Most of the institutions that pass their resilience assessments are, by the framework's own terms, prepared. The framework asks them to map their important business services, to define impact tolerances, to test against scenarios within those tolerances, and to demonstrate the capability to recover within the defined windows. The institutions that pass the assessments demonstrate those things. The assessments are not, in general, fraudulent. The institutions are not, in general, careless. The illusion is in what the framework was built to evaluate, not in the integrity of the evaluation.
What the framework was built to evaluate
The operational resilience frameworks that govern modern banking were designed to evaluate the institution's capacity to absorb, respond to, and recover from disruption events. The premise is that a disruption begins, that the institution detects it, that the response activates, and that the recovery completes within the tolerance window. The framework asks the institution to demonstrate each step.
The premise is correct for a substantial category of incidents. Hardware failures, configuration errors, data centre outages, denial-of-service campaigns, and a wide range of other incidents conform to the shape the framework anticipates. The framework has materially improved the response to these incidents in the years since it was formalised.
What the framework was not built to evaluate is the institution's capacity to absorb, respond to, and recover from a continuous compromise that produces no discrete event. An adversary that obtained access to a critical business service eight months ago, has been extracting value continuously since, and is calibrated to remain below the threshold of detection is producing an experience that the framework does not have a vocabulary for. The institution may pass its resilience assessment with the compromise still active.
Why this is not a failure of the institutions
It would be straightforward to read this observation as an indictment of the institutions or of their compliance functions. That reading would be wrong. The institutions are operating within the framework as it has been articulated to them. The compliance functions are evaluating the institutions against the criteria they have been given. Both are doing their work to a high standard.
The gap is upstream of the institutions and the compliance functions. It is in the framework itself, which was drafted in a period when the threat landscape made the discrete-event premise reasonable. The institutions that have begun to internalise the limitations of the framework, and to develop the parallel constructs required to evaluate continuous compromise scenarios, are doing so in advance of any explicit supervisory requirement. The supervisory community is moving in the same direction, but the formal expectation has not yet caught up to the threat.
What genuinely adaptive resilience requires
The institutions that have begun to develop a more adaptive model of resilience have made several changes that are visible from the outside. The first is the migration from threshold-based detection to behavioural analytics, which we examined in an earlier instalment. The second is the development of what some institutions call a residual exposure construct, an estimate of the consequence under a continuous compromise scenario that runs in parallel to the traditional impact tolerance. The third is a more candid posture in supervisory dialogue, in which the institution surfaces the gap between the framework and the threat and engages the supervisor in the conversation about what comes next.
These changes are not free. Each requires sustained investment and the cultural authority to translate the new constructs into the language of the board, the audit committee, and the supervisor. The institutions that have made the most progress have invested as much in the translation as in the underlying capabilities. The institutions that have not made the changes are, in most cases, materially exposed in ways that their resilience assessments do not surface.
The role of consumers and treasury teams
The discussion above is institutional. The implications for individual customers and treasury teams are more immediate. The category of fraud that has produced the most consistent customer losses in the past eighteen months, authorised push payment fraud accelerated by AI-generated social engineering, is occurring in the conversation that precedes the payment rather than in any breach of the institution. The reimbursement frameworks have improved the recovery of losses but have not closed the underlying gap.
The most consistent variance reduction in losses to this category of fraud follows from a procedural habit rather than a technological control. Out of band verification of any unusual instruction, regardless of how legitimate the request appears, regardless of the seniority of the apparent originator, and regardless of the urgency that has been engineered into the request, is the highest-leverage habit a household or a treasury function can install. The institutional defences are improving. The procedural defences sit with the customer, and the customers that have installed them are materially less exposed.
What adequate preparedness looks like in 2026
Adequate preparedness in 2026 is no longer a destination. It is a posture. The institution that is adequately prepared has accepted that the threat landscape will continue to change at a tempo the formal framework does not yet reflect, has invested in the continuous capabilities required to detect and respond to that landscape, and has built the institutional and cultural authority to translate the resulting exposure into the language of the board and the supervisor.
The institution that is adequately prepared has also accepted that the operational resilience framework, even as it evolves, will remain a partial picture. The framework will continue to evaluate the response to discrete events, and the institution will continue to need a parallel capability to evaluate the response to continuous compromise. The two pictures are complementary. Neither is sufficient on its own.
The customers and treasury teams that are adequately prepared have installed the procedural habits that close the variance in their own exposure to the fraud typologies that the institutional defences cannot fully control. The procedural cost is small. The variance reduction is substantial.
The wider implication
The wider implication of the analysis presented in this series is that the relationship between adversaries and defenders in financial cyber risk has changed shape, and that the change is consequential. The frameworks that have governed the response are evolving but have not yet caught up. The institutions and customers that recognise the gap candidly and begin to close it are, by every available measure, materially better positioned than those that do not.
The next supervisory cycle will, in most jurisdictions, make the expectation more explicit. The institutions that have already started will find that cycle a continuation of work already in progress. The institutions that have not started will find it a more difficult conversation. The choice of which conversation to enter is one that institutions still control, for now.
