Part 2: Crisis Response Strategy for Brunei Darussalam Central Bank
Introduction
CMS Part 2 — Crisis Response Strategy for Brunei Darussalam Central Bank (BDCB) builds on the threats and crisis scenarios identified through the Crisis Risk Assessment and the preventive measures established in CMS Part 1 — Crisis Prevention Strategy.
Its purpose is to determine the strategic posture BDCB should adopt when preventive controls fail to prevent an incident from developing into a crisis.
The BCM Institute's Guidance Notes to Complete the Crisis Management (CM) Strategy identify four broad crisis-response strategies: Do Nothing, Stonewall, Respond and Defend, and Take the Offensive.
It states that the immediate objective of crisis management should include rapid resolution, defusing the crisis, and preserving organisational integrity and credibility.
CST2 also requires explaining and justifying the selected strategy, including consideration of financial and reputational consequences.
For this BDCB case study, these four terms are interpreted as follows:
|
CST2 Response Strategy |
Application in this BDCB Guide |
|
Do Nothing |
Deliberately take no external strategic action beyond monitoring or routine management because intervention could be unnecessary or counterproductive. This is an active decision, not neglect. |
|
Stonewall |
Withhold, restrict or defer information or engagement where disclosure would be inappropriate because facts are unverified, information is protected, investigations are active, or security/legal considerations apply. |
|
Respond and Defend |
Actively manage the crisis, protect people and operations, establish facts, correct misinformation, explain BDCB's position and demonstrate appropriate action. |
|
Take the Offensive |
Act proactively to shape the situation rather than merely reacting—for example through decisive intervention, authoritative communication, enforcement, coordinated sector action or proactive stakeholder engagement. |
The strategy selected should not be mechanically determined by the crisis category. It should reflect the facts, severity, stakeholder expectations, legal constraints, information available and potential consequences.
This is especially important for BDCB because its responsibilities include monetary policy, currency issuance and management, supervision of financial institutions, financial-system stability and efficient payment systems.
BDCB also operates Brunei Darussalam's RTGS, ACH and CSD systems.
The strategies below are illustrative recommendations for the case study, rather than statements of BDCB's existing approved crisis-response arrangements.
Natural Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Natural |
Flood |
Significant flooding restricts access to BDCB premises and affects employees, utilities, telecommunications or supporting infrastructure. |
Respond and Defend |
Protect life; assess premises; activate alternate working arrangements; maintain critical functions; coordinate with authorities; communicate operational status. |
Active response is necessary to protect people and maintain central-bank operations. |
Escalate if critical functions or financial institutions are affected. |
|
Natural |
Flash Flood |
Rapid flooding suddenly makes premises or access routes unsafe. |
Respond and Defend |
Evacuate or shelter as appropriate; account for personnel; suspend unsafe access; activate alternate arrangements. |
Speed and life safety outweigh attempts to maintain normal workplace arrangements. |
Early CMT activation may be required where access deteriorates rapidly. |
|
Natural |
Severe Rain / Thunderstorm |
Severe weather causes transport, utility, telecommunications and workforce disruption. |
Respond and Defend |
Monitor conditions; restrict travel; activate remote work; protect facilities and maintain essential staffing. |
Limits personnel exposure while sustaining priority operations. |
Manage initially as an incident unless impacts escalate. |
|
Natural |
Lightning |
Lightning damages power, communications or technology infrastructure. |
Respond and Defend |
Protect personnel; isolate damaged infrastructure; assess technology impact; activate recovery arrangements. |
Requires active technical and operational intervention. |
Link with technology and facilities response. |
|
Natural |
Strong Wind / Windstorm |
High winds damage buildings or infrastructure and make travel unsafe. |
Respond and Defend |
Restrict access; protect personnel; assess damage; maintain essential functions remotely or from alternate facilities. |
Necessary to minimise safety and operational consequences. |
Consider secondary power and telecommunications failures. |
|
Natural |
Tropical Storm / Severe Weather System |
Widespread severe weather simultaneously affects premises, transport, workforce and utilities. |
Respond and Defend |
Activate severe-weather arrangements; prioritise critical functions; coordinate with authorities and suppliers; communicate with stakeholders. |
Multi-dimensional disruption requires coordinated management. |
Consider early CMT activation. |
|
Natural |
Haze / Poor Air Quality |
Air quality becomes unsafe for normal working arrangements. |
Respond and Defend |
Reduce on-site staffing; protect vulnerable employees; implement remote work; communicate health guidance. |
Employee health must be protected while essential operations continue. |
Escalation depends on duration and severity. |
|
Natural |
Earthquake / Regional Seismic Event |
Tremors create uncertainty over building safety and supporting infrastructure. |
Respond and Defend |
Evacuate where necessary; conduct structural inspection; account for personnel; assess infrastructure dependencies. |
Uncertainty over structural safety requires precautionary action. |
Do not reoccupy affected facilities until appropriately assessed. |
|
Natural |
Infectious Disease Outbreak |
Significant illness reduces employee availability and affects workplace operations. |
Respond and Defend |
Implement health measures; remote work; workforce segregation; prioritise essential activities and monitor staffing. |
Protects employees while sustaining critical central-bank capabilities. |
Coordinate with national health guidance. |
|
Natural |
Pandemic |
Widespread disease affects BDCB, financial institutions, government agencies and suppliers simultaneously. |
Take the Offensive |
Proactively activate pandemic governance; prioritise critical services; implement workforce measures; coordinate with financial institutions and relevant authorities; communicate early. |
Waiting for severe disruption could allow simultaneous dependencies to deteriorate. |
Requires strategic rather than solely HR or BCM management. |
Technological Crisis
Technology crises warrant particularly rapid escalation where payment infrastructure is involved.
