-focused perspective.

Why Understanding the Organisation Comes First

Operational Resilience is fundamentally concerned with an organisation's ability to continue delivering its most important services when disruption occurs.

Before MBSB can determine what must remain resilient, it must understand:

  • what services it provides;
  • who receives and depends upon those services;
  • how those services are delivered;
  • what internal and external resources enable their delivery;
  • which dependencies could become points of failure;
  • what consequences could arise from disruption;
  • what existing resilience capabilities are already available; and
  • what regulatory expectations influence resilience priorities.

This is particularly important for a financial institution because a seemingly simple customer transaction may depend on a complex chain of resources.

For example:

 

Customer

Digital Banking Channel

Authentication and Identity Services

Payment Processing Application

Core Banking Platform

Payment Network / External Financial Infrastructure

Settlement and Account Update

 

The customer experiences this as a single service. Operationally, however, numerous internal systems, teams and external organisations may be involved.

A weakness anywhere along this chain can disrupt the final customer outcome.

This is why Operational Resilience requires an end-to-end service perspective rather than a purely departmental, process or technology perspective.

Understanding MBSB Bank's Organisational Context

For this case study, MBSB should be understood as a Malaysian financial institution operating within an increasingly digital and interconnected financial ecosystem.

Its organisational context can be examined through several dimensions.

Customers and Stakeholders

MBSB serves different customer segments whose dependence upon banking services can vary significantly.

These may include:

  • individual and retail customers;
  • small and medium-sized enterprises;
  • commercial and corporate customers;
  • financing customers;
  • depositors;
  • payment recipients and counterparties;
  • other financial institutions; and
  • regulators and financial-market participants.

Operational Resilience should consider the consequences of disruption from these stakeholders' perspectives rather than assessing impact solely from MBSB's internal financial or operational perspective.

This is particularly important because BNM notes that digitalisation has increased consumer expectations for uninterrupted financial services, especially services affecting access to funds, such as mobile and online banking and real-time payments.

Products and Services

MBSB's operating environment encompasses banking activities that may include:

  • deposit and account services;
  • financing;
  • payments and funds transfers;
  • digital banking;
  • cash access;
  • corporate banking;
  • transaction authentication;
  • customer support; and
  • associated financial services.

Not every product, process or activity will necessarily qualify as a Critical Business Service (CBS).

Understanding the complete service landscape nevertheless provides the starting population from which critical services can subsequently be identified.

Understanding MBSB as a Service Ecosystem

Traditional organisational analysis frequently begins with the organisational chart.

Operational Resilience requires a different perspective.

MBSB should increasingly be viewed as a service ecosystem comprising interconnected business and operational capabilities.

A simplified representation is:

 

Customers and Stakeholders

Business Services

Business Processes

People and Skills

Applications and Technology

Data and Information

Facilities and Infrastructure

Third Parties and Financial Ecosystem

 

Each layer can contain dependencies capable of affecting the service delivered to the customer.

For example, the availability of a customer payment service may depend on more than the payment application. It may also require authentication, core banking data, network connectivity, payment infrastructure, cybersecurity controls, operational personnel and external service providers.

BNM specifically identifies tightly interconnected payment networks, clearing and settlement infrastructure, telecommunications, cloud ecosystems, outsourced functions, fintech platforms and data centres as sources of dependency and concentration risk.

Understanding these relationships becomes a prerequisite for meaningful resilience analysis.

MBSB's External Operating Environment

 

Operational Resilience should not be assessed within the boundaries of MBSB alone.

The bank operates within a broader environment consisting of regulators, customers, technology providers, telecommunications operators, payment infrastructure, financial counterparties and other service providers.

Changes or disruptions within this environment can affect MBSB even when the bank's own internal operations remain functional.

Digitalisation

Digital financial services have transformed the way customers interact with banks.

Customers increasingly expect banking services to be available continuously and transactions to occur in near real time.

BNM observes that mobile banking, electronic Know-Your-Customer, digital onboarding, QR payments, cloud applications, APIs and open financial architectures have created increasingly complex dependency chains.

These developments improve service delivery but also increase sensitivity to outages and vulnerabilities across software supply chains and interfaces.

For MBSB, this means technology resilience must be considered from the perspective of the business service being delivered, not merely whether individual systems meet their availability targets.

Cyber Threats

Cybersecurity represents another major component of MBSB's operating environment.

BNM identifies increasingly sophisticated cyber threats, including ransomware, attacks on critical infrastructure, destructive malware, supply-chain exploitation and attacks delivered through third-party providers.

Such incidents can impair financial services for extended periods and require capabilities beyond traditional recovery arrangements.

Operational Resilience therefore complements cybersecurity.

Cybersecurity asks:

How can MBSB prevent and detect cyber incidents?

Operational Resilience additionally asks:

If the cyber incident succeeds, can MBSB continue delivering its Critical Business Services within acceptable limits?

