## tnmea2021010

## Source details

**Canonical URL:** [tnmea2021010](https://www.imf.org/-/media/files/publications/tnm/2021/english/tnmea2021010.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/tnm/2021/english/tnmea2021010.pdf.md)
- [Structured JSON version](/-/media/files/publications/tnm/2021/english/tnmea2021010.pdf.json)

---

### Conclusion — Importance of Business Continuity Planning (BCP) for Treasuries
- Government treasuries execute cash and debt management functions critical for delivery of government services and functioning of the financial system.
- Disruptions in payment processes, including debt service and cash transfers, can have significant consequences for service delivery, financial markets, and can have a negative fiscal and/or reputational impact.
- BCPs are critical to ensure core operations are maintained and losses limited across scenarios including ICT outages, natural disasters, and pandemics.

### Conclusion — Evolving threats and implications from COVID-19
- COVID-19 reinforced the importance of BCP for cash and debt management and exposed shortcomings:
  - Most BCPs focused on system failures and data loss with less emphasis on personnel and non-system related activities.
  - Existing plans were often geared to shorter disruptions and did not cover prolonged work-from-home challenges.
  - Treasuries had to continue cash and debt management while staff worked remotely and/or in shifts, and meet additional liquidity needs.
- Operational responses cited:
  - Work-at-home measures, special ICT arrangements, shifts to reduce on-site staff, contact tracing, PPE, enhanced cleaning, quarantine compliance.
  - Country examples: Uganda measures beginning March 2020; Portugal two-week shifts and remote work with less than 10 percent of staff working on-site in October; USA extensive work-from-home testing and market engagement.
- Survey evidence:
  - In 45 percent of cases, staff work from home overwhelmed virtual desktop infrastructure (VDI)/VPN processes.
  - In one third of cases, business continuity IT plans were not prepared for a long-term at-home work force.
- Cyber-attack activity during COVID-19: “more than 200,000 per week in late April 2020 and stayed above 120,000 till mid-June 2020.”

### BCP within an Operational Risk Management (ORM) framework
- Operational risk defined: “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.”
- BCP is a component of ORM focusing on residual risks to critical business processes after mitigating controls.
- Characteristics of an effective BCP:
  - Builds on business impact analysis (BIA).
  - Includes risk mitigation and recovery strategies, testing, training, communication, and crisis management programs.
  - May need to comply with ministry-wide or national directives.

### Digitalization, teleworking, and changing recovery options
- Many cash and debt management functions can be conducted via remote working if digital infrastructure exists.
- Remote arrangements reduce dependency on physical infrastructure and alternate business sites.
- BCPs relying primarily on data backups and alternate sites should be reviewed to include tele-working and digital-first recovery options.

### Cybersecurity and ICT-related risks
- Digitalization increases exposure to cyber risks; financial services have been heavily targeted.
- Government financial units are exposed to cyber risks and have been victims of attacks.
- Long-term remote work increases vulnerability; attacks can be conducted at relatively low cost due to evolving hacking tools.
- BCP measures should defend, respond, and recover against unauthorized access to ICT systems and protect privacy for securities issuance and direct cash transfers.

### Practical approach and objectives of the note
- Aims to:
  - Discuss evolving challenges and solutions to BCP from technological advances and emerging threats.
  - Develop and present a simplified and practical approach to developing a BCP for cash and debt management that saves scarce resources.
- Includes adaptable templates for treasuries to draft and implement BCPs focused on cash and debt management and extendable to other functions.

