Operational Resilience cannot be developed in isolation from the environment in which an organisation operates.
For MBSB Bank (MBSB), its resilience requirements are influenced not only by its internal operations but also by Malaysia's financial system, customer expectations, regulatory requirements, technological developments, cyber threats, third-party dependencies, payment infrastructure and physical and environmental risks.
This operating environment is becoming increasingly complex. Bank Negara Malaysia's (BNM) 2025 Discussion Paper on Operational Resilience, issued on 19 December 2025, identifies rapid digitalisation, rising cyber threats, deeper third-party dependencies and increasing severity and frequency of operational disruptions as important factors driving the need for stronger resilience among Malaysian financial institutions.
BNM notes that sustaining the continuity of essential services under stress has become as important as maintaining adequate financial buffers as digital interdependencies deepen.
For MBSB, examining its operating environment therefore provides an essential bridge between understanding the organisation and determining which business services must be prioritised for Operational Resilience.
By understanding these factors, Metrobank can anticipate risks, respond effectively to disruptions, and integrate resilience into its operations.
The purpose of this chapter is to examine the internal and external operating environment of MBSB Bank and identify the conditions that could influence its ability to continue delivering important financial services during disruption.
The rationale for undertaking this analysis before identifying Critical Business Services (CBSs) is straightforward: MBSB cannot determine what must remain resilient without understanding the environment within which those services are delivered.
Digital banking, interconnected payment infrastructure, telecommunications, cyber threats, external service providers, changing customer expectations and physical disruptions can create dependencies and vulnerabilities extending well beyond the boundaries of individual departments, applications or facilities.
BNM's 2025 Discussion Paper reinforces this perspective by emphasising the need for financial institutions to understand critical services and their internal and external dependencies.
By the end of this chapter, the reader should be able to identify the principal characteristics of MBSB's operating environment, distinguish between internal and external factors affecting resilience, recognise emerging sources of operational vulnerability, and understand how these factors should influence the design of MBSB's Operational Resilience programme.
The reader should also appreciate how the examination of MBSB's environment supports BNM's emerging direction concerning critical services, dependency visibility, impact tolerances, severe but plausible scenario testing, governance and continuous improvement.
The chapter, therefore, provides the contextual analysis needed before MBSB progresses to identifying and prioritising its Critical Business Services.
Operational Resilience begins with the assumption that disruption will occur.
The objective is therefore not to design an organisation in which every disruption can be prevented. Rather, MBSB should develop sufficient capability to anticipate, withstand, respond to, recover from and learn from disruptions while continuing to deliver its most important services within acceptable limits.
BNM similarly observes that disruptions are becoming increasingly complex and inevitable. Prevention remains important, but it needs to be complemented by preparedness, adaptability and robust recovery capabilities.
The implication for MBSB is significant.
A disruption does not need to originate within MBSB to affect its customers.
For example:
Telecommunications Provider Failure
↓
Loss of Connectivity
↓
Digital Banking / ATM Connectivity Affected
↓
Customers Unable to Access Banking Services
↓
Payment or Cash Access Disrupted
↓
Customer and Business Impact
In this example, MBSB's core banking system could remain operational while the customer-facing service becomes unavailable.
Operational Resilience must therefore consider the entire operating ecosystem rather than only assets directly controlled by MBSB.
A practical assessment of MBSB's operating environment should consider two broad perspectives:
This consists of factors predominantly within MBSB's organisational boundary, including:
This consists of factors outside MBSB's immediate organisational control, including:
The distinction is useful for analysis, but Operational Resilience should not treat the two environments independently.
They are interconnected.
A weakness in an external provider can become an internal operational incident. Likewise, weaknesses in MBSB's internal processes may affect customers, counterparties and other participants in the financial ecosystem.
MBSB operates within a highly interconnected Malaysian financial ecosystem.
Its services may depend directly or indirectly on:
Customers
↓
MBSB Delivery Channels
↓
MBSB Applications and Infrastructure
↓
Telecommunications and Technology Providers
↓
Payment and Settlement Infrastructure
↓
Other Financial Institutions
↓
Beneficiaries and Counterparties
This interconnectedness creates efficiency and convenience, but it also creates the potential for disruptions to propagate.
BNM specifically notes that the financial system is tightly interconnected through payment networks, clearing and settlement infrastructure, shared telecommunications services, cloud ecosystems, fintech arrangements and API-driven platforms.