Both capabilities are necessary.

Third-Party and External Dependencies

 

Modern banking operations depend heavily on organisations outside the direct control of the financial institution.

For MBSB, potential external dependencies may include:

  • telecommunications providers;
  • technology vendors;
  • software providers;
  • cloud service providers;
  • data centres;
  • payment infrastructure;
  • outsourced operational providers;
  • cybersecurity service providers;
  • cash logistics providers; and
  • specialist professional services.

The resilience of a Critical Business Service therefore cannot be determined solely by examining MBSB's own controls.

BNM highlights the challenge of substituting external providers during disruption, particularly where dependency chains are opaque or where financial institutions depend upon a concentrated number of specialist providers that cannot easily be replaced.

This has an important implication for MBSB:

Outsourcing an activity does not outsource accountability for the resilience of the service.

MBSB should consequently understand not only its direct third parties but, where material, the critical dependencies those providers themselves rely upon.

Understanding MBSB's Internal Environment

The internal environment is equally important.

Operational Resilience requires MBSB to understand how its organisational capabilities combine to deliver customer services.

Six broad resource categories should be considered.

 

Resource Category

Examples Relevant to MBSB

Operational Resilience Consideration

People

Operations staff, technology teams, customer-service personnel, cyber specialists, branch employees

Are critical skills sufficiently available during disruption?

Processes

Account servicing, payments, authentication, settlement, reconciliation

Can critical processes operate under degraded conditions?

Technology

Core banking, digital banking, databases, networks, payment applications

Are there single points of failure or recovery limitations?

Information

Customer information, account balances, transaction records, payment instructions

Can information remain available, accurate and trustworthy?

Facilities

Branches, offices, operations centres and technology facilities

Can services continue if a critical location becomes unavailable?

Third Parties

Telecommunications, technology, payment and outsourced service providers

Can critical services continue if an external provider fails?

 

These categories provide the foundation for the more detailed mapping of interconnections and interdependencies later in the Operational Resilience implementation process.

Existing BCM as a Foundation for Operational Resilience

 

Operational Resilience does not mean abandoning Business Continuity Management.

BCM remains an important foundation.

MBSB's existing BCM arrangements would typically provide capabilities such as:

  • Business Impact Analysis;
  • risk assessment;
  • continuity strategies;
  • Business Continuity Plans;
  • technology disaster recovery;
  • alternate working arrangements;
  • crisis management;
  • incident response;
  • testing and exercising; and
  • recovery objectives.

Operational Resilience builds upon these capabilities but changes the perspective.

A traditional BCM assessment might ask:

How quickly can a critical business function or system be recovered?

Operational Resilience asks:

Can the Critical Business Service continue to be delivered within an acceptable level of disruption, regardless of which supporting resource fails?

BNM makes a similar distinction by observing that internal metrics such as Maximum Tolerable Downtime (MTD) and Recovery Time Objective (RTO) remain necessary but may not be adequate because impact tolerances should also consider outcomes for customers and other stakeholders.

MBSB should therefore use its existing BCM capability as a building block rather than create an entirely separate resilience structure.

Regulatory Context for MBSB

 

BNM's 2025 Discussion Paper provides an important indication of the emerging direction of Operational Resilience regulation in Malaysia.

It is important, however, to distinguish between existing regulatory requirements and emerging expectations presented for discussion.

The December 2025 publication is a Discussion Paper rather than, by itself, a final Operational Resilience policy document. BNM describes it as setting out its emerging direction and key considerations for strengthening the Operational Resilience of financial institutions.

For MBSB, the Discussion Paper nevertheless provides a valuable basis for preparing its Operational Resilience programme.

Examples of the capabilities that MBSB should consider include:

Identification of Critical Operations and Services

BNM states that financial institutions should identify which operations and/or services are critical to consumers and the market and preserve their continuity.

For MBSB, this supports the development of a formally governed Critical Business Service inventory.

End-to-End Dependency Visibility

BNM identifies deep visibility over internal and external dependencies as essential.

MBSB should therefore map CBS dependencies across people, processes, technology, information, facilities and third parties.

Impact Tolerance

BNM highlights the importance of considering customer and stakeholder outcomes when determining tolerable disruption and notes that traditional MTD and RTO measures alone may be insufficient.

MBSB should therefore complement existing recovery objectives with service-level impact tolerances.

Severe but Plausible Scenario Testing

BNM observes that testing isolated failures is no longer sufficient. Scenario testing should be severe but reasonably plausible and should consider concurrent scenarios where appropriate.

MBSB should consequently test the end-to-end resilience of its CBSs rather than rely solely on component-level disaster recovery exercises.

Governance and Accountability

BNM identifies strong board oversight and timely decision-making through cross-functional and integrated arrangements as important characteristics of resilient financial institutions.

MBSB's OR framework should therefore establish clear accountability from the Board and Senior Management through to individual business service owners.