### Box 2 — Cyber Risks for Public Financial Institutions: documented incidents and implications
- Documented incidents:
  - Central Bank of Bangladesh (February 2016)
    - Attack: unauthorized transactions from an official computer; attempts via SWIFT.
    - Sent 35 payment instructions worth of US$951 million to the Federal Reserve Bank of New York.
    - First 5 transactions completed; remaining 30 blocked.
    - Between February 5 to 9 attackers withdrew US$81 million in total under fictitious identities.
  - Central Bank of Malaysia (March 2018)
    - Attempted unauthorized transfers using falsified SWIFT messages; no financial loss to BNM.
  - Norfund (March 2020)
    - US$10 million fraud via data breach; fraud took place on March 16 and was discovered on April 30.
- Observed vulnerabilities exploited:
  - International bank account monitoring; network and physical security; credentials; weekend protocols.
- Implications for government cash and debt management:
  - Integration risk via FMIS and electronic funds transfers increases exposure.
  - Counterparty and business continuity risk where central bank and private banks act as fiscal agents.
  - Need for coordinated ICT and cyber measures across fiscal agents and counterparties.
  - National coordination required for major threats (example: COVID-19 lockdowns and directives).

### Box 2 — Policy and operational recommendations (cyber focused)
- Establish cyber-security governance and culture.
- Maintain an effective vulnerability management program and documented incident response plan.
- Harmonize ICT and cyber security measures with fiscal agents and banks; incorporate dependencies into business continuity policies.
- Coordinate directives, guidelines, and compliance requirements at national/federal level for major threats.
- Leverage mitigation and operational options:
  - Prevention or avoidance.
  - Transference (insurance, outsourcing).
  - Containment (controls, Incident Management Team).
  - Acceptance and recovery (disaster recovery plans).
- Teleworking as a mitigation enabler:
  - Use secure and encrypted internet connections, tele-conferencing platforms, and cloud storage.
  - Support telework with regulatory frameworks and robust ICT infrastructure.

### Key figures and timelines (Box 2)
- 35 payment instructions worth of US$951 million (Bangladesh).
- First 5 transactions completed; remaining 30 blocked (Bangladesh).
- Between February 5 to 9 attackers withdrew US$81 million in total (Bangladesh).
- March 2018: attempted SWIFT-based unauthorized transfers at Central Bank of Malaysia; no financial loss.
- US$10 million fraud at Norfund; fraud occurred on March 16 and discovered on April 30 (2020).

### Box 4 — ICT Solutions for Business Continuity under Teleworking: country examples and controls
- Country ICT measures:
  - Brazil: VPN with external dedicated server and backup set up a year before pandemic and tested in February 2020; web-access to central securities depositories and web-based Bloomberg.
  - Korea: Government VPN and cloud-based work data storage; dBrain IFMIS remote access; expanded chat services and portal announcements.
  - Portugal: IGCP set up VPN access, virtual meeting licenses, updated firewall/network, procured laptops and peripherals; less than 10 percent of staff on-site in October.
  - Turkey: VPN and remote desktop connections, safe internet, webcams/microphones for meeting rooms.
  - USA: maintained and tested “hot” fail-over operational sites.
- Common adjustments: increased VPN capacity/bandwidth; new virtual meeting technologies; reference to “Telework Enhancement Act of 2010” in USA.
- Cybersecurity guidance and recommended controls for remote work:
  - Implement international standards (e.g. NIST 800-46 Rev 2, BSI IT-Grundschutz Compendium, COBIT 2019, ISO 27000 series).
  - Activate remote access services and user profiles only when required.
  - Base cloud usage on detailed risk assessments.
  - Use vetted teleconference platforms and protect from unauthorized access.
  - Launch cybersecurity awareness campaigns; implement robust endpoint configuration controls.
  - Apply additional security for critical functions not normally allowed to work remotely.
  - Supervisors to reinforce heightened cybersecurity risk in remote work.

### Box 4 — Devolution, fail-over sites, and continuity planning
- Devolution: statutory delegation to transfer responsibilities to designated staff, alternate location, subordinate agency or third party until primary staff resume activities.
  - Activation typically via significant incident such as a state of emergency.
  - Requires tight definition, governance, and time-period assignments to avoid fraud/corruption.
  - Devolution can be a separate document to the BCP.
- Fail-over sites:
  - “Fail-over” = switching to a stand-by system upon primary system failure.
  - “Hot” site: near duplicate with full computer systems and complete backups.
  - “Cold” site: backup facility with little or no hardware installed.