BDCB operates the NPSS comprising RTGS, ACH and CSD; ACH obligations are submitted to RTGS for settlement, demonstrating an important interdependency.
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Technological |
Hardware Failure |
Critical hardware fails and disrupts important systems or services. |
Respond and Defend |
Isolate failed components; fail over to redundant infrastructure; restore service; assess downstream impact. |
Prompt restoration limits operational consequences. |
Escalate based on criticality and duration. |
|
Technological |
Application Failure |
A critical application becomes unavailable or produces unreliable results. |
Respond and Defend |
Stop unsafe processing; assess integrity; invoke fallback or rollback; restore controlled service. |
Availability should not be restored at the expense of data integrity. |
Confirm integrity before full resumption. |
|
Technological |
Network Failure |
BDCB loses internal, external or participant connectivity. |
Respond and Defend |
Fail over communications; isolate faults; prioritise critical traffic; engage providers. |
Network dependency can rapidly create multi-system impact. |
Assess financial-institution connectivity. |
|
Technological |
Telecommunications Failure |
Communications with staff, institutions or external parties are interrupted. |
Respond and Defend |
Activate alternative channels and carrier arrangements; prioritise critical communications. |
Communication is essential during crisis coordination. |
Consider out-of-band channels. |
|
Technological |
Major Cyberattack |
Malicious activity compromises critical systems, networks or information. |
Take the Offensive |
Contain affected systems; mobilise cyber and crisis teams; protect unaffected environments; investigate attack vectors; coordinate stakeholders; communicate authoritative facts. |
A passive approach could allow compromise to spread and increase operational and confidence impacts. |
Cyber containment and crisis communication must be coordinated. |
|
Technological |
Ransomware |
Systems are encrypted and/or data is stolen with an extortion demand. |
Take the Offensive |
Isolate affected environments; activate cyber response; protect backups; assess exfiltration; initiate recovery; coordinate legal, security and communication actions. |
Rapid containment is necessary to prevent lateral spread and secondary consequences. |
Strategic decisions should be made by authorised governance. |
|
Technological |
DDoS Attack |
Malicious traffic overwhelms public-facing services. |
Respond and Defend |
Activate DDoS mitigation; redirect/filter traffic; engage providers; communicate service status if material. |
Technical defence is usually the fastest route to stabilisation. |
Escalate if prolonged or part of a wider attack. |
|
Technological |
IT Sabotage / Malicious Insider |
An authorised person intentionally disrupts technology or information. |
Take the Offensive |
Immediately restrict access; preserve evidence; isolate affected assets; investigate scope; engage security/legal functions. |
Continued authorised access could permit further damage. |
Preserve evidential integrity. |
|
Technological |
Data Corruption / Integrity Failure |
BDCB cannot determine whether critical records or transactions remain trustworthy. |
Take the Offensive |
Suspend affected processing; establish trusted data point; reconcile records; identify contamination boundaries; restore only after integrity validation. |
Incorrect processing can be more damaging than temporary unavailability. |
Treat integrity separately from availability. |
|
Technological |
Data Breach |
Sensitive supervisory, financial, employee or operational information is exposed. |
Respond and Defend |
Contain access; determine affected information; preserve evidence; meet applicable notification requirements; manage affected stakeholders. |
Transparency must be balanced against investigation and confidentiality requirements. |
Use Stonewall only for specific protected information, not as the overall strategy. |
|
Technological |
Data Centre Failure |
Loss of a technology facility disrupts multiple services. |
Respond and Defend |
Activate alternate processing/failover; prioritise critical systems; assess common dependencies; restore facility capability. |
Multi-service disruption requires coordinated recovery. |
CMT activation likely if failover is unsuccessful. |
|
Technological |
DR / Failover Failure |
Primary services fail, and recovery systems do not operate as intended. |
Take the Offensive |
Establish command structure; prioritise essential services; implement alternative recovery methods; mobilise vendors and specialists. |
Loss of both primary and recovery capability represents a significant escalation. |
Consider extended manual or alternative processing. |
|
Technological |
Failed Technology Change |
A technology change causes widespread disruption, and rollback is unsuccessful. |
Take the Offensive |
Freeze further changes; invoke rollback/recovery; establish technical command; prioritise critical services; communicate with affected stakeholders. |
Continuing normal change activity could worsen instability. |
Independent technical review after stabilisation. |
|
Technological |
Identity / Authentication Failure |
Users cannot access otherwise operational critical systems. |