Growing dependence on cloud providers, outsourced operational and IT functions, fintech partners, data centres and telecommunications can create both concentration and systemic risks.
For MBSB, resilience, therefore, cannot be assessed solely by asking:
It must also ask:
One of the most significant characteristics of MBSB's operating environment is the growing dependence of banking services on technology.
Customers increasingly expect banking services to be accessible through digital channels and transactions to be completed quickly.
This creates multiple benefits but also introduces dependency chains.
BNM identifies mobile banking, digital onboarding, electronic Know-Your-Customer, QR payments, cloud-hosted financial applications, APIs and open financial architectures as examples of technologies reshaping financial services.
It also notes that these developments increase sensitivity to outages and create more complex dependencies and potential vulnerabilities across software supply chains and interfaces.
For MBSB, a customer transaction might depend upon:
Customer Device
↓
Internet / Mobile Network
↓
MBSB Digital Channel
↓
Authentication Service
↓
Application Infrastructure
↓
Core Banking
↓
Payment Processing
↓
External Financial Infrastructure
A disruption to any component can prevent completion of the transaction.
Consequently, the Operational Resilience programme should assess technology from an end-to-end service perspective, rather than considering individual applications independently.
Digitalisation has also changed customer expectations.
Customers increasingly expect immediate and continuous access to banking services.
BNM specifically highlights financial services affecting customers' ability to access their funds, including mobile and online banking and real-time payments. Interruptions can rapidly create customer dissatisfaction and potentially undermine trust and confidence, particularly where personal information or fraudulent activity is involved.
For MBSB, the impact of disruption should therefore be considered from the customer's perspective.
Questions should include:
These considerations subsequently become important when MBSB establishes Impact Tolerances for its Critical Business Services.
Cyber threats represent a major component of the operating environment for financial institutions.
BNM identifies sophisticated cyber threats, including AI-enabled exploits, ransomware, attacks targeting critical infrastructure, destructive malware, third-party attacks and supply-chain exploitation.
These incidents may impair systems for extended periods and require capabilities beyond traditional recovery measures.
For MBSB, cyber resilience and Operational Resilience should therefore be closely integrated.
A traditional cybersecurity perspective asks:
Operational Resilience adds:
For example, a ransomware scenario affecting core banking should not only test whether technology can be recovered.
MBSB should determine whether:
This transforms cyber incident testing from a technology recovery exercise into an end-to-end service resilience test.
MBSB's operating environment also includes organisations that provide critical technology, telecommunications, infrastructure and operational services.
Potential dependencies may include:
BNM highlights two particular challenges.
First, external dependency chains may be opaque, meaning that financial institutions have limited visibility into the supply chains supporting their providers.
Second, certain services may be concentrated among a small number of specialist providers, making rapid substitution difficult during disruption.
This creates an important principle for MBSB:
MBSB should therefore identify critical third parties when mapping its Critical Business Services and determine whether realistic alternatives exist.
A particularly important resilience concern is the existence of common dependencies.
Different MBSB services may appear independent while relying on the same underlying resource.
For example:
Digital Banking
ATM Services
Branch Transactions
Corporate Payments
↓
Common Core Banking Platform
A failure of that platform could simultaneously affect multiple customer channels.
Similarly:
Digital Banking
Customer Contact Centre
Branch Connectivity
↓
Common Telecommunications Provider
The existence of alternative channels therefore, does not necessarily provide resilience if those channels depend on the same underlying infrastructure.
BNM's discussion of shared infrastructure and concentration risk reinforces the importance of identifying these common points of dependency.
For MBSB, mapping should therefore identify not only dependencies, but also concentrations and single points of failure.
As a bank, MBSB participates in an ecosystem in which payments may involve multiple institutions and infrastructure providers.
A simplified transaction could involve:
MBSB Customer
↓
MBSB Channel
↓
MBSB Core Banking / Payment Processing
↓
External Payment Infrastructure
↓
Receiving Financial Institution
↓
Beneficiary
The successful completion of the customer's transaction therefore, depends on more than MBSB.
A disruption affecting payment networks, switching infrastructure, clearing or settlement could affect the service even where MBSB's internal systems remain operational.
BNM notes that Malaysia has experienced operational disruptions affecting mobile and online banking channels, payment systems, switching networks and ATMs.
