Operational resilience

Separate failures converge

When two different systems fail, do they hit the same services?

A scenario test usually takes one failure at a time, and each test produces its own list of affected services.

In the Operational Resilience model, Legacy Core Banking is the mainframe ledger. Network Infrastructure is the production network, the routing and connectivity layer the bank runs on. The two failures start in different places. Both reach the same nine of the ten important business services.

When two different platform shocks land on the same services, that is structural. It is a question a dependency list cannot answer, however well it is maintained: not what depends on what, but where separate failures converge.

Seen in: Operational Resilience, a synthetic model of a retail bank's operational spine.

Related: The tolerance clock

To see it, ask us for a guest login.

A guest login lets you explore the demonstration models yourself.

Ask for a guest login

Next finding

The fallback is not independent

If digital banking fails, can customers still phone the bank?

Read