Learning Objectives:
-
Understand the importance of testing and drills for cyber resilience.
-
Design and conduct readiness assessments.
-
Apply testing results to improve cyber resilience.
-
Recognise regulatory expectations for testing.
8.1 The Importance of Testing
Testing is essential for ensuring that cyber resilience measures are effective. The Central Bank of Eswatini’s Guidelines note that “a key means of achieving situational awareness for a financial institution and its ecosystem is a financial institution’s active participation in information-sharing arrangements and collaboration with trusted stakeholders” . Testing provides tangible evidence of readiness.
8.2 Types of Testing
Readiness Assessments:Â The Kincaid course covers “conducting records recovery tests” and “evaluating readiness and gaps” . Readiness assessments evaluate the organisation’s current state of preparedness.
Tabletop Exercises:Â As discussed in Lesson 5, tabletop exercises test the effectiveness of plans and procedures through discussion-based scenarios. The ITEdgeNews article notes that simulations allow organisations to evaluate their weaknesses and incident responses in a controlled environment .
Technical Drills:Â Technical drills test the technical capabilities for detecting, containing, and recovering from incidents. The Finance Derivative article notes that unlike passive training or paper-based exercises, cyber simulations recreate the chaos of a real attack by forcing teams to respond in real time .
8.3 Designing Readiness Assessments
Scope:Â Determine the scope of the assessment, including the functions, systems, and processes to be tested.
Methodology:Â Select appropriate testing methodologies, including tabletop exercises, technical drills, and full-scale simulations.
Metrics:Â Define metrics to measure performance, such as detection time, containment time, and recovery time.
Reporting:Â Document the results of the assessment and report them to senior management and the board.
8.4 Regulatory Expectations
The Central Bank of Eswatini’s Guidelines require financial institutions to establish a threat intelligence process to gather and analyse relevant cyber threat information and conduct a threat analysis that considers threats that could trigger extreme but plausible cyber events . The Skills for Africa course covers “cyber security frameworks and standards (e.g., ISO 27001, NIST)” as part of the curriculum .