These incidents demonstrate dependencies across internal systems, common industry infrastructure and third-party providers, as well as the importance of end-to-end operational visibility.
Such dependencies should consequently form part of MBSB's Critical Business Service mapping and scenario testing.
Operational Resilience should not become exclusively focused on technology and cyber risks.
Physical disruptions remain relevant.
BNM identifies climate-related physical risks such as:
Such events can affect physical infrastructure, data-centre operations, branch accessibility and logistics networks. BNM also notes that increasingly severe climate events and other high-impact, multi-layered outages can prolong disruptions across regions.
For MBSB, relevant scenarios could include:
Major Flood
↓
Branch / Office Inaccessibility
↓
Workforce Displacement
↓
Telecommunications and Utility Disruption
↓
Third-Party Logistics Disruption
↓
Multiple Customer Services Affected
The resilience assessment should therefore consider combinations of failures rather than assuming each disruption will occur independently.
People remain a critical component of MBSB's operating environment.
Even highly automated banking services require personnel to:
Operational Resilience should therefore identify:
A technology platform may be available but still fail to deliver the required service if essential personnel cannot operate, monitor or recover it.
BNM's 2025 Discussion Paper is particularly relevant to the examination of MBSB's operating environment because it establishes the emerging regulatory direction for strengthening Operational Resilience among Malaysian financial institutions.
The paper applies its discussion to financial institutions, including banking and Islamic banking institutions.
It is important to recognise that the publication is a Discussion Paper, rather than to present every concept within it as an already-finalised regulatory requirement.
BNM describes the document as setting out its emerging direction and key considerations and explicitly connects Operational Resilience with existing requirements issued by the Bank.
For MBSB, the practical direction emerging from the paper can be summarised as follows:
|
BNM Operational Resilience Direction |
Practical Application for MBSB |
|
Preserve continuity of critical operations and/or services |
Identify MBSB's Critical Business Services and prioritise their resilience |
|
Understand internal and external dependencies |
Map people, processes, technology, information, facilities, third parties and external infrastructure supporting each CBS |
|
Consider customer and stakeholder outcomes |
Assess disruption from the perspective of customer harm rather than only internal operational loss |
|
Move beyond MTD and RTO alone |
Establish service-level Impact Tolerances in addition to existing recovery objectives |
|
Use severe but plausible scenario testing |
Test CBSs against sufficiently severe scenarios, including concurrent failures |
|
Strengthen Board oversight |
Establish clear governance, accountability, challenge and reporting |
|
Use cross-functional arrangements |
Integrate business, Operational Risk, BCM, Technology, Cybersecurity, Third-Party Risk and Crisis Management |
|
Learn continuously from disruption |
Convert incidents, exercises and near misses into resilience improvements |
BNM's lessons from operational disruptions are particularly clear: financial institutions need to identify critical operations or services, understand dependencies, establish impact tolerances focused on internal and external outcomes, test severe but plausible scenarios, maintain strong Board oversight and systematically learn from disruption.
Operational Resilience should not be treated as an entirely separate regulatory programme.
For MBSB, existing BNM requirements and established risk disciplines provide much of the underlying capability needed to strengthen resilience.
These may include:
Provides Business Impact Analysis, continuity strategies, recovery arrangements, exercises and crisis preparedness.
Provides governance and controls supporting technology availability, cybersecurity and technology recovery. BNM issued its revised Risk Management in Technology policy document on 28 November 2025.
Provides the broader framework for identifying, assessing, monitoring and managing operational risks.
Supports assessment and oversight of dependencies arising from outsourcing and external service providers.
Provides escalation, command, coordination and decision-making mechanisms during significant disruption.
Operational Resilience should integrate these capabilities around the continued delivery of the Critical Business Service.
The objective is therefore not to create parallel arrangements for every resilience discipline, but to ensure existing capabilities collectively support service continuity.
The examination of MBSB's operating environment is also consistent with the principles of ISO 22316:2017 — Security and resilience — Organisational resilience — Principles and attributes.
ISO 22316 takes a broad organisational perspective on resilience. Applied to MBSB, this means resilience should not be viewed solely as an emergency response or technology recovery capability.
Instead, MBSB should develop the organisational capacity to understand and respond to change.
From an Operational Resilience perspective, this requires:
The alignment between these principles and BNM's emerging Operational Resilience direction is particularly useful for MBSB.
