Site icon Finance Derivative

Why compliance does not guarantee cyber resilience

Hacker attack computer hardware microchip while process data through internet network, 3d rendering insecure Cyber Security exploit database breach concept, virus malware unlock warning screen

~ Why passing an audit is not proof that financial organisations can withstand a real cyber-attack ~

Cyber security has become one of the most audited and regulated areas of enterprise technology. However, simply passing an audit or achieving certification is not the same as proving that systems, people and processes can withstand a genuine outage or cyber incident. Here, Nathan Charles, head of customer experience at cyber resilience specialist OryxAlign, explains why organisations need to look beyond compliance to build genuine operational resilience.

Banks, building societies and wider financial organisations are among the most targeted businesses for cyber criminals. In 2025, the UK’s Treasury Select Committee investigated nationwide IT failures and found there were at least 803 hours, or 33+ days, of tech outages caused by cyber-attacks.

Organisations invest significant time and resource into achieving certifications such as ISO 27001 and Cyber Essentials, while regulated firms face additional obligations under frameworks such as the Financial Conduct Authority (FCA) and Prudential Regulation Authority (PRA) operational resilience rules. These frameworks provide valuable structure and demonstrate a credible baseline of security maturity.

Compliance frameworks like these set a recognised baseline, create accountability and give boards and customers a way to benchmark security maturity. The risk lies in what happens post-certification.

For many organisations, passing an audit becomes the objective in itself, rather than a step towards genuine resilience. Certification and self-assessment exercises capture a snapshot of security controls at a single point in time, under conditions that are largely predictable. They rarely test what happens when those controls are placed under real pressure, such as a ransomware attack that spreads faster than the incident response plan anticipated, a misconfigured update that takes core systems offline, or a supplier outage with knock-on effects nobody had mapped.

When the paperwork doesn’t match reality

The gap between documented compliance and operational reality is well evidenced. The UK Government’s Cyber Security Breaches Survey 2025/2026 found that 43 per cent of UK businesses reported experiencing a cyber security breach or attack in the past twelve months. This is despite most organisations already having basic technical measures, such as malware protection, firewalls and access controls, in place.

The financial services sector, where operational resilience obligations are most mature, illustrates the same gap. In March 2026, the FCA published its first detailed review of how firms had performed since the transition period for its operational resilience rules ended in March 2025. The review examined whether firms had genuinely embedded resilience into daily operations, or whether their self-assessments amounted to little more than a paperwork exercise. In other words, an organisation can produce all the required documentation and still be unable to demonstrate that its most critical services would survive a severe but plausible disruption.

Regulators are recognising the gap too

Encouragingly, this is not a case of compliance frameworks being wrong; it reflects how regulators and standard-setters are actively evolving what they expect organisations to demonstrate. The National Cyber Security Centre (NCSC) has developed its Principles Based Assurance approach specifically to move away from assessment against fixed, compliance-driven control sets, in favour of a risk-based approach.

The FCA has followed a similar trajectory, shifting its supervisory focus from asking firms whether they have identified their important business services, to asking whether they can prove they remain within agreed impact tolerances today, through tested evidence rather than policy documents.

Similar principles underpin the EU’s Digital Operational Resilience Act, which requires financial entities to test their resilience through scenario-based exercises rather than rely on point-in-time compliance reviews. Across sectors and geographies, there is a consistent direction of travel where demonstrated resilience, not paperwork, is the real measure of readiness.

From checklist to stress test

For organisations that want to close this gap, the starting point is treating resilience as something that is tested and proven, not assumed because a framework has been satisfied. That means running scenario-based exercises that simulate severe but plausible disruption, such as the loss of a critical supplier, a ransomware incident or a major cloud outage, and observing how systems, teams and decision-making actually hold up under pressure.

Compliance frameworks and regulatory obligations remain an essential part of managing cyber risk, and organisations should not disregard them. But they represent a floor, not a ceiling. Genuine operational resilience is proven under pressure, not certified on paper. Organisations that build a culture of continuous testing, honest assumption-challenging and cross-functional ownership will be far better placed to keep critical services running when, not if, disruption occurs.

Exit mobile version