Continuous Improvement

BNM also emphasises structured learning from operational disruptions and incorporating lessons into future planning.

For MBSB, incidents, exercises, near misses and scenario tests should therefore result in documented corrective actions and measurable improvements.

Alignment with ISO 22316

BNM's emerging Operational Resilience direction can also be considered alongside ISO 22316:2017, Security and resilience — Organizational resilience — Principles and attributes.

ISO 22316 guides enhancing organisational resilience and is applicable to organisations of different sizes and sectors. Importantly, the standard does not prescribe a uniform approach; resilience objectives and initiatives should be appropriate to the individual organisation's needs.

The standard takes a broad view of organisational resilience, including the importance of organisational culture, shared values, awareness of changing circumstances, effective risk management and strong leadership.

For MBSB, these principles complement the more financial-services-specific direction emerging from BNM.

 

Resilience Principle

Application to MBSB

Understanding organisational context

Understand MBSB's customers, services, dependencies and operating environment

Leadership and commitment

Establish Board and Senior Management ownership of resilience

Awareness of changing circumstances

Monitor cyber, technology, third-party, regulatory and environmental developments

Resilience-supporting culture

Embed resilience responsibilities across business and supporting functions

Coordinated management disciplines

Integrate Operational Risk, BCM, ITDR, Cybersecurity, Crisis Management and Third-Party Risk

Adaptability

Develop capabilities to respond when disruption does not follow predetermined recovery assumptions

Continuous improvement

Convert incidents, exercises and scenario-test findings into resilience improvements

 

ISO 22316 therefore provides the broader organisational principles, while BNM's emerging direction provides a financial-sector context for applying resilience to the continuity of critical financial services.

Developing MBSB's Organisational Resilience Profile

 

Based on the considerations discussed in this chapter, MBSB can establish an initial Operational Resilience profile.

 

Dimension

Initial MBSB OR Consideration

Organisation

MBSB Bank

Jurisdiction

Malaysia

Sector

Financial Services Institution

Primary Regulator

Bank Negara Malaysia

Primary OR Focus

Continued delivery of Critical Business Services

Key Stakeholders

Customers, businesses, counterparties, regulators and financial-market participants

Key Dependencies

People, processes, technology, information, facilities and third parties

Major Disruption Sources

Cyber incidents, technology failures, third-party outages, data compromise, telecommunications failures and physical disruption

Existing Foundations

BCM, operational risk, technology risk, cybersecurity, crisis management and third-party risk

Emerging OR Requirements

CBS identification, dependency mapping, impact tolerance, severe but plausible scenario testing, governance and continuous improvement

Desired Outcome

Critical services remain deliverable within acceptable levels of disruption

 

This profile should not be regarded as static.

It should evolve as MBSB's products, technologies, customer behaviours, suppliers, regulatory requirements and operating environment change.

From Understanding the Organisation to Identifying What Matters

 

Understanding MBSB establishes the foundation for the next stages of Operational Resilience.

The progression can be represented as:

The importance of this sequence is straightforward.

MBSB cannot meaningfully establish an impact tolerance until it knows what service the tolerance applies to.

It cannot adequately test the resilience of that service until it understands what the service depends upon.

And it cannot determine which services deserve priority until it understands the organisation, its customers and the consequences of disruption.

Understanding the organisation is the starting point for developing an effective Operational Resilience programme for MBSB Bank.

MBSB operates within a financial ecosystem characterised by growing digitalisation, interconnected payment and financial infrastructure, cyber threats, third-party dependencies and rising customer expectations for continuous access to financial services.

BNM's 2025 Discussion Paper makes clear that these conditions require financial institutions to move beyond an approach focused predominantly on preventing incidents and recovering individual systems.

Institutions increasingly need to understand which services are critical, how those services depend upon internal and external resources, how much disruption can be tolerated and whether they can remain within those tolerances during severe but plausible events.

For MBSB, existing capabilities in BCM, operational risk management, technology resilience, cybersecurity, crisis management and third-party risk provide an important foundation. Operational Resilience brings these capabilities together around a common organising principle: the continued delivery of Critical Business Services.

This service-oriented approach is also consistent with the broader organisational resilience principles of ISO 22316, which emphasise context, leadership, adaptability, coordinated capabilities and a culture that supports resilience.

The principal lesson from this chapter is therefore:

MBSB must first understand how the organisation delivers value before it can determine what must remain resilient.

Having established this organisational context, the subsequent chapters can progressively narrow the analysis from the organisation as a whole to the services that matter most.

This will ultimately enable MBSB to identify its Critical Business Services, understand their interconnections and interdependencies, establish appropriate impact tolerances and test whether those services can withstand severe but plausible disruption.

 

 

eBook 1: Understanding Your Organisation: MBSB Bank
C1 C2 C3 C4
C5 C6 C7 C8
 

For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

If you have any questions, click to contact us.