Join our Newsletter — 33% off our NHI Course

How should financial services firms adjust business continuity planning when a public health shock also changes cyber risk?

Firms should treat business continuity planning as both an operational resilience exercise and a security control. That means testing remote access, email, collaboration, monitoring, and approval workflows under stress, then validating that critical functions can continue without weakening supervision or compliance. Planning should cover continuity of decision making, not just system uptime, because crisis conditions often create the opening attackers need.

How continuity planning should change when cyber risk rises with the crisis

When a public health shock changes how people work, a business continuity plan can no longer assume that “remote” is a temporary exception. The plan has to cover alternate ways to approve work, verify people, monitor activity, and recover from disruption while maintaining control over sensitive access paths. For financial firms, continuity becomes a test of operational resilience and security together.

That shift matters because the same crisis that disrupts staff availability and office-based processes also expands the attack surface. Remote channels, emergency access, temporary process changes, and staff fatigue can all weaken supervision if the continuity plan only measures whether systems stay up.

Why continuity planning has to include security controls, not just uptime

A useful continuity plan defines how critical business functions continue when normal staffing, locations, and approval chains are unavailable. In practice, that means checking whether the organisation can still authenticate users, route approvals, monitor exceptions, and preserve auditability when work moves to home networks and ad hoc collaboration tools. Business continuity is therefore inseparable from identity, access, and control design.

For financial services, the key issue is not simply whether applications are available. It is whether the firm can continue to make controlled decisions under stress, especially in areas like payments, trading, customer servicing, fraud handling, and incident escalation. If continuity planning ignores those decision paths, the firm may remain technically operational while becoming materially less governable.

That is why continuity exercises should include remote access failover, alternative approval routes, out-of-band escalation, and tested monitoring coverage. If a control only works when everyone is in one building, in one meeting room, or using one office-based workflow, it is not resilient enough for a public health shock.

Which continuity failures become more likely when cyber risk shifts

Crises change attacker behaviour as well as defender behaviour. Security teams should assume that phishing, credential theft, fraudulent payment instructions, and abuse of temporary exceptions become more attractive when staff are dispersed and pressure is high. Continuity arrangements that speed up access or relax review can be sensible, but they must be bounded and reversible.

Firms should also expect visibility gaps. Monitoring may be weaker when staff are offsite, logs are harder to review in real time, and exception handling becomes more manual. A continuity plan that does not preserve detection and escalation paths can create a blind spot exactly when adversaries are most likely to exploit confusion.

NHIMG’s Financial Services Identity Security Guide is useful here because the continuity problem in financial firms is often an access problem in disguise: who can approve, who can override, and how third-party or privileged access is constrained when normal operations are disrupted. The same principle appears in broader breach patterns, including The 52 NHI Breaches Report, where overextended access and weak governance turn operational shortcuts into attack paths.

What good preparedness looks like in practice

Good planning starts with the most important services and the decisions that keep them safe. The first question is not “Can people work from home?” It is “Can the firm still run critical processes with acceptable supervision, segregation of duties, and evidence when it must work from home?” That distinction changes the continuity design, the test plan, and the recovery criteria.

Practitioners should verify four things: remote access capacity, alternate approval flows, monitoring coverage, and the ability to revoke or tighten emergency permissions quickly. If one of those breaks, the continuity plan is incomplete, even if business applications remain available. Testing should include real operational scenarios, such as mass remote logins, unavailable managers, and delayed approvals, because those are the conditions where weak process assumptions surface.

Firms should also align continuity with third-party and cloud dependencies. External service providers, identity services, collaboration platforms, and support desks may all become bottlenecks during a public health shock. If a recovery path depends on a vendor that cannot respond quickly, the continuity objective should be revised before the crisis, not during it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 and DORA define the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 RC.RP-01 — Recovery Plan Execution Continuity planning must prove recovery and operating resilience under crisis conditions.
PR.AA-05 — Least Privilege Emergency continuity changes can expand access and weaken supervision if not bounded.
DE.CM-01 — Network Monitoring Continuity must preserve visibility when work shifts to remote channels and exception paths.
Recommendation — Exercise recovery steps under remote-work and staff-disruption scenarios. Limit temporary crisis access to the minimum needed and review it quickly. Validate that monitoring still covers remote access and unusual approval activity.
ISO/IEC 27001:2022 A.5.29 — Information security during disruption This question is about maintaining security controls while continuity processes change during disruption.
Recommendation — Build disruption procedures that preserve security requirements during continuity operations.
DORA ICT third-party risk management — ICT Third-Party Risk Management Financial firms must consider provider dependencies that can become bottlenecks in crises.
Recommendation — Test vendor dependencies and confirm continuity assumptions for critical ICT providers.

Practitioner Guidance

What to prioritise: Start with the business processes where delayed or unsupervised decisions create the greatest loss, not the applications with the loudest outage alert. In financial services, that usually means customer-facing operations, payment approvals, privileged changes, and incident escalation paths.

What to verify: Test whether remote access, authentication, approval, monitoring, and exception handling still work together under reduced staffing. If a recovery step depends on informal trust or office-only review, treat it as a continuity defect, not a convenience.

Common mistake: Teams often overplan for system recovery and underplan for controlled decision making. The more remote and stressed the workforce is, the more important it becomes to prove that temporary operating changes remain observable, bounded, and easy to roll back.

Practitioner takeaway: A strong continuity plan for a public health shock is one that preserves control under pressure, not just service availability under ideal conditions.