A specialist service from CyPro
Operational resilience consulting for UK financial services
The UK's resilience rules are now fully in force, and the FCA and PRA have moved from setting expectations to checking what firms actually built. We measure your resilience against the recognised frameworks, build the plans that close the gaps, test them properly and handle SWIFT CSP and DORA, as fixed-fee services with the prices published.
- Every service priced and published
- PS21/3, SS1/21 and DORA covered
- Fixed fees under the market's floor
- Senior UK practitioners throughout
Trusted by
The services
Resilience work, delivered as services with prices
Six ways in, each a bounded engagement with a fixed published fee, each answering something the regulators actually ask firms for.
Resilience Gap Analysis
Your resilience measured against ISO 22301, DORA, NIST and the UK regimes, self-assessment included, returned as a gap report and a board summary.
Resilience Framework
Business impact analyses run, business continuity and IT disaster recovery plans built with your teams, and tolerances documented with their rationale.
Scenario Testing Exercise
A severe-but-plausible tabletop designed from your own services and tolerances, run to a timed script and evidenced in a pack your auditors can use.
SWIFT CSP Assessment
The independent assessment CSCF v2026 makes mandatory, delivered by a UK team at a published fee, sized by your architecture type.
DORA for UK Firms
Whether the EU regime catches your UK business, answered properly, and a gap analysis that maps DORA onto the FCA and PRA work you already run.
CBEST and TLPT Readiness
Preparation for threat-led testing across CBEST, STAR-FS and DORA: scoping, evidence and an intelligent buyer sitting on your side of the table.
What does operational resilience consulting involve?
For a UK financial services firm it means making the regulatory machinery real: identifying important business services and their tolerances, keeping the self-assessment current, testing severe-but-plausible scenarios and evidencing all of it to the FCA and PRA, with DORA layered on where EU exposure exists. Some firms need a full programme; most need specific, well-bounded help at a known cost, which is what our fixed-fee services are for.
Why this practice
Resilience consulting that shows its workings
Fees on the page, not in a proposal
Almost nobody in this market publishes a figure, and the few that exist start at £15,000, reached only by asking. Every one of our fees is on the pricing page.
Built around what supervisors said
The FCA's 2026 review told firms exactly where programmes fall short. Each service answers a named finding rather than a generic maturity model.
Bounded services, not programmes by default
A gap analysis, a framework build, an exercise: bounded pieces of work with fixed fees. The full programme exists for firms that genuinely need one, and gets quoted as such.
Written twice, on purpose
Every deliverable arrives as practitioner detail and as a board pack, because a finding the committee cannot read is a finding that stays unfunded.
Both regimes, one evidence base
FCA and PRA rules on one side, DORA on the other: dual-scoped firms gather evidence once and answer both, instead of running parallel programmes.
A security bench behind the advice
The consultants here sit beside CyPro's incident responders, penetration testers and round-the-clock operations team, so the advice comes from people who handle real disruption.
Your experts hold
Verifiable outcomes
What clients report back
Before you ask us
Frequently asked questions
What is operational resilience, in one sentence?
The ability of a firm to keep its important business services running through disruption, within tolerances its board has set, evidenced well enough that a supervisor believes it. Everything else in the regime, mapping, testing, self-assessment, exists to make that one sentence true and provable.
How is it different from business continuity?
Business continuity plans for getting sites, systems and people back; operational resilience starts from the customer-facing service and asks how much disruption is tolerable at all. A firm can hold an excellent ISO 22301 certificate and still fail supervision, because plans are not outcomes and recovery time objectives are not impact tolerances.
Who do the FCA and PRA operational resilience rules apply to?
Banks, building societies, PRA-designated investment firms and insurers, plus enhanced-scope SM&CR firms, payment and e-money institutions and recognised investment exchanges on the FCA side. Dual-regulated firms answer to both regulators, which in practice means one set of work evidenced two ways.
The transition ended in March 2025. What are firms expected to have now?
A current self-assessment the board has approved, impact tolerances for every important business service, mapping that reaches your third parties, scenario testing that is genuinely severe, and evidence that vulnerabilities found along the way are being fixed. The regime stopped being a project and became business as usual; supervision now reads it that way.
Where to begin
Find out how your resilience programme actually reads
A free 45 minute scoping call with a consultant covers where your resilience genuinely stands against what the regulators now expect, and which fixed-fee service closes the gap. Nobody sells at you.