Respond and Defend |
Activate alternate authentication or controlled emergency access; restore identity services. |
Rapid action restores access while protecting security. |
Emergency access must remain controlled and auditable. |
|
Technological |
Capacity / Performance Crisis |
Extreme transaction or processing demand severely degrades systems. |
Respond and Defend |
Prioritise critical workloads; increase capacity where possible; throttle non-critical activity; engage providers. |
Service prioritisation limits wider disruption. |
Investigate whether demand is legitimate or malicious. |
Payment and Settlement System Crisis
BDCB describes RTGS as the heart of a modern national payment system and designed to meet criteria for systemically important payment systems.
RTGS processes large-value and urgent interbank payments, while ACH performs bulk clearing and submits net obligations to RTGS for settlement.
CSD supports government-securities records, auctions, transfers, secondary-market trading and collateral management.
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Technological / Payment |
RTGS System Disruption |
RTGS becomes unavailable or unreliable, affecting large-value and urgent interbank settlement. |
Take the Offensive |
Immediately assess scope and integrity; activate recovery/failover; coordinate participants; prioritise settlement continuity; provide authoritative status updates. |
RTGS has systemic importance; prolonged uncertainty could affect liquidity and confidence. |
High-priority CMT scenario. |
|
Technological / Payment |
ACH System Disruption |
Bulk clearing becomes unavailable and settlement obligations cannot proceed normally. |
Respond and Defend |
Restore ACH; coordinate clearing windows and participants; assess RTGS dependency; manage accumulated transactions. |
Active intervention limits backlog and downstream settlement impact. |
Escalate if disruption approaches critical processing deadlines. |
|
Technological / Payment |
CSD System Disruption |
Securities records, auctions, transfers or collateral-related activities are unavailable. |
Respond and Defend |
Suspend unsafe processing; preserve record integrity; restore service; coordinate affected participants and government stakeholders. |
Securities integrity is as important as system availability. |
Assess dependencies with RTGS. |
|
Technological / Payment |
Combined RTGS / ACH Failure |
Multiple national payment components fail simultaneously. |
Take the Offensive |
Activate strategic crisis governance; prioritise settlement; coordinate financial institutions; establish alternatives where available; communicate proactively. |
Compound failure increases systemic and confidence consequences. |
Severe-but-plausible exercise scenario. |
|
Technological / Payment |
Payment Data Integrity Crisis |
Payment records may be incorrect, corrupted or manipulated. |
Take the Offensive |
Stop affected processing; establish trusted records; reconcile transactions; coordinate participant verification; resume only after integrity assurance. |
Finality and trust in payment records make integrity critical. |
Do not prioritise availability over correctness. |
|
Technological / Payment |
Participant Connectivity Crisis |
Multiple financial institutions cannot access payment infrastructure. |
Take the Offensive |
Establish participant coordination; determine common dependency; implement alternate connectivity arrangements and prioritise urgent transactions. |
Multiple affected institutions may create sector-wide consequences. |
Assess common-provider failure. |
Confrontation Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Confrontation |
Public Protest |
Demonstrators gather around BDCB and generate access, safety and media concerns. |
Respond and Defend |
Protect personnel; maintain safe access; engage authorities; monitor protest dynamics; communicate BDCB's factual position where appropriate. |
Silence may permit misunderstanding while aggressive engagement could escalate confrontation. |
Respect lawful activity while protecting operations. |
|
Confrontation |
Blockade / Occupation |
Protest activity prevents normal access or occupies BDCB-controlled space. |
Respond and Defend |
Protect people; secure critical areas; activate alternate operations; coordinate with authorities; establish controlled stakeholder communication. |
Operational continuity and safety require active intervention. |
Avoid unnecessary confrontation. |
|
Confrontation |
Regulatory Dispute |
An affected institution publicly contests BDCB regulatory or supervisory action. |
Respond and Defend |
Reaffirm factual and legal basis where disclosure is appropriate; maintain due process; correct material inaccuracies. |
Institutional credibility requires factual explanation without compromising confidential supervisory matters. |
Stonewall protected supervisory information. |
|
Confrontation |
Coordinated Online Campaign |
Sustained online criticism creates reputational pressure. |
Respond and Defend |
Assess facts and reach; correct significant inaccuracies; use official channels; avoid amplifying insignificant criticism. |
Response should be proportionate to actual impact. |
Do Nothing may be appropriate for low-impact commentary. |
Malevolence Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Malevolence |
Terrorist / Hostile Attack |