### Box 5 — Devolution: definition, operations, and trade-offs
- Devolution transfers critical operations temporarily or permanently under statutory delegation, executive order or power of attorney.
- Central bank is a natural candidate for devolution of cash and debt management functions.
- Operational considerations:
  - Prepare training for devolution partner staff and ensure ICT access.
  - Define triggers, roles and responsibilities (active and passive triggers).
  - Legal/regulatory amendments may be needed for delegations and authorized signatories.
  - Conduct joint tests with third-party providers.
- Devolution examples:
  - Domestic securities issuance: central bank conducts auctions on behalf of treasury.
  - Debt service payments: central bank or regional offices make payments when treasury signatories are unavailable.
- International practice:
  - US Treasury conducts regular devolution exercises and requires primary dealers to maintain geographically dispersed disaster recovery sites.
  - Industry-wide testing example: October 24, 2020 simulated government securities auction (SIFMA, 2020).
- Mitigation and ICT options:
  - Straight-through-processing (STP) with SWIFT interfaces.
  - Software-as-a-Service (SaaS) and infrastructure-as-a-service examples (Australia, New Zealand).
  - Alternate data centers with replication frequency based on time criticality; triangulated connections recommended.
  - Contingent financial resources: CAT bonds, national catastrophe funds, DRFI programs to reduce auction time-criticality.
- Prerequisites for effective devolution:
  - Incorporate telework into BCP; upgrade ICT; establish IMT and DRP backup teams; implement cyber-attack detection tools; update legal/regulatory frameworks; conduct joint tests.
- Selection of mitigation strategies depends on scenario, impact, time criticality, budget and service availability.
  - Preferred: prevention/avoidance via internal controls and replication.
  - If prevention expensive, consider transfer to third parties (devolution).
  - For major incidents, prioritize containment and IMT activation.
  - Cost-recovery trade-off example: alternate staff site vs work-from-home with encrypted channels.

### Table 3 — Mitigation Strategy Identification Example (Debt Servicing)
- Process: Debt Servicing
  - S1 Physical Infrastructure Inaccessible:
    - Activation of DRP; Alternate site; Teleworking; Devolution
  - S2 ICT System Failure:
    - Install backup or redundant systems; Alternate data center and replication; Activation of ICT DRP; Devolution; Software-as-a-Service
  - S3 Staff Unavailability:
    - Alternate staff; Devolution; Teleworking
  - S4 Key Counterparty/Service Provider Failure:
    - Straight-through-processing; Joint-tests

### ANNEX I — BCP TEMPLATE: structure and timing
- Distribution List and References: include plan locations and persons supplied with copy; references to related documents; header includes: <insert name of the treasury> Business Continuity Plan; Date: dd/mm/yyyy
- SECTION 1 — Executive Summary and Objectives:
  - Executive Summary: one page or shorter.
  - Objectives example: undertake risk management assessment; define/prioritize critical functions; detail immediate response; detail strategies to continue operations; review and update regularly.
- SECTION 2 — Business Impact Analysis (BIA):
  - BIA outputs should cover at least: Debt Servicing; Execution of Payment Requests; Daily Cash Flow Planning; Security Issuances via Auctions; Loan Contracting.
  - Complement BIA with Business Process Analysis.
- SECTION 3 — Risk Mitigation:
  - Treasury selects cost effective mitigation per BIA.
  - Policy requirements: adopt approved mitigation strategies; no essential new activities until mitigation implemented and tested; compliance manager maintains BCP compliance.
- SECTION 4 — Incident Management Team, Response, and Recovery:
  - Establish IMT; ensure efficient information flow and decision making.
  - Emergency center guidance for evacuation/partial incidents.
  - Response phases: Evacuation and Containment; Assessment and Decision; Information delivery.
  - Recovery: return to pre-emergency conditions; re-establish critical activities within recovery time objectives; include pocket card initial action plan.
- SECTION 5 — Rehearse, Maintain, and Review:
  - Rehearse regularly; new staff to receive induction training.
  - Assign training/maintenance tasks; exemplary timeframes:
    - BCP documentation review and update: Six monthly
    - Technology recovery test: Six monthly
    - Staff familiarity training: Annually
    - Scenario (white board) testing: At least six monthly
    - Full test (simulated incident): At least annually
  - Maintain training and review schedules; use staff titles rather than names where possible.

