BDCB conducts monetary policy, issues and manages Brunei currency, regulates and supervises banks and other financial institutions, supports financial-system stability, and assists in establishing and overseeing efficient payment systems.
The technological crisis exposure of BDCB, therefore, extends considerably beyond an ordinary internal IT outage.
A severe technology incident could affect BDCB's own operations while simultaneously disrupting payment and settlement infrastructure, supervisory activities, access to financial information, communications with regulated institutions, currency-related operations, and confidence in the wider financial system.
This chapter examines the principal technological crisis scenarios that could affect BDCB, how such events could escalate from technology incidents into enterprise or potentially systemic crises, and the crisis-management capabilities required to manage them.
A technological crisis is a serious situation arising from the failure, compromise, corruption, unavailability, or misuse of technology or supporting infrastructure where the consequences exceed the ability of routine technical incident-management arrangements to manage the situation effectively.
A technological event does not automatically constitute a crisis. An application failure that is quickly restored by the IT team may remain an operational incident.
The situation becomes a crisis when its severity, duration, uncertainty, interconnected consequences, or stakeholder impact requires coordinated strategic decisions by senior management.
For BDCB, the distinction can be understood as:
Technology Event
Technical Incident
Major Technology Disruption
Critical Functions Affected
Financial-Sector or Stakeholder Impact
Senior Management Intervention Required
Technological Crisis
The critical issue is therefore not simply whether technology has failed, but what the technology failure prevents BDCB and the financial system from doing.
BDCB occupies a particularly important position because it is simultaneously a central bank, financial-sector regulator, and operator of important national financial infrastructure.
BDCB operates Brunei Darussalam's National Payment and Settlement Systems (NPSS), comprising the Real-Time Gross Settlement (RTGS), Automated Clearing House (ACH), and Central Securities Depository (CSD) systems.
RTGS processes large-value and urgent interbank payments in real time; ACH supports bulk clearing, including direct credit transfers; and CSD supports securities-related activities.
BDCB itself describes RTGS as the heart of a modern national payment system and notes that a systemically important payment system needs to remain reliable, robust, and resilient, including during market crises.
Consequently, technological resilience at BDCB has several dimensions:
Institutional Technology Resilience — protecting BDCB's own systems, applications, information, and communications.
Financial Infrastructure Resilience — maintaining critical payment, settlement, and securities infrastructure.
Supervisory Resilience — maintaining BDCB's ability to oversee financial institutions and respond to sector-wide problems.
Information Resilience — preserving the confidentiality, integrity, and availability of regulatory, financial, and operational information.
Systemic Resilience — preventing a technological disruption from contributing to instability or loss of confidence in Brunei Darussalam's financial system.
For crisis planning purposes, BDCB should consider technological crises as a family of scenarios rather than a single "IT outage" scenario.
A major ICT infrastructure failure may involve:
The immediate consequence may be loss of access to applications and data. However, the crisis-management significance depends on which business activities rely on the affected infrastructure.
A widespread infrastructure failure could prevent employees from accessing critical systems, delay management decisions, restrict communications with financial institutions, interrupt supervisory activities, and affect financial infrastructure.
The crisis may become particularly serious where there is no immediately available alternative processing capability.
Cyberattacks represent one of the most significant forms of technological crisis because it introduces both disruption and uncertainty.
Unlike a straightforward hardware failure, management may initially be unable to determine:
Potential attacks include:
BDCB's regulatory framework itself recognises the increasing importance of technology and cybersecurity risk.
Its published regulations include technology-risk-management requirements, IT third-party risk guidance and requirements concerning early detection of cyber intrusion and incident reporting.
A sophisticated threat actor compromises BDCB's technology environment. Several critical systems become unavailable while forensic teams discover indications that sensitive information may also have been accessed.
Management must simultaneously determine:
This is no longer simply a cybersecurity incident. It is a strategic crisis involving technology, operations, information security, financial-sector stakeholders, reputation and potentially financial stability.
Ransomware deserves consideration as a specific crisis scenario because modern attacks can combine several consequences simultaneously:
For BDCB, a severe ransomware attack could create a difficult management dilemma.
Restoring systems quickly may conflict with the need to preserve forensic evidence and ensure that compromised systems are safe. At the same time, prolonged isolation of technology could interfere with important central-bank functions.
The crisis-management team would need to coordinate closely with:
Cyber incident response and crisis management should therefore be connected but not confused. Technical teams contain and eradicate the attack; the crisis-management structure manages the enterprise consequences and strategic decisions arising from it.
This represents a particularly important BDCB-specific technological scenario.
BDCB operates RTGS, ACH, and CSD. RTGS facilitates large-value and urgent payments between banks, with interbank payments settled using funds held in Brunei Dollar settlement accounts at BDCB.
ACH supports bulk clearing, while CSD supports electronic securities records and settlement-related activities.
A prolonged disruption could therefore have consequences extending well beyond BDCB's internal operations.
