Operational Resilience in Action: Case Studies and Best Practices for Maybank
BB OR [A] 6

[OR] [MB] [E4] [CBS] [4] [SuPS] Identify Severe but Plausible Scenarios

New call-to-action

In the context of operational resilience, the identification and evaluation of Severe but Plausible (SbP) Scenarios is a crucial step in preparing for disruptive events that could critically impact the delivery of critical business services.

For Maybank, the Payment and Settlement Systems (CBS-4) form a backbone of its financial services, ensuring liquidity, trust, and transaction continuity across diverse channels.

This chapter maps out specific SbP scenarios for each Sub-CBS process, integrating insights from cyber, ICT, third-party, and physical risk domains. 

These scenarios are not extreme outliers, but instead tailored disruptions that are within the realm of realistic, yet significant occurrences. 

Dr Goh Moh Heng
Operational Resilience Planner-Specialist-Expert
New call-to-action

Identify Severe but Plausible Scenarios

New call-to-action

CBS-4 – Payment and Settlement Systems

[OR] [MB] [E4] [CBS] [1] [SuPS] Identify Severe but Plausible Scenarios

In the context of operational resilience, the identification and evaluation of Severe but Plausible (SbP) Scenarios is a crucial step in preparing for disruptive events that could critically impact the delivery of critical business services.

For Maybank, the Payment and Settlement Systems (CBS-4) form a backbone of its financial services, ensuring liquidity, trust, and transaction continuity across diverse channels. 

This chapter maps out specific SbP scenarios for each Sub-CBS process, integrating insights from cyber, ICT, third-party, and physical risk domains. 

These scenarios are not extreme outliers, but instead tailored disruptions that are within the realm of realistic, yet significant occurrences. 

Each scenario includes an analysis of cyber/ ICT risk links and demonstrates proactive risk management efforts already in place or required.
 

No.

Process Description

Severe but Plausible Scenario

Cyber/ICT Risk Integration

Evidence of Proactive Risk Management Action

1

Retail Funds Transfer Processing

Core banking system outage during peak hours

Core system DDoS attack

DDoS mitigation tools and rerouting architecture are in place

2

Corporate & Bulk Payments

Batch file corruption due to system misconfiguration

Insider threat or privilege misuse

Role-based access control (RBAC) and activity logging

3

Real-Time Gross Settlement (RENTAS)

RENTAS host connectivity loss to the BNM node

Network routing attack or DNS hijacking

Encrypted VPN to BNM and an alternate leased line connection

4

Cross-Border Payments (SWIFT)

SWIFT connector compromise (e.g., fraudulent instruction)

Malware in the SWIFT Alliance interface

SWIFT CSP compliance and periodic security validation

5

Cheque Clearing

Data mismatch or delay due to third-party failure

Poor encryption or API dependency

Vendor due diligence and automated fallback routing

6

E-Wallet and Mobile Payment Integration

Mobile app API outage from the third-party aggregator

API abuse or integration vulnerability

Penetration testing and traffic throttling

7

JomPAY & Bill Payments

National biller integration is down for an extended period

External service interruption

Biller redundancy and daily connectivity health checks

8

Merchant & Acquiring Payments

POS transaction flow delay due to the gateway outage

Gateway spoofing or protocol flaw

Secure channel protocols and endpoint authentication

9

ATM & CDM Transactions Settlement

ATM/CDM transaction queue overflow due to sync failure

Sync script corruption or patch rollback

Dual-site processing and periodic integrity checks

10

Fraud & Risk Monitoring in Payment Systems

Fraud detection rules disabled or bypassed

Malware, rule manipulation, or config tampering

Endpoint protection and 24/7 SOC alerting on config changes

11

Reconciliation & Daily Settlement

The end-of-day report job fails due to a system delay

System clock misconfiguration or corruption

Time-sync verification protocol and job resumption scripts

12

Chargeback & Dispute Resolution

Spike in disputes overwhelms case management team

Bot-generated chargeback abuse

Automated triage and fraud pattern detection using ML

13

Payment System Resilience & Uptime

Simultaneous failure of primary and backup data centres

Coordinated ransomware or data centre attack

Geo-redundancy, immutable backups, and ransomware drills

Legend
  • Cyber/ICT Risk Integration: Shows the nature of ICT/cyber threats tied to the scenario.
  • Evidence of Proactive Risk Management Action: Demonstrates implemented control, mitigation, or governance mechanism addressing the risk.

 

Operational Resilience in Action: Case Studies and Best Practices for MayBank

eBook 4: Starting Your OR Implementation
CBS-4 Payment and Settlement Systems
CBS-4 DP CBS-4 MD CBS-4 MPR CBS-4 ITo CBS-4 SuPS CBS-4 ST
[OR] [MB] [E4] [DP] [CBS] [2] Payment and Settlement Systems [OR] [MB] [E4] [CBS] [4] [MD] Map Dependency [OR] [MB] [E4] [CBS] [4] [MPR] Map Processes and Resources [OR] [MB] [E4] [CBS] [4] [ITo] Establish Impact Tolerances [OR] [MB] [E4] [CBS] [1] [SuPS] Identify Severe but Plausible Scenarios [OR] [MB] [E4] [CBS] [4] [ST] Perform Scenario Testing



New call-to-actionNew call-to-actionGain Competency: For organisations looking to accelerate their journey, BCM Institute’s training and certification programs, including the OR-5000 Operational Resilience Expert Implementer course, provide in-depth insights and practical toolkits for effectively embedding this model.

 

More Information About OR-5000 [OR-5] or OR-300 [OR-3]

To learn more about the course and schedule, click the buttons below for the [OR-3] OR-300 Operational Resilience Implementer course and the [OR-5] OR-5000 Operational Resilience Expert Implementer course.

BL-OR-3 Register Now BL-OR-3_Tell Me More BL-OR-3_View Schedule
BL-OR-5_Register Now BL-OR-5_Tell Me More  [BL-OR] [3-4-5] View Schedule
[BL-OR] [3] FAQ OR-300

If you have any questions, click to contact us.Email to Sales Team [BCM Institute]

FAQ BL-OR-5 OR-5000
OR Implementer Landing Page

New call-to-action

New call-to-action

 

Your Comments Here:

 

More Posts

New Call-to-action