Strengthening Financial-Sector Cyber Resilience Through Crisis Simulation
- 25 September 2026
- Posted by: SAIA
- Category: Stakeholders
As cyber threats become increasingly sophisticated and interconnected, the financial sector’s ability to respond collectively to a major cyber incident is becoming increasingly important.
The fourth ASISA–SAIA Cyber Crisis Simulation Exercise (CCSE), held on 19 August 2026, offered financial-sector organisations the opportunity to test their preparedness for a significant cyber crisis and to assess their ability to coordinate responses across technical, operational and business functions.
The exercise followed the joint ASISA–SAIA Computer Security Incident Response Team (CSIRT) meeting and cybersecurity workshop held on 29 July 2026. Together, these initiatives support ongoing efforts to strengthen collaboration, information sharing and coordinated responses to cyber incidents that could affect multiple institutions.
Responding to an evolving threat environment
The exercise took place against a complex cyber-threat landscape, with the sector’s cyber-threat status remaining at Elevated (Yellow). Key risks include AI-enabled phishing and deepfakes, identity theft, ransomware and data breaches, social engineering, supply-chain vulnerabilities, and concentration risks arising from shared technology and service providers.
The growing interconnectedness of financial institutions means that an incident affecting one organisation or critical service provider could have consequences across the wider sector. Cyber resilience therefore requires not only strong internal controls but also effective industry coordination, third-party risk management and tested business-continuity arrangements.
Testing preparedness before a crisis
The CCSE tested how organisations would respond and make decisions under pressure and uncertainty. Participating teams represented functions including cybersecurity, operations, risk, legal and compliance, business continuity, communications and customer management.
The simulation focused on incident identification and escalation, executive decision-making, business continuity, customer impacts, stakeholder communication, third-party failures, and industry-level information sharing.
Approximately 40 financial-sector response teams participated, with the Prudential Authority and the Financial Sector Conduct Authority attending as observers.
Relevance for insurers
For the non-life insurance industry, the exercise reinforced that cyber resilience is an enterprise-wide responsibility rather than solely an IT function.
Insurers need to consider how a major cyber event could affect policyholder services, claims processing, payments, intermediaries, regulatory obligations, and access to critical data. Third-party dependencies are also important, particularly where multiple institutions rely on common technology platforms or service providers.
Building collective resilience
The CCSE also supports the broader Financial Sector Cyber Resilience Hub, which is intended to facilitate cyber-threat intelligence sharing, coordinated sector responses and preparedness for incidents extending beyond a single organisation. Its governance framework and operational playbook have been approved, with the supporting memorandum of understanding being finalised.
SAIA will share the findings of the simulation once circulated and continue working through the joint ASISA–SAIA CSIRT structures to strengthen the non-life insurance industry’s cyber preparedness.
Exercises such as the CCSE enable organisations to test plans, identify gaps and strengthen relationships before a real crisis occurs. As cyber threats become increasingly interconnected, ongoing collaboration across the financial sector will be essential to protect institutions and their customers.
Lebohang Tsotetsi
Manager: Insurance Risks