A deliberate attack threatens lives and critical BDCB operations. |
Take the Offensive |
Protect life; activate emergency response; coordinate with authorities; secure critical assets; account for personnel; maintain essential functions. |
Immediate decisive action is required to limit harm. |
Authorities lead law-enforcement response. |
|
Malevolence |
Bomb Threat |
A credible explosive threat affects BDCB premises. |
Respond and Defend |
Follow security protocols; evacuate or shelter as directed; coordinate specialist authorities; activate alternate operations. |
Life safety is the immediate priority. |
Do not disclose security-sensitive details publicly. |
|
Malevolence |
Sabotage |
Critical facilities or equipment are deliberately damaged. |
Take the Offensive |
Secure site; prevent further access; preserve evidence; assess scope; recover affected capability. |
Continued malicious access creates further risk. |
Coordinate security and law enforcement. |
|
Malevolence |
Cyber Espionage |
Sensitive BDCB information is covertly accessed. |
Take the Offensive |
Contain access; investigate persistence; protect sensitive information; preserve evidence; coordinate appropriate authorities. |
Covert compromise may persist unless actively eradicated. |
External disclosure depends on facts and obligations. |
|
Malevolence |
Extortion / Blackmail |
An actor threatens disclosure, harm or disruption unless demands are met. |
Respond and Defend |
Preserve evidence; involve security/legal specialists; assess credibility; protect threatened persons/assets; manage communications. |
Uncoordinated engagement could increase leverage for the attacker. |
Restrict sensitive negotiation information. |
Organisational Misdeeds — Skewed Management Values
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Organisational Misdeeds — Skewed Management Values |
Stakeholder Interests Inadequately Considered |
A significant decision produces unintended stakeholder harm and escalating criticism. |
Respond and Defend |
Acknowledge concerns; establish facts; review decision impacts; explain rationale; implement corrective action where warranted. |
Credibility is better protected through evidence and corrective action than denial. |
Independent review may be appropriate. |
|
Organisational Misdeeds — Skewed Management Values |
Resilience Neglected |
A preventable crisis exposes inadequate attention to resilience. |
Respond and Defend |
Stabilise operations; acknowledge verified deficiencies; commission review; implement corrective programme. |
Defensive denial may deepen reputational damage. |
Demonstrate measurable improvement. |
|
Organisational Misdeeds — Skewed Management Values |
Risk Culture Breakdown |
Employees failed to escalate warning signs before a major incident. |
Take the Offensive |
Initiate independent review; protect speak-up channels; address leadership/control failures; communicate corrective measures. |
Structural causes require proactive remediation. |
Avoid blaming individuals before facts are established. |
Organisational Misdeeds — Deception
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Organisational Misdeeds — Deception |
Concealment of Material Information |
Significant information was deliberately withheld from legitimate decision-makers or stakeholders. |
Take the Offensive |
Secure evidence; initiate independent investigation; correct material information; take governance action. |
Continued concealment magnifies legal, governance and credibility consequences. |
Stonewall only investigation-sensitive details. |
|
Organisational Misdeeds — Deception |
Misrepresentation of Information |
Material information was deliberately presented inaccurately. |
Take the Offensive |
Establish facts; correct records and communications; investigate accountability; notify affected parties as appropriate. |
Rapid factual correction limits continuing harm. |
Preserve audit trail. |
|
Organisational Misdeeds — Deception |
Manipulation of Reports / Records |
Official records are suspected of deliberate alteration. |
Take the Offensive |
Secure systems and records; preserve evidence; independently validate information; investigate responsible parties. |
Integrity of official information is fundamental to institutional credibility. |
Potential legal consequences. |
|
Organisational Misdeeds — Deception |
Misleading Public Communication |
Material public information is discovered to be inaccurate or misleading. |
Take the Offensive |
Correct inaccurate information promptly; explain verified facts; investigate how error or misconduct occurred. |
Delay permits inaccurate information to persist. |
Differentiate genuine error from intentional deception. |
Organisational Misdeeds — Management Misconduct
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Organisational Misdeeds — Management Misconduct |
Fraud |
Serious fraudulent activity involves personnel or associated parties. |
Take the Offensive |
Secure records; suspend inappropriate access; commission investigation; protect assets; take governance/legal action. |
Immediate action limits financial and reputational damage. |
Maintain procedural fairness. |
|
Organisational Misdeeds — Management Misconduct |
Corruption / Bribery |
Credible evidence indicates improper influence over decisions. |
Take the Offensive |
