The Bank of England has intensified its focus on digital resilience across the financial system with the publication of new guidance on how banks, insurers and financial market infrastructures should prepare for, withstand, and recover from severe cyber-attacks.
The latest paper, Effective Practices: Cyber Response and Recovery Capabilities, was released in coordination with the Prudential Regulation Authority (PRA) and the Financial Conduct Authority (FCA), and builds on a growing body of regulatory initiatives that now place software testing and operational resilience at the heart of supervisory expectations.
For the Bank, cyber threats are no longer a peripheral risk but a core determinant of financial stability. “Cyber-attacks remain a major threat to the financial sector,” the Bank wrote on LinkedIn.
“Our latest paper outlines effective practices observed across systemic firms and financial market infrastructures, highlighting the continued evolution of their cyber response and recovery capabilities,” the authority posted.
The new guidance highlights how systemic firms are evolving their defences in response to an increasingly hostile environment where complex attacks can disable critical systems, compromise data, and ripple through supply chains. It represents a clear message to the sector: resilience can no longer be assumed, it must be proven.
The publication marks the latest stage in a multi-year regulatory effort to embed resilience testing into the financial sector’s operations.
It builds on the joint operational resilience policies introduced in 2021 and complements the Bank’s new STAR-FS, which stands for Simulated Targeted Attack and Response for Financial Services framework.
Under STAR-FS, firms are required to demonstrate their ability to continue delivering important business services within defined impact tolerances, not only under normal operations but during live, threat-led simulations.
As reported by QA Financial last week, regulators have made it clear that resilience must be “continuously tested, measured and evidenced,” transforming quality assurance from a reactive function into a regulatory imperative.
STAR-FS represents a decisive step towards embedding resilience testing into ongoing QA processes rather than treating it as a compliance exercise.
It demands that testing teams validate how systems behave under degraded conditions, including transaction delays, API failures or cyber intrusions, and produce regulator-ready documentation for every cycle.
Simulating the unthinkable
The Bank’s new guidance reveals that firms are increasingly simulating destructive scenarios involving highly capable threat actors that could simultaneously affect multiple systems and suppliers.
Leading institutions are expanding beyond simple duration-based impact tolerances to include metrics such as value, volume and types of payments, providing a more realistic measure of potential harm to consumers, markets and financial stability.
In practice, this means designing and testing fallback mechanisms to ensure that essential services can continue during a disruption. Some firms have developed the ability to process critical payments even in the event of major outages by restoring essential infrastructure in minimal form or switching to segregated alternative environments.
The Bank also highlights the importance of communication during a crisis. The most advanced firms maintain pre-defined communication plans that have been tested for transparency and resilience throughout an attack.
Several have replicated authentication and security systems in cloud-based tertiary environments or built independent communication channels to ensure continuity even if on-premises networks are compromised.
According to the report, many financial institutions have accelerated their ability to recover from severe cyber-attacks through advances in backup technology, clean recovery environments and structured rebuilds.
Among the most effective practices observed are the implementation of immutable data backups that cannot be altered once written, rigorous testing of bare-metal recovery processes, and the prioritisation of critical data restoration to ensure operations can resume within regulatory impact tolerances.
Some firms have invested in segregated tertiary facilities, designed to isolate production environments from external actors and allow a secure switchover if needed. The Bank emphasises that such capabilities must be part of an integrated response framework that combines technology, governance and decision-making across the enterprise.
Third-party and sector-wide resilience
A recurring theme in the guidance is the growing risk of third-party dependencies. The Bank notes that mature institutions actively assess the resilience capabilities of their suppliers to ensure they match internal standards.
Where that assurance is not achievable, firms are expected to consider alternative measures to remain within tolerance, including failing over to other providers, establishing manual workarounds, or restoring services independently.
The guidance also underlines the importance of collective action across the financial ecosystem. The Cross Market Operational Resilience Group (CMORG) continues to play a pivotal role in coordinating cross-sector efforts. Its reconnection framework, published earlier this year, aims to reduce the time needed to restore access after disconnection events and will be tested across the sector before year-end.

The initiative follows the findings of the Bank’s 2024 Cyber Stress Test, which underscored the systemic importance of collaboration and coordinated exercises.
The Bank’s latest publication aligns closely with its wider digital transformation programme, led by James Benford, Executive Director for Data and Analytics Transformation.
Earlier this year, Benford described how the Bank is advancing AI-assisted code testing to improve data quality and accelerate development.
“The Bank aims for reliable AI systems that perform to a high standard and are grounded in high-quality data,” he said.
“In some cases, this means using smaller models to do the work.” He noted that writing code with the help of AI has “accelerated our transformation efforts,” with processes that previously took months now completed in days.
The emphasis on transparent, testable and ethically governed AI complements the Bank’s resilience agenda. By embedding AI-driven testing into its own operations, the Bank is signalling that data integrity, model validation and software assurance are inseparable components of digital resilience.
QA’s expanding role
For QA and testing professionals, the implications are far-reaching. Assurance is now a regulatory function as much as a technical one.
Under STAR-FS and the new cyber-recovery guidance, QA teams are expected to design and execute scenario-based resilience tests, provide evidence for supervisory review, and integrate fault injection, chaos testing and recovery validation into continuous integration and delivery pipelines.
This approach requires deeper collaboration with risk and security functions, ensuring that testing strategies incorporate real-world threat intelligence and business-critical dependencies.
As the Bank’s report concluded, operational resilience “is not a one-off compliance activity.” It is a dynamic, adaptive discipline that must evolve in step with the threat landscape and be understood across both business and technology domains.
Taken together, the Bank of England’s latest guidance, the STAR-FS framework, and its internal AI testing transformation point to a fundamental redefinition of resilience in financial services.
Where once continuity was measured by recovery plans and documentation, it is now measured by demonstrable assurance that systems can withstand and recover from the most severe disruptions. For QA teams, that means resilience is no longer a box to tick. It is a continuous process, woven into every line of code, every test, and every release, a new era of resilience by design.
NEXT MONTH

Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *

REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Goldman puts AI coding to the test
- How to test AI models that banks do not control
- OpenAI, Filigran and SunTec: the latest vendor and product news
- Sygnum: Testing AI is ‘a measurement problem’
- Banks’ ‘code for all’ push raises testing risks
WATCH NOW