### ANNEX II — Business Impact Analysis (BIA) methodology and ISO alignment
- BIA components:
  - Identification of scenarios/threats; evaluation of impacts; estimation of likelihood; assessment of time criticality.
- Scenarios and duration categories:
  - Use 3 time frames: hours (Intraday), days (Short-term), weeks (Medium-term).
  - 12 scenarios under S1–S4 across Intraday/Short-term/Medium-term (S1.1–S4.3).
- Impact, Likelihood, and Time Criticality scaling (3x3):
  - Impact: High / Medium / Low.
  - Likelihood: High / Medium / Low.
  - MTPD bands for Time Criticality:
    - MTPD<1 day
    - 1≤MTPD≤5 days
    - 5<MTPD≤30 days
  - Time Criticality score assignment examples and logic given.
- Combined Risk Score calculation (concatenation format):
  - Combined Risk Score = Impact-Likelihood-Time Criticality (e.g., HiMeHi).
  - Process deemed critical if combined score has at least 2 High factors or 1 High and 2 Medium factors.
- Alternatives and additional analytical tools:
  - Detailed 3x3 or optional 5x5 scales; Annex Table templates for Combined Risk Score and granular RTOs.
  - BIA is iterative and should be reviewed quarterly or yearly.

### ANNEX III — Process Analysis template, IMT structure, pocket card, emergency kit
- Process Analysis template captures: Inputs, Person Responsible, Workflow, Control Criteria, Required Action/Resource, Output, Critical Resources, Performance Criteria, Inter-process impacts, Risks.
- Example: External Securities Servicing Process — detailed workflow (payment notice → SWIFT setup → payment confirmation), critical systems (Debt Recording System; IFMIS; Central Bank Information System; SWIFT Software).
- IMT structure and roles:
  - IMT headed by head of risk management; liaises with business units and executive (head of treasury, MoF).
  - Support: Treasury Systems Administrator; MoF Media Liaison; MoF ICT staff; Admin/HR; Building Services; Floor Representatives.
  - IMT responsibilities include BCP activation, alternate site decisions, stakeholder communication, delegated authority arrangements, recovery oversight.
- Pocket card and emergency kit:
  - Pocket card: foldable A4, Side 1 general info, Side 2 business-unit-specific info.
  - Emergency kit contents include: computer back-up tapes/disks/USB memory sticks or flash drives; spare keys/security codes; message pads; marker pens; general stationery; mobile telephone with credit and charger.
  - Document checklist: BCP; employee contact lists; procedure manuals; customer/supplier contact lists; emergency services contacts; building site plan; evacuation plan; bank account details; stock/equipment inventory.
  - Kit handling: store on-site and off-site; check regularly.

### BCP testing scenarios and simulated live tests (guidance and examples)
- Simulated live tests recommended in real-time where possible; avoid testing during significant activities.
- Scenario 1: System Failure — system crash at 4:00pm; replacement and reinstall expected to take the rest of the day and all night; senior IT and risk staff unavailable.
- Scenario 2: Building Evacuation — 11:00 am municipal evacuation due to explosion risk; may take more than one day; occurs on day of government securities auction.
- Scenario 3: Damage to Premises — overnight fire; access denied due to structural risk; staff aware at 7:30 am.
- Scenario 4: Local Pandemic — similar to H1N1; by end of week at least 50 percent of staff affected or opted to stay at home; isolation for at least 14 days.
- Scenario 5: COVID-19 Pandemic — several staff test positive after meeting; positive staff relocated to quarantine; non-positive staff isolate for 2 weeks; testing every 3 days; no staff able to return to office for 2 weeks; connectivity available at quarantine facility; premises require thorough sanitization.
- Simulated Live Test #1: Substation explosion at 9:45 am causing central city power outage; restoration estimate at least 1 week; diesel for generator expected to last 3-4 hours; generator reserved for server rooms; telecom tower impact reduces mobile coverage; IMT activates BCP.
- Simulated Live Test #2: Serious explosion on premises at ~5.30pm; around 50 percent in office at event time; dense smoke, injuries, fatalities possible; building sealed for at least 72 hours; IMT activates disaster recovery and relocation; police and media involvement by next morning.