Preserve evidence; establish independent investigation; manage conflicts; cooperate with competent authorities as appropriate. |
Institutional integrity requires demonstrably independent action. |
Avoid prejudging individuals. |
|
Organisational Misdeeds — Management Misconduct |
Abuse of Authority |
Senior personnel are alleged to have misused official authority. |
Respond and Defend |
Protect affected individuals; independently investigate; maintain governance continuity; communicate verified outcomes appropriately. |
Response must protect both institutional integrity and due process. |
Independent oversight advisable. |
|
Organisational Misdeeds — Management Misconduct |
Misuse of Confidential Information |
Sensitive BDCB information is deliberately exploited or disclosed. |
Take the Offensive |
Restrict access; contain disclosure; investigate scope; protect affected information and stakeholders. |
Continued access could compound damage. |
Coordinate with cyber/security response where relevant. |
Workplace Violence Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Workplace Violence |
Physical Assault |
An individual attacks another person at BDCB premises. |
Take the Offensive |
Protect life; summon security/emergency services; isolate threat; provide medical assistance; preserve evidence. |
Immediate intervention is required to prevent further harm. |
Employee welfare follows stabilisation. |
|
Workplace Violence |
Armed Intruder |
An armed individual enters or attempts to enter BDCB premises. |
Take the Offensive |
Activate emergency protocols; notify authorities; protect personnel; secure critical areas; account for employees. |
Life safety demands decisive action. |
Law enforcement leads tactical response. |
|
Workplace Violence |
Threatened Violence |
A credible threat is made against BDCB personnel or facilities. |
Respond and Defend |
Assess credibility; protect targeted persons; restrict access; involve authorities as appropriate. |
Early intervention can prevent escalation. |
Maintain confidentiality. |
|
Workplace Violence |
Hostage Situation |
Individuals are unlawfully detained. |
Take the Offensive |
Activate CMT; coordinate with police; protect unaffected personnel; manage families, operations and communications. |
Strategic coordination is required alongside specialist law-enforcement response. |
Do not interfere with police negotiation/tactical command. |
Rumours, Misinformation and Disinformation Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Due to Rumours |
Minor Unsubstantiated Online Rumour |
Low-reach commentary makes an unsupported claim with little evidence of stakeholder impact. |
Do Nothing |
Monitor reach and sentiment; prepare facts; avoid unnecessary amplification. |
Public response could give insignificant misinformation greater visibility. |
Escalate if reach or behaviour changes. |
|
Due to Rumours |
False Rumour About BDCB |
Material misinformation about BDCB gains public attention. |
Take the Offensive |
Issue authoritative facts rapidly; use official channels; engage key stakeholders and monitor reaction. |
Confidence can deteriorate while misinformation remains unanswered. |
Speed and accuracy are both critical. |
|
Due to Rumours |
False Rumour About Financial-System Stability |
Claims of widespread financial instability trigger concern. |
Take the Offensive |
Verify conditions; coordinate relevant stakeholders; communicate authoritative facts; monitor financial behaviour. |
BDCB has an objective to ensure financial-system stability. BDCB |
Avoid reassurance unsupported by evidence. |
|
Due to Rumours |
False Rumour About Currency |
False claims concern currency validity, availability or arrangements. |
Take the Offensive |
Correct misinformation through authoritative channels and provide practical public guidance. |
Currency confidence warrants proactive correction. |
Monitor physical currency demand where relevant. |
|
Due to Rumours |
False Rumour About Bank Failure |
Misinformation about a financial institution triggers customer concern or withdrawals. |
Take the Offensive |
Establish facts; coordinate appropriately with institution and authorities; correct material misinformation within legal/confidentiality constraints. |
Delay could permit behavioural amplification and contagion. |
Supervisory confidentiality may constrain detail. |
|
Due to Rumours |
False Payment-System Failure Claim |
Claims circulate that national payment infrastructure has failed or transactions are unsafe. |
Take the Offensive |
Verify system status; issue authoritative service information; coordinate participants. |
Payment confidence may depend on rapid factual clarification. |
Use operational status evidence. |
|
Due to Rumours |
Deepfake of BDCB Official |
Manipulated media falsely depicts an official making a material announcement. |
Take the Offensive |
Rapidly declare content unauthorised where verified; publish authentic information; seek removal where appropriate; monitor spread. |
Delay increases likelihood that fabricated content is accepted as authentic. |
Preserve evidence for investigation. |
Lack of Funds / Financial System Crisis
BDCB's objectives include ensuring financial system stability. Its overnight standing facilities are available to eligible licensed banks and are intended to support bank liquidity management under specified conditions.