A payment-system technological crisis could result from:
Depending on severity and timing, consequences could include:
Because ACH settlement ultimately interfaces with RTGS, dependencies between systems are important when analysing technological crisis scenarios. BDCB
The crisis-management question, therefore, becomes:
Is this an isolated system outage, or is the outage beginning to affect the functioning and confidence of the wider financial system?
Technology does not have to become unavailable to create a crisis.
A potentially more difficult situation occurs when systems remain operational, but management cannot determine whether the information within them is accurate.
Examples include:
This introduces a fundamental distinction between:
System Availability — Can BDCB access and operate the system?
and
System Integrity — Can BDCB trust the information and transactions produced by the system?
A system that is available but producing unreliable information may be more dangerous than one that is visibly unavailable.
For crisis management, this could require BDCB to suspend certain activities voluntarily until data integrity can be established.
BDCB handles information that may be confidential, sensitive, or significant to financial-sector supervision and central-bank activities.
A technological compromise could result in unauthorised disclosure of:
The crisis may intensify where stolen information is:
The organisation then faces two simultaneous problems:
Information-Security Incident and Crisis of Stakeholder Confidence.
The response must therefore address not only technical containment but also legal implications, stakeholder notification, information verification, communications and reputation management.
Central-bank operations depend heavily on connectivity.
A major telecommunications disruption could affect:
A telecommunications crisis becomes particularly significant where apparently independent systems share a common network dependency.
This highlights an important crisis-planning principle:
Multiple applications may appear resilient individually while remaining vulnerable to a single shared technology dependency.
BDCB should therefore assess technology crises based on end-to-end service dependencies, rather than individual systems alone.
Loss of a primary data centre or critical technology facility could result from:
The existence of a disaster-recovery facility does not automatically eliminate the crisis.
A severe event may reveal problems such as:
The crisis-management team should therefore focus not merely on whether DR has been invoked, but whether critical business outcomes can actually be delivered from the recovery environment.
Not all technological crises originate from malicious activity or infrastructure breakdown.
A routine technology change can itself trigger a severe crisis.
Examples include:
The danger is increased when changes affect highly interconnected infrastructure.
A change-management failure could progress from:
Technology Change
Unexpected Failure
Multiple Systems Affected
Rollback Unsuccessful
Critical Service Disruption
Financial Institutions Affected
Crisis Management Activation
For BDCB, major changes affecting critical national financial infrastructure should therefore be included in severe-but-plausible scenario exercises.
BDCB's technological resilience can also depend on organisations outside its direct control.
Potential dependencies could include providers of:
BDCB's own regulatory materials recognise IT third-party risk as a distinct technology-risk consideration. BDCB
A third-party crisis becomes particularly difficult because BDCB may have limited direct control over restoration.
Management may need to determine:
Technology resilience also depends on non-IT infrastructure.
A prolonged power disruption may eventually exhaust:
The scenario becomes more severe where the same infrastructure disruption affects:
Crisis planning should therefore avoid treating power, telecommunications, facilities, and ICT as independent risks.
Not every technological crisis involves complete system failure.
Systems may remain technically available but become unusable because of extreme demand.
Potential causes include:
This is especially relevant to financial infrastructure because severe market or public events may create peak demand precisely when technology is already under stress.
Capacity testing should therefore form part of technology resilience and crisis preparedness.
As financial-sector technology evolves, BDCB should also consider emerging technological risks.
Potential scenarios include:
A particularly relevant crisis scenario would involve a convincing deepfake purporting to show a senior BDCB official making a sensitive announcement.
Although technically originating from malicious technology, the resulting crisis could rapidly become one of misinformation, reputation, and financial confidence.
The most severe BDCB technology crisis is unlikely to remain purely technological.
For example, a cyberattack could simultaneously create:
Technology Impact — systems unavailable.
Operational Impact — critical activities cannot be performed normally.
Information Impact — integrity or confidentiality becomes uncertain.
Financial Infrastructure Impact — payment or settlement activity may be disrupted.
Regulatory Impact — supervision and communication with institutions may be constrained.
Stakeholder Impact — financial institutions require guidance and information.
Reputational Impact — media and public attention increase.
Financial-Stability Impact — prolonged or widespread disruption could raise broader concerns.
This interconnection is what transforms a technology incident into a crisis.
