CBS-7 Digital and Online Banking Services
In the context of operational resilience, severe but plausible scenarios test the ability of Metrobank’s Digital and Online Banking Services to remain within established impact tolerances under disruptive conditions.
These scenarios are designed to represent realistic but extreme situations—ones that could significantly affect customer access, service availability, and data integrity. Considering the digital nature of these services, the integration of Cyber and ICT risks is a critical factor in designing effective resilience strategies.
The table below outlines the recommended severe but plausible scenarios for each Sub-CBS of CBS-7 Digital and Online Banking Services, including the corresponding proactive risk management actions and how each links to Cyber and ICT risk management integration.
Table P5: Identify Severe but Plausible Scenarios for CBS-7
|
Sub-CBS Code |
Sub-CBS |
Impact/Effect |
Severe but Plausible Scenario |
Proactive Risk Management Action |
Link to Integration of Cyber and ICT Risks |
|
7.1 |
Online Banking Platform Management |
Major service downtime, customer dissatisfaction, and reputational damage |
Extended unavailability of the online banking platform due to a cloud service provider outage |
Implement multi-cloud redundancy and continuous availability testing |
Aligned with ICT infrastructure redundancy and supplier cyber resilience requirements |
|
7.2 |
Mobile Banking Application Services |
Customer access disruption, transaction delays |
Critical vulnerability exploited in a mobile app, resulting in a data breach or unauthorized transactions |
Conduct secure code reviews, regular penetration testing, and app hardening |
Integration with the mobile app security lifecycle and vulnerability management |
|
7.3 |
Digital Account Access and Authentication |
Customer lockouts, unauthorized access |
Credential stuffing or phishing campaign compromising a large user base |
Implement adaptive authentication and behavioral biometrics |
Integrated with cyber threat intelligence and identity access management (IAM) controls |
|
7.4 |
Online Funds Transfer and Payment Processing |
Financial loss, regulatory breach |
Compromise of the payment gateway leading to unauthorized fund transfers |
Enforce transaction anomaly detection and out-of-band verification |
Integration with payment system, cybersecurity, and fraud analytics systems |
|
7.5 |
Digital Customer Onboarding and e-KYC |
Regulatory non-compliance, identity theft |
Large-scale e-KYC system failure due to third-party API compromise |
Diversify onboarding verification vendors and ensure API isolation |
Integrated with third-party risk and data integrity management frameworks |
|
7.6 |
Digital Customer Support and Service Channels |
Inability to serve customers, reputational harm |
Chatbot and call centre systems taken offline due to a DDoS attack |
Implement DDoS protection, load balancing, and alternate contact channels |
Linked to ICT network security and incident management frameworks |
|
7.7 |
Card-Not-Present (CNP) and e-Commerce Transaction Processing |
Fraud escalation, financial loss |
Surge in fraudulent e-commerce transactions from a major merchant breach |
Deploy AI-driven fraud detection and merchant risk scoring |
Integrated with enterprise fraud monitoring and PCI DSS compliance controls |
|
7.8 |
ATM and Electronic Channel Management |
Service disruption, public trust erosion |
Malware infection spreading through the ATM network |
Deploy endpoint protection and network segmentation for ATMs |
Integration with endpoint security and physical channel protection policies |
|
7.9 |
Cybersecurity and Fraud Monitoring for Digital Channels |
Undetected breaches, financial loss |
Simultaneous cyberattack (ransomware and phishing) is overwhelming the SOC capacity |
Implement cyber incident playbooks and automated threat containment |
Fully aligned with Cyber and ICT resilience testing and SOC automation |
|
7.10 |
Digital Banking Data Management and Reporting |
Data corruption, loss of regulatory confidence |
Data integrity breach due to insider manipulation or ransomware encryption |
Regular data validation, encryption, and immutable backup implementation |
Integration with ICT data governance, backup, and recovery frameworks |
Through identifying and analyzing severe but plausible scenarios, Metrobank enhances its capacity to prepare for complex digital disruptions.
Each scenario reflects a balance between realism and severity, ensuring resilience testing aligns with actual cyber and ICT vulnerabilities.
By integrating cyber risk management into every Sub-CBS, Metrobank fortifies its Digital and Online Banking Services against evolving threats, thereby maintaining operational continuity and customer trust even under adverse conditions.
Gain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.




![Banner [Table] [OR] [E3] Identify Severe but Plausible Scenarios](https://no-cache.hubspot.com/cta/default/3893111/f4f3c007-e864-48cd-8bc1-0242c8b7fd86.png)
![Banner [Summing] [OR] [E3] Identify Severe but Plausible Scenarios](https://no-cache.hubspot.com/cta/default/3893111/446ccb83-e056-40d0-aae5-834d73c13f43.png)
![[OR] [MBT] [E3] [CBS] [7] [DP] Digital and Online Banking Services](https://no-cache.hubspot.com/cta/default/3893111/c47a4937-4109-4d28-9d0c-f7bc2461ba12.png)
![[OR] [MBT] [E3] [CBS] [7] [MD] Map Dependency](https://no-cache.hubspot.com/cta/default/3893111/9db4d0f4-354c-4fc8-b69d-808fea4879be.png)
![[OR] [MBT] [E3] [CBS] [7] [MPR] Map Processes and Resources](https://no-cache.hubspot.com/cta/default/3893111/0f03bf16-72a7-4d33-bf0a-03b28ed71a47.png)
![[OR] [MBT] [E3] [CBS] [7] [ITo] Establish Impact Tolerances](https://no-cache.hubspot.com/cta/default/3893111/6f245a6c-acf7-4aee-bf23-31eafc8e55ae.png)
![[OR] [MBT] [E3] [CBS] [7] [ST] Perform Scenario Testing](https://no-cache.hubspot.com/cta/default/3893111/7c904ed5-8d88-498a-b94e-32c80918f743.png)





![[BL-OR] [3-4-5] View Schedule](https://no-cache.hubspot.com/cta/default/3893111/d0d733a1-16c0-4b68-a26d-adbfd4fc6069.png)
![[BL-OR] [3] FAQ OR-300](https://no-cache.hubspot.com/cta/default/3893111/f20c71b4-f5e8-4aa5-8056-c374ca33a091.png)
![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)