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Lack of Fund |
Liquidity Stress at Financial Institution |
A supervised institution faces serious short-term liquidity pressure. |
Take the Offensive |
Intensify monitoring; establish facts; engage institution; assess available tools within BDCB's authority; monitor payment and contagion implications. |
Early action can prevent deterioration and wider confidence effects. |
Decisions must remain within applicable legal/policy frameworks. |
|
Lack of Fund |
Solvency Crisis |
An institution's financial condition raises concerns about its ability to meet obligations. |
Take the Offensive |
Activate enhanced supervisory and crisis coordination; assess systemic implications; coordinate appropriate authorities and communications. |
Delay can increase losses and confidence consequences. |
Distinguish liquidity from solvency. |
|
Lack of Fund |
Bank Run / Rapid Withdrawals |
Customers rapidly withdraw funds due to actual or perceived concerns. |
Take the Offensive |
Monitor liquidity and withdrawal behaviour; establish underlying facts; address misinformation; coordinate institution-level and system-level actions. |
Behaviour can accelerate faster than normal decision cycles. |
Communication must not substitute for substantive action. |
|
Lack of Fund |
Multiple Institutions Under Stress |
Several institutions experience significant stress simultaneously. |
Take the Offensive |
Activate financial-stability crisis governance; assess interconnectedness; coordinate sector response; prioritise systemic functions. |
Simultaneous stress increases contagion potential. |
Major strategic CMT scenario. |
|
Lack of Fund |
Settlement Liquidity Shortage |
A participant lacks sufficient liquidity to meet time-sensitive settlement obligations. |
Take the Offensive |
Monitor settlement position; engage participant; apply applicable liquidity arrangements; protect orderly settlement. |
Settlement difficulties can propagate through payment infrastructure. |
Coordinate closely with RTGS operations. |
|
Lack of Fund |
Financial Contagion |
Stress spreads from one institution or market segment to others. |
Take the Offensive |
Establish system-wide situational awareness; identify transmission channels; coordinate interventions within BDCB's authority; communicate strategically. |
Systemic spread requires action beyond institution-by-institution management. |
Financial-stability considerations dominate. |
|
Lack of Fund |
Critical Supplier Financial Failure |
A key BDCB provider can no longer deliver contracted services. |
Respond and Defend |
Invoke contractual rights and contingency arrangements; activate alternate suppliers; prioritise critical services. |
Primary objective is continuity rather than public confrontation. |
Escalate if shared sector supplier. |
Due to Natural Factors — Cascading Crisis
|
Crisis Type |
Type of Threats / Crisis Scenario |
Detailed Description |
Response Strategy |
Details of Strategy |
Justification of Strategy |
Remarks |
|
Due to Natural Factors |
Denial of Access Due to Flood |
Flooding prevents safe access to or occupation of BDCB facilities. |
Respond and Defend |
Activate alternate facilities/remote work; account for staff; prioritise essential functions. |
Maintaining critical operations reduces secondary impacts. |
Link BCM and CMT arrangements. |
|
Due to Natural Factors |
Workforce Shortage Due to Pandemic |
Critical functions lose significant numbers of personnel. |
Take the Offensive |
Prioritise functions; redeploy cross-trained personnel; invoke succession and minimum-staffing arrangements. |
Proactive prioritisation prevents uncontrolled service degradation. |
Monitor fatigue and prolonged staffing impacts. |
|
Due to Natural Factors |
Power Failure Due to Severe Weather |
Weather causes prolonged utility failure. |
Respond and Defend |
Activate backup power; reduce non-critical loads; transfer operations if endurance becomes insufficient. |
Controlled load management extends critical capability. |
Monitor fuel and cooling dependencies. |
|
Due to Natural Factors |
Data Centre Impact |
Natural hazard threatens or disables a technology facility. |
Respond and Defend |
Protect personnel; fail over processing; monitor replication and service integrity. |
Rapid transfer reduces outage duration. |
Escalate if recovery site shares hazard exposure. |
|
Due to Natural Factors |
Multiple Financial Institutions Disrupted |
A major natural event simultaneously affects BDCB and financial institutions. |
Take the Offensive |
Establish sector-wide situational awareness; prioritise critical financial infrastructure; coordinate stakeholders and communications. |
Simultaneous disruption requires system-level management. |
Severe-but-plausible exercise scenario. |
|
Due to Natural Factors |
Currency Distribution Disruption |
Severe weather interrupts normal movement or availability of physical currency. |
Take the Offensive |
Assess demand and inventories; prioritise distribution; coordinate logistics and affected institutions; communicate where required. |
Currency availability can become a public-confidence issue. |
Security considerations remain important. |
Applying the Four CM Strategies
View the four CST2 strategies as strategic postures, not rigid labels. BCM Institute's Guidance Notes to Complete the Crisis Management (CM) Strategy methodology identifies Do Nothing, Stonewall, Respond and Defend, and Take the Offensive as the available response strategies.
