What Does Cyber Resilience Really Mean for a Building Society?

Cyber resilience

Cyber resilience for a building society means the ability to keep delivering important services to members, such as access to savings, mortgage payments, and online banking, even when a cyber-attack or IT failure hits. It is different from cyber security. Security is about stopping an attack from getting in. Resilience is about what happens next: staying within an acceptable level of disruption, recovering quickly, and protecting members and market stability even if a breach or outage does occur.

That distinction matters more than ever. According to Bridewell’s 2026 research report, 93% of financial services organisations experienced a cyber incident in the past 12 months. For a building society, built on member trust and a mutual model with no shareholders to absorb a bad headline, the question is no longer if disruption happens. It is whether members can still get to their money when it does.

 

Why cyber security alone isn't enough

Most building societies have invested heavily in perimeter defences, firewalls, monitoring and staff training. That is all necessary, but it is not the whole picture. Cyber security stops threats. Cyber resilience assumes some threats will get through anyway, and asks a harder question: can we keep our important business services running within a tolerable level of disruption?

Third-party failure is worth dwelling on here. A growing share of breaches now involves a third-party rather than the firm itself, and financial services firms report some of the slowest incident response times of any critical national infrastructure sector as a result (Bridewell, 2026). When AWS, Azure, or a core banking platform provider has an outage, it is the building society's members who cannot log in, not the supplier's. Regulators have made clear that this is not an excuse. A firm remains accountable for its important business services regardless of who is running the system behind them.

 

What the regulator expects

The FCA's operational resilience rules (PS21/3, alongside PRA SS1/21) apply directly to building societies. The transition period ended on 31 March 2025, and the FCA has now shifted from checking firms have a plan to checking firms have evidence.

In its "insights and observations one year on" publication, the FCA set out what it is finding when it looks. In practice, that means:

  • Impact tolerances stated without justification are being flagged. It is not enough to say "four hours." A firm needs to show why four hours is the point at which harm to members becomes intolerable.

  • Mapping diagrams with generic placeholders rather than named systems are treated as incomplete evidence, not proof of readiness.

  • Self-assessments frozen in March 2025 are a red flag. The FCA expects the document to be a living one, reviewed at least annually and updated after any material change to systems, suppliers, or risk posture.

  • Severe but plausible scenario testing needs to be severe. The FCA points to recent cloud outages at AWS, Azure, and Cloudflare, and high-profile attacks on well-known UK retailers, as exactly the kind of scenario boards should be testing against, not treating as unlikely edge cases.

New reporting requirements (SS1/26) covering operational incidents and third parties come into force on 18 March 2027, which gives building societies a narrowing window to close any gaps found in 2026.

 

What good cyber resilience looks like in practice

For a mid-tier building society, genuine resilience tends to share a few characteristics:

  • Important business services are defined from the member's point of view, not the org chart. "Ability to withdraw savings" is an important business service. "The savings team" is not.

  • Impact tolerances have a rationale a board member can explain in one sentence, tying the tolerance to real member harm rather than an arbitrary number.

  • Third-party resilience is tested, not assumed. The society satisfies itself that a supplier's own testing methodology is fit for purpose, rather than taking a certificate at face value.

  • Scenario testing includes the uncomfortable scenarios, not just the ones the firm is confident it will pass.

  • The self-assessment is a working document the board actually uses, not a file produced once for a supervisory visit and left untouched.

None of this replaces good cyber security. It sits alongside it, and it is the layer that determines whether members notice a disruption at all.

 

Where genuine resilience starts

The building societies that handle this well tend to start from the same place: real clarity on which services must never fail, what "intolerable" actually means for their members, and where their genuine dependencies sit. That clarity is what gives a society the freedom to grow, adopt new technology and work with new suppliers with confidence, rather than treating every change as a new risk to firefight.

If you'd like to talk through where your building society's resilience genuinely stands, or how the FCA's expectations apply to your firm, get in touch with our team – we’d be more than happy to help.

See more...