AloqaBank runs a hands-on cybersecurity scenario workshop: preparing for a ransomware attack through a third-party supplier

On July 20, JSC "AloqaBank" held a practical workshop for its Cybersecurity Service and Risk Management staff, focused on one of the most pressing scenarios facing the financial sector today: a ransomware attack delivered through a third-party service provider.

Participants worked through a realistic case: a managed service provider is compromised, and through privileged remote access, ransomware is deployed into part of the bank's digital environment overnight. Online and mobile banking become intermittent, card authorisation degrades, the contact centre is overwhelmed — while the scope of the breach, data exposure and backup integrity remain unclear.

Using this scenario, the team worked through a repeatable methodology — "one scenario, five lenses" — built on the structure of NIST CSF 2.0:

  • Identify — what actually breaks, and which services are critical;

  • Protect/Detect — how the attack path unfolded, and what could have caught it earlier;

  • Respond/Recover — how the bank acts and recovers under pressure;

  • Gap analysis — what weaknesses the incident exposes;

  • Govern — turning the lessons into a 30/60/90-day roadmap.

The exercise moved the discussion beyond theory, giving the team a structured way to rehearse who makes which decisions in the first hours of a serious incident — and where compliance ends and real cyber resilience begins.

Employees from the bank's Cybersecurity Service and Risk Management function took an active part in the discussion, proposing their own answers to the key questions at each stage — from identifying critical services to shaping the roadmap for the next three months.

Workshops like this are part of AloqaBank's ongoing effort to strengthen the resilience of critical financial infrastructure against modern cyber threats.