Do Nothing is appropriate only where management consciously determines that intervention would add no value or could amplify an insignificant issue. Monitoring continues, and escalation criteria remain active.
Apply Stonewall selectively rather than as BDCB's default crisis posture.
It may be justified for confidential supervisory information, security-sensitive details, personal information, law-enforcement matters, privileged legal information or facts that have not yet been verified. It should not be interpreted as misleading stakeholders.
Respond and Defend is appropriate when BDCB needs to protect people, operations and institutional credibility while explaining verified facts and demonstrating that the event is being controlled.
Take the Offensive is appropriate where waiting creates greater risk—for example, systemic payment disruption, rapidly spreading misinformation, financial contagion, ransomware, deliberate misconduct or immediate threats to life.
Strategy Can Change During the Crisis
The selected response strategy should not necessarily remain unchanged throughout the event.
For example, an unverified allegation may initially justify restricted disclosure while facts are established. Once evidence becomes available, BDCB may move to Respond and Defend.
If misinformation subsequently begins influencing public behaviour, BDCB may move to Take the Offensive through authoritative communication and stakeholder coordination.
Similarly, a routine technology failure may initially require Respond and Defend. Discovery that the failure resulted from an active cyberattack could require an immediate transition to Take the Offensive.
The strategic progression can therefore be represented as:
Monitor and Verify → Assess Severity and Consequences → Select Response Strategy → Implement Strategic Actions → Monitor Stakeholder Reaction → Adjust Strategy → Stabilise Crisis → Recover
For the eBook, convert this sequence into a standalone professional diagram rather than retaining it as text arrows.
Relationship Between Prevention and Response
CMS Part 1 and CMS Part 2 should operate together.
CMS Part 1 — Crisis Prevention Strategy seeks to prevent a crisis or identify deterioration early.
CMS Part 2 — Crisis Response Strategy determines the strategic posture when prevention has failed or the event has already escalated.
The complete progression is:
Threat / Crisis Scenario → Crisis Prevention Strategy → Early-Warning Indicators → Prevention Controls Fail or Are Overwhelmed → Crisis Escalation → Crisis Response Strategy → Stabilisation → Recovery → Lessons Learned
This should also be presented as an individual professional diagram in the eBook.
Response Strategy and Crisis Communications
The BCM Institute's Guidance Notes to Complete the Crisis Management (CM) Strategy highlight that CMS should directly influence BDCB's crisis communications.
A Do Nothing strategy may involve no external communication but continued monitoring.
A Stonewall posture may require a carefully controlled statement explaining that BDCB cannot provide specific information at that stage, without speculating or misleading stakeholders.
A Respond and Defend strategy requires factual explanation, evidence-based stakeholder reassurance, operational updates, and correction of material inaccuracies.
A Take the Offensive strategy requires BDCB to communicate proactively rather than waiting for questions or misinformation to shape the narrative.
For a central bank, communication should be treated as a strategic response capability, particularly where payment-system confidence, financial-institution stability, currency confidence or financial-system stability may be affected.
Management Validation of the BCM Institute's Guidance Notes to Complete the Crisis Management (CM) Strategy Table
The relevant BDCB crisis-management, business, risk, technology, cyber, security, communications, legal, and senior-management stakeholders should validate the completed Crisis Response Strategy Table.
For every scenario, management should confirm the chosen response strategy, strategic objectives, decision authority, activation threshold, immediate actions, information requirements, stakeholders, communication posture, confidentiality constraints, coordination requirements and criteria for changing strategy.
The validation should also answer a particularly important question:
What evidence would cause BDCB to change from one CMS response strategy to another?
Defining this in advance reduces hesitation and inconsistent decision-making during an actual crisis.
