A specialist service from CyPro
Operational resilience consulting for UK financial services
The transition period ended and supervision has started marking the homework. We review self-assessments, set impact tolerances, run scenario exercises and handle SWIFT CSP and DORA, as fixed-fee products with the prices published.
- A published product ladder
- PS21/3, SS1/21 and DORA covered
- Fixed fees under the market's floor
- Senior UK practitioners throughout
Trusted by
The product ladder
Resilience work, sized as products with prices
Six ways in, each a bounded engagement with a fixed published fee, each answering something a supervisor has actually asked firms for.
Self-Assessment Review
Your SYSC 15A self-assessment desk-reviewed against what the FCA's 2026 findings say good looks like, returned as a gap letter and a board summary.
Impact Tolerance Workshop
Important business services identified and tolerances documented in a facilitated day, written so supervisors read decisions rather than aspirations.
Scenario Testing Exercise
A severe-but-plausible tabletop designed from your own services and tolerances, run to a timed script and evidenced in a pack your auditors can use.
SWIFT CSP Assessment
The independent assessment CSCF v2026 makes mandatory, delivered by a UK team at a published fee, sized by your architecture type.
DORA for UK Firms
Whether the EU regime catches your UK business, answered properly, and a gap analysis that maps DORA onto the FCA and PRA work you already run.
CBEST and TLPT Readiness
Preparation for threat-led testing across CBEST, STAR-FS and DORA: scoping, evidence and an intelligent buyer sitting on your side of the table.
What does operational resilience consulting involve?
For a UK financial services firm it means making the regulatory machinery real: identifying important business services and their tolerances, keeping the self-assessment current, testing severe-but-plausible scenarios and evidencing all of it to the FCA and PRA, with DORA layered on where EU exposure exists. Some firms need a full programme; most need specific, well-bounded help at a known cost, which is what the product ladder is for.
Why this practice
Resilience consulting that shows its workings
Fees on the page, not in a proposal
This market's published floor is £15,000 and most firms publish nothing at all. Our product ladder sits underneath it with every figure on the pricing page.
Built around what supervisors said
The FCA's 2026 review told firms exactly where programmes fall short. Each product answers a named finding rather than a generic maturity model.
Products, not programmes by default
A review, a workshop, an exercise: bounded pieces of work with fixed fees. The full programme exists for firms that genuinely need one, and gets quoted as such.
Written twice, on purpose
Every deliverable arrives as practitioner detail and as a board pack, because a finding the committee cannot read is a finding that stays unfunded.
Both regimes, one evidence base
FCA and PRA rules on one side, DORA on the other: dual-scoped firms gather evidence once and answer both, instead of running parallel programmes.
A security bench behind the advice
The consultants here sit beside CyPro's incident responders, penetration testers and round-the-clock operations team, so the advice comes from people who handle real disruption.
Your experts hold
Verifiable outcomes
What clients report back
Before you ask us
Frequently asked questions
What is operational resilience, in one sentence?
The ability of a firm to keep its important business services running through disruption, within tolerances its board has set, evidenced well enough that a supervisor believes it. Everything else in the regime, mapping, testing, self-assessment, exists to make that one sentence true and provable.
How is it different from business continuity?
Business continuity plans for getting sites, systems and people back; operational resilience starts from the customer-facing service and asks how much disruption is tolerable at all. A firm can hold an excellent ISO 22301 certificate and still fail supervision, because plans are not outcomes and recovery time objectives are not impact tolerances.
Who do the FCA and PRA operational resilience rules apply to?
Banks, building societies, PRA-designated investment firms and insurers, plus enhanced-scope SM&CR firms, payment and e-money institutions and recognised investment exchanges on the FCA side. Dual-regulated firms answer to both regulators, which in practice means one set of work evidenced two ways.
The transition ended in March 2025. What are firms expected to have now?
A current self-assessment the board has approved, impact tolerances for every important business service, mapping that reaches your third parties, scenario testing that is genuinely severe, and evidence that vulnerabilities found along the way are being fixed. The regime stopped being a project and became business as usual; supervision now reads it that way.
Where to begin
Find out how your resilience programme actually reads
A free 45 minute scoping call with a consultant covers where your self-assessment, tolerances and testing stand against what supervisors now expect, and which fixed-fee product closes the gap. Nobody sells at you.