. .
Building Organisational Resilience: An Operational Resilience Guide for Malaysian Life Reinsurance
OR BB FI MY Gen-8

[OR] [MLRE] [E3] [CBS] [2] [SuPS] Identify Severe but Plausible Scenarios

MLRE Logo

The organisation discussed in this chapter is Malaysian Life Reinsurance (MLRe), a licensed professional reinsurer operating within Malaysia’s financial services sector and subject to the supervisory expectations of Bank Negara Malaysia (BNM).

In line with BNM’s 2025 Discussion Paper on Operational Resilience and the principles outlined in the BCM Institute blog “[OR] [P2-S4] What is Severe but Plausible Scenarios in Operational Resilience,” severe but plausible scenarios are those that are extreme in impact yet realistic enough to occur within the operating environment.

New call-to-action

Moh Heng Goh
Operational Resilience Certified Planner-Specialist-Expert

x [OR] [MLRE] Legal Disclaimer Banner

New call-to-actionCBS-2 Claims Processing & Settlement

Introduction

[OR] [MLRE] [E3] [CBS] [2] [SuPS] Identify Severe but Plausible Scenarios

The organisation discussed in this chapter is Malaysian Life Reinsurance (MLRe), a licensed professional reinsurer operating within Malaysia’s financial services sector and subject to the supervisory expectations of Bank Negara Malaysia (BNM).

In line with BNM’s 2025 Discussion Paper on Operational Resilience and the principles outlined in the BCM Institute blog “[OR] [P2-S4] What is Severe but Plausible Scenarios in Operational Resilience,” severe but plausible scenarios are those that are extreme in impact yet realistic enough to occur within the operating environment.

For Critical Business Service (CBS-2) Claims Processing & Settlement, the identification of severe but plausible scenarios ensures that MLRe can continue to honour reinsurance claims obligations within defined impact tolerances, even under cyber, ICT, third-party, or operational disruptions.

Banner [Table] [OR] [E3] Identify Severe but Plausible Scenarios

Table P5: Identify Severe but Plausible Scenarios for CBS-2  

Sub-CBS Code

Sub-CBS

Severe but Plausible Scenario

Impact / Effect

Proactive Risk Management Action (Evidence)

Link to Integration of Cyber & ICT Risk

2.1

Claim Notification & Receipt

Distributed Denial-of-Service (DDoS) attack on the claims submission portal during a catastrophe event

Inability of cedants to notify claims within the required timeframe; backlog accumulation

Redundant submission channels (secure email, SWIFT, hotline); DDoS mitigation service; tested surge procedures

Cyber attack resilience, network monitoring, SOC alerts, and ICT capacity stress testing

2.2

Document & Data Verification

Ransomware encrypts the document management system

Inaccessibility of claim documents; delay in verification; potential data breach

Immutable backups; endpoint detection & response (EDR); offline recovery testing; cyber playbooks

Backup resilience, privileged access management (PAM), and ransomware response integration

2.3

Preliminary Assessment & Triage

Sudden 300% spike in claims due to regional pandemic or natural catastrophe

Triage bottlenecks; breach of service level agreements (SLAs)

Pre-defined catastrophe surge plan; cross-trained staff; automated triage rules engine

ICT scalability testing, cloud auto-scaling, stress-testing against peak load

2.4

Detailed Claims Assessment

Core claims assessment system outage due to data centre failure

Suspension of assessment activities; impact tolerance breach

Active-active data centre setup; disaster recovery (DR) site with tested RTO/RPO

DR testing aligned to impact tolerance; ICT resilience metrics reporting

2.5

Third-Party Engagement & Investigation

External loss adjuster suffers a cyber breach compromising shared claim data

Confidentiality breach; reputational damage; regulatory reporting requirement

Third-party cyber due diligence; contractual security clauses; secure file transfer protocols

Third-party ICT risk assessment; vendor monitoring; integration into enterprise cyber risk register

2.6

Claims Decisioning & Approval

Internal fraud or manipulation of the approval workflow via compromised credentials

Financial loss; regulatory sanction; erosion of trust

Segregation of duties (SoD); multi-factor authentication (MFA); transaction monitoring

Identity & access management controls; insider threat detection analytics

2.7

Settlement Calculation & Fund Disbursement

Payment system outage or SWIFT connectivity disruption

Delayed settlement to cedants; liquidity strain; contractual penalties

Alternative payment channel; liquidity buffer; payment contingency playbook

Payment system cyber resilience; integration with treasury ICT continuity plans

2.8

Claim Communication & Reporting

Email server compromise leading to phishing or misinformation to cedants

Misinformation; reputational damage; possible financial fraud

Secure email gateway; DMARC/SPF controls; communication verification protocol

Email security controls, cyber awareness training, and incident escalation integration

2.9

Record Archival & Compliance Reporting

Data corruption was discovered in archival storage due to a silent system failure

Inaccurate regulatory reporting; audit qualification risk

Periodic data integrity checks; hash validation; independent audit review

Data integrity monitoring; ICT governance & audit alignment

2.10

Continuous Improvement & Analytics

Manipulation or corruption of analytics data affecting reserving insights

Poor decision-making; mispricing risk exposure

Data governance framework, role-based access, model validation process

ICT data governance, AI/model risk management, cyber monitoring of analytics platforms

 Banner [Summing] [OR] [E3] Identify Severe but Plausible Scenarios

The identification of severe but plausible scenarios for CBS-2 Claims Processing & Settlement enables Malaysian Life Reinsurance to test the resilience of its claims value chain against extreme but credible disruptions.

These scenarios extend beyond traditional disaster recovery considerations to include cyber-attacks, ICT system failures, third-party vulnerabilities, fraud, and surge events — consistent with supervisory expectations articulated by Bank Negara Malaysia.

By linking each Sub-CBS to integrated cyber and ICT risk controls, MLRe demonstrates proactive operational resilience management — ensuring that even under severe stress, the organisation can remain within defined impact tolerances, protect cedant confidence, and maintain financial stability.

 

Building Organisational Resilience: An Operational Resilience Guide for Malaysian Life Reinsurance

eBook 3: Starting Your OR Implementation
CBS-2 Claims Processing & Settlement
CBS-2 DP CBS-2 MD CBS-2 MPR CBS-2 ITo CBS-2 SuPS CBS-2 ST
[OR] [MLRE] [E3] [CBS] [2] [DP] Claims Processing & Settlement [OR] [MLRE] [E3] [CBS] [2] [MD] Map Dependency [OR] [MLRE] [E3] [CBS] [2] [MPR] Map Processes and Resources [OR] [MLRE] [E3] [CBS] [2] [ITo] Establish Impact Tolerances [OR] [MLRE] [E3] [CBS] [2] [SuPS] Identify Severe but Plausible Scenarios [OR] [MLRE] [E3] [CBS] [2] [ST] Perform Scenario Testing

New call-to-actionNew call-to-action

For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the OR-300 Operational Resilience Implementer course and the OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Comments:

 

CTA Banner_OR

CTA Banner_ORA

CTA Banner_BCM

CTA Banner_ITDR

CTA Banner_CM