CMS Part 2 — Crisis Response Strategy for Brunei Darussalam Central Bank establishes how BDCB could respond strategically once a threat or crisis scenario has developed beyond prevention and requires active crisis management.
Consistent with BCM Institute's Guidance Notes to Complete the Crisis Management (CM) Strategy methodology, the chapter applies four strategic response options: Do Nothing, Stonewall, Respond and Defend, and Take the Offensive.
The appropriate option depends on the severity of the crisis, the certainty of available information, stakeholder expectations, legal and confidentiality requirements, operational consequences, and the potential impact on BDCB's credibility.
The response strategy is especially significant for BDCB because its responsibilities extend beyond its own organisational operations.
BDCB conducts monetary policy, issues and manages Brunei currency, regulates and supervises financial institutions, seeks to ensure financial-system stability and supports efficient payment systems.
BDCB also operates RTGS, ACH and CSD as components of Brunei Darussalam's National Payment and Settlement Systems.
Accordingly, crisis strategy selection should consider not only:
“How should BDCB protect itself?”
but also:
“What strategic response is required to protect people, maintain critical central-bank functions, support orderly financial infrastructure, preserve trustworthy information, manage stakeholders and reduce the possibility that the crisis develops into a wider financial-system or confidence event?”
CMS Part 2 therefore bridges crisis prevention and strategic crisis action.
Together with the preceding CRA and CMS Part 1 activities, it enables BDCB to move systematically from threat identification and prevention to deliberate, proportionate and adaptable crisis response.
More Information About Crisis Management Blended/ Hybrid Learning Courses
To learn more about the course and schedule, click the buttons below for the CM-300 Crisis Management Implementer [CM-3] and the CM-5000 Crisis Management Expert Implementer [CM-5].


![[CM] [BDCB] [Full Banner] Crisis Management in Action_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/399bc296-6bd2-4c03-8819-8bfe517a3e07.png)
![[Banner] [Title] [CM] [E3] Part 2_ Crisis Response Strategy](https://no-cache.hubspot.com/cta/default/3893111/118cae05-ad59-4fd4-9a2e-d021183d5e97.png)
![[CM] [BDCB] Legal Disclaimer Banner](https://no-cache.hubspot.com/cta/default/3893111/062c8304-1699-4f7b-a38d-f128d9815304.png)
![Banner [CM] [Summing Up] [E3] [CMS] [P2] Crisis Response Strategy](https://no-cache.hubspot.com/cta/default/3893111/a4477696-991b-440f-bab2-7bf6d272b280.png)
![[CM] [BDCB] [3/4 Banner] Crisis Management in Action_ A Practical Implementation Guide for BDCB](https://no-cache.hubspot.com/cta/default/3893111/b3d8c34f-d579-45e8-aba7-c04de5f90bb2.png)
![[CM] [BDCB] [E3] [CRA] [P1-1] List of Threats](https://no-cache.hubspot.com/cta/default/3893111/aca43cda-9319-49d4-81cf-9ec36c6c6ab6.png)
![[CM] [BDCB] [E3] [CRA] [P1-2] List of Crisis Scenarios [Natural and Man-made]](https://no-cache.hubspot.com/cta/default/3893111/029d6134-feb9-446e-884c-562eb4fd8e70.png)
![[CM] [BDCB] [E3] [CRA] [P1-3] List of Crisis Scenarios [Technology]](https://no-cache.hubspot.com/cta/default/3893111/883a9c65-15e5-408d-a406-3835732e8f16.png)
![[CM] [BDCB] [E3] [RAR] [P2] Treatment and Control](https://no-cache.hubspot.com/cta/default/3893111/a122225c-4e8c-435a-8268-4e24d1d834bf.png)
![[CM] [BDCB] [E3] [CRA] [P3] Risk Impact and Likelihood Assessment](https://no-cache.hubspot.com/cta/default/3893111/7a44ac98-15cf-427b-b8fa-011061502369.png)
![[CM] [BDCB] [E3] [CMS] [P1] Crisis Prevention Strategy](https://no-cache.hubspot.com/cta/default/3893111/8e764d9a-b2ac-4551-b953-7f5bec6e662d.png)
![eBook Cover [CM] [BDCB] [E3] [2D]](https://no-cache.hubspot.com/cta/default/3893111/77f3104a-2f3b-4e2b-a101-9e72c37001c2.png)





![[BL-CM] [5] Register](https://no-cache.hubspot.com/cta/default/3893111/82024308-16f4-4491-98be-818a882c6286.png)

![Email to Sales Team [BCM Institute]](https://no-cache.hubspot.com/cta/default/3893111/3c53daeb-2836-4843-b0e0-645baee2ab9e.png)