|
Scenario |
Illustrative Event |
Potential Crisis Consequence |
|
TC-01 Cyberattack |
Advanced threat actor compromises BDCB systems |
Loss of systems, data, or confidence |
|
TC-02 Ransomware |
Systems, encrypted, and confidential data were stolen |
Operational disruption, extortion, and reputational impact |
|
TC-03 RTGS Disruption |
RTGS is unavailable for an extended period |
Large-value interbank settlement disruption |
|
TC-04 ACH Disruption |
Clearing service becomes unavailable |
Bulk payment and clearing delays |
|
TC-05 CSD Disruption |
Securities records or settlement capability unavailable |
Securities-related operational disruption |
|
TC-06 Data Corruption |
Critical records become unreliable |
Decisions or transactions cannot safely proceed |
|
TC-07 Data Breach |
Sensitive information exfiltrated |
Confidentiality, legal, and reputation consequences |
|
TC-08 Data Centre Failure |
Primary processing environment unavailable |
Multiple critical systems were affected |
|
TC-09 Telecommunications Failure |
Network connectivity lost |
BDCB and financial institutions cannot communicate normally |
|
TC-10 Failed Technology Change |
Upgrade causes widespread system failure |
Multiple interconnected services were disrupted |
|
TC-11 Third-Party Failure |
Critical technology supplier becomes unavailable |
Service restoration is dependent on the external provider |
|
TC-12 Power Infrastructure Failure |
Prolonged utility disruption |
Technology and facility availability affected |
|
TC-13 Capacity Failure |
Transaction demand exceeds system capability |
Severe degradation or service unavailability |
|
TC-14 Credential Compromise |
Privileged account compromised |
Unauthorised access to critical systems |
|
TC-15 Emerging Technology Crisis |
AI/deepfake or new technology creates severe consequences |
Fraud, misinformation or confidence impact |
A practical escalation decision should consider several dimensions.
A technological incident should be considered for crisis escalation when one or more of the following occur:
The trigger should therefore be based on business and systemic consequences, not simply technical severity classifications.
When the BDCB Crisis Management Team is activated for a technological crisis, its priorities should differ from those of the technical response team.
The Crisis Management Team should determine:
Crisis Management, Business Continuity, Cyber Incident Response, and IT Disaster Recovery should operate as connected capabilities.
Cyber / Technology Incident Management addresses the technical cause.
IT Disaster Recovery restores technology.
Business Continuity Management maintains priority business activities while technology is unavailable.
Crisis Communication manages information provided to internal and external stakeholders.
Crisis Management integrates these activities and provides strategic direction.
None should operate independently during a major technological crisis.
For BDCB, the desired relationship is:
Technological Disruption
Technical Containment
Business Continuity Activation
Technology Recovery
Strategic Crisis Coordination
Stakeholder Communication
Service Stabilisation
Return to Normal Operations
Post-Crisis Improvement
BDCB should test technological crises using scenarios that are severe enough to challenge normal assumptions.
Examples could include:
Exercises should test not only whether systems can technically recover, but whether BDCB can continue fulfilling its central-bank responsibilities while managing uncertainty, stakeholder pressure, and potentially cascading consequences.
The central crisis-management concern can be summarised as:
Technological Crisis — Cyberattack
Critical Systems Become Unavailable
Operational Disruption
Rumours of Financial System Problems
Media and Public Concern
Potential Confidence Impact
Strategic Crisis
This progression demonstrates why technological crisis management cannot remain solely an ICT responsibility.
The first stages may require predominantly technical expertise. As consequences spread, responsibility progressively expands to business functions, communications, senior management, financial-sector stakeholders, and potentially national-level coordination.
For BDCB, technological resilience should ultimately be evaluated by asking:
Can BDCB continue to fulfil its critical central-bank responsibilities safely and credibly when the technology on which those responsibilities depend is severely disrupted or cannot be trusted?
This is a more meaningful question than simply asking whether individual applications have disaster-recovery arrangements.
Technology recovery is an enabler. The ultimate objective is the continuity and recovery of BDCB's critical functions and the protection of financial system stability.
A technological crisis affecting the Brunei Darussalam Central Bank can originate from a cyberattack, ransomware, infrastructure failure, payment-system disruption, data corruption, data breach, telecommunications failure, data-centre loss, failed technology change, third-party failure, power disruption, capacity problems, or emerging technologies.
BDCB's position makes these scenarios particularly significant. It operates the country's RTGS, ACH, and CSD infrastructure and has responsibilities for monetary policy, currency, financial-sector supervision, financial stability, and payment-system oversight.
The principal crisis-management concern is therefore cascading impact.
A technical failure may begin within one system but subsequently affect business operations, financial institutions, payment and settlement activity, information integrity, stakeholders, reputation, and public confidence.
BDCB's crisis-management framework should consequently prepare for the progression from:
Technology Incident
Critical Service Disruption
Cross-Functional Impact
Financial-Sector Impact
Stakeholder and Public Concern
Strategic Crisis
Effective preparedness requires BDCB to integrate technology risk management, cybersecurity, IT disaster recovery, business continuity, crisis communication, and strategic crisis management into a coordinated response capability.
The objective is not merely to restore technology. It is to ensure that during a severe technological disruption, BDCB can make informed strategic decisions, maintain critical central-bank functions, coordinate the financial-sector response, communicate credibly, and protect confidence in Brunei Darussalam's financial system.
| eBook 1: Understanding Your Organisation | ||||||
| C1 | C2 | C3 | C4 | C5 [x] | C5A | C6 [x] |
| C7 [x] | C8 [x] | C9 [x] | C10 [x] | C11 [x] | C12 [x] | C13 [x] |
To learn more about the course and schedule, click the buttons below for the CM-300 Crisis Management Implementer [CM-3] and the CM-5000 Crisis Management Expert Implementer [CM-5].
|
Please feel free to send us a note if you have any questions. |
||