ISO 22316 provides the broader organisational resilience perspective, while BNM provides the financial-services context within which resilience should be operationalised.
Based on the considerations discussed above, an initial operating-environment assessment can be developed.
|
Operating Environment Factor |
Relevance to MBSB |
Potential OR Implication |
|
Digitalisation |
Increasing reliance on electronic banking and transaction channels |
Greater sensitivity to technology outages |
|
Customer Expectations |
Customers expect continuous and rapid access to banking services |
Customer harm may emerge quickly |
|
Cyber Threats |
Financial institutions remain attractive cyber targets |
Need to test service continuity following a successful cyberattack |
|
Core Technology Dependencies |
Multiple services may depend upon common platforms |
Potential concentration and single-point-of-failure risk |
|
Payment Infrastructure |
Banking transactions depend upon the external financial infrastructure |
MBSB cannot assess resilience solely within its organisational boundary |
|
Third Parties |
Technology and operational services may depend upon external providers |
Supplier resilience becomes part of MBSB's service resilience |
|
Telecommunications |
Digital channels and operational sites depend on connectivity |
Telecom outages could affect multiple services simultaneously |
|
Data and Information |
Banking requires accurate and available customer and transaction information |
Data integrity incidents may prevent safe service restoration |
|
Physical and Climate Risks |
Facilities, personnel and infrastructure may be affected by major events |
Scenario testing should include physical and regional disruptions |
|
People and Skills |
Critical operations depend upon specialist knowledge and decision-makers |
Key-person and workforce concentration risks should be identified |
|
Regulatory Environment |
BNM expectations continue to evolve |
The OR framework should be adaptable and evidence-based |
|
Financial-System Interconnection |
Services interact with counterparties and shared infrastructure |
Disruption may propagate beyond MBSB |
This assessment should be reviewed periodically because the operating environment will continue to change.
Examining the operating environment should ultimately influence how MBSB implements Operational Resilience.
The analysis can be translated through the following pathway:
Examine Operating Environment
↓
Identify Sources of Disruption
↓
Understand Customers and Stakeholders
↓
Identify Critical Business Services
↓
Map Interconnections and Interdependencies
↓
Identify Concentrations and Vulnerabilities
↓
Establish Impact Tolerances
↓
Develop Severe but Plausible Scenarios
↓
Test Resilience
↓
Remediate and Improve
This ensures that Operational Resilience is not implemented as a theoretical compliance framework.
It becomes a structured response to the actual conditions under which MBSB delivers financial services.
At the conclusion of the operating-environment assessment, MBSB should be able to answer several fundamental questions:
These questions provide the bridge from environmental understanding to Critical Business Service identification.
Examining MBSB Bank's operating environment demonstrates why Operational Resilience must extend beyond conventional organisational boundaries.
MBSB operates within an ecosystem of customers, employees, digital channels, technology platforms, telecommunications networks, payment infrastructure, third-party providers and other financial institutions. Disruption affecting any important element of this ecosystem can ultimately affect the financial service experienced by the customer.
BNM's 2025 Discussion Paper reinforces this perspective. Malaysia's experience with disruptions affecting mobile and online banking, payment systems, switching networks and ATMs illustrates the importance of understanding dependencies across internal systems, common infrastructure and third-party providers.
BNM consequently identifies critical-service continuity, deep dependency visibility, customer-oriented impact tolerances, severe but plausible scenario testing, strong Board oversight and continuous learning as important components of stronger Operational Resilience.
For MBSB, the principal lesson is:
The operating-environment assessment, therefore, provides the foundation for determining where MBSB should focus its resilience efforts.
Rather than attempting to make every activity equally resilient, MBSB should use this understanding to identify the services whose disruption could create the greatest consequences for customers, the bank and the wider financial ecosystem.
The next stage is therefore to move from the question:
to the more focused question:
Answering that question establishes the basis for identifying MBSB's Critical Business Services, which can then be mapped end-to-end, assigned Impact Tolerances and subjected to severe but plausible scenario testing as the Operational Resilience pro
| eBook 1: Understanding Your Organisation: MBSB Bank | |||
| C1 | C2 | C3 | C4 |
| C5 | C6 | C7 | C8 |
For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.
To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.
|
If you have any questions, click to contact us. |
||
|
|