### Practical recommendations and lessons from country experience
- Prepare and train devolution partners; ensure ICT access and legal delegations.
- Conduct joint tests and live simulations with counterparties and market participants.
- Use contingency financing to reduce time-critical pressures on auctions.
- Maintain the BCP as a live document with regular updates and tests.
- Prepare short reference documents (e.g., pocket cards) for staff during disruptions.
- Simplify BIA focusing on time criticality of key processes.
- Accept that not all processes must continue under all conditions; defer non-time-critical processes.
- Maintain BCP responsibility across all treasury staff; testing builds confidence and identifies deficiencies.

*Source: Conclusion section; Box 2; Box 4; Box 5; Annex I–III of tnmea2021010 (Technical Notes and Manuals 21/03 | 2021).*

### Conclusion                                                                                                        26

### Conclusion

### Importance of Business Continuity Planning (BCP) for Treasuries
- Government treasuries execute cash and debt management functions critical for delivery of government services and functioning of the financial system.
- Disruptions in payment processes, including debt service and cash transfers, can have significant consequences for service delivery, financial markets, and can have a negative fiscal and/or reputational impact.
- BCPs are critical to ensure core operations are maintained and losses limited across scenarios including ICT outages, natural disasters, and pandemics.

### Evolving threats and implications from COVID-19
- The COVID-19 pandemic reinforced the importance of business continuity planning for cash and debt management and exposed shortcomings of many existing BCPs:
  - Most BCPs focused on system failures and data loss with less emphasis on personnel and non-system related activities.
  - Existing plans were often geared to shorter disruptions and did not cover prolonged work-from-home challenges.
  - For many treasuries, pandemic conditions required continuing cash and debt management while staff worked remotely and/or in shifts, and meeting additional liquidity needs.
- Examples of operational responses:
  - Work-at-home measures, special ICT arrangements, shifts to reduce on-site staff, contact tracing, PPE, enhanced cleaning, quarantine compliance.
  - Country examples noted: Uganda measures beginning March 2020; Portugal adjustments including two-week shifts and remote work with less than 10 percent of staff working on-site in October; USA Treasury tested extensively for work-from-home and engaged market participants.
- Survey evidence cited: in 45% of cases, staff work from home overwhelmed virtual desktop infrastructure (VDI)/VPN processes. In one third of cases, business continuity IT plans were not prepared for a long-term at-home work force.
- Cyber-attack activity during COVID-19: “more than 200,000 per week in late April 2020 and stayed above 120,000 till mid-June 2020.”

### BCP within an Operational Risk Management (ORM) framework
- Operational risk is defined as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.”
- BCP is a component of ORM and focuses on managing residual risks to critical business processes after mitigating controls are applied.
- An effective BCP:
  - Builds on analysis of potential impacts on business processes (e.g., business impact analysis).
  - Includes risk mitigation and recovery strategies, testing, training, communication, and crisis management programs.
  - Often must comply with ministry-wide or national business continuity directives and plans.

### Digitalization, teleworking, and changing recovery options
- The pandemic demonstrated many cash and debt management functions can be conducted via remote working, provided digital infrastructure exists.
- Remote arrangements revealed opportunities to reduce dependency on physical infrastructure and on relocation to alternate physical business sites.
- Consequently, BCPs that depend primarily on data backups and alternate work sites should be reviewed to consider tele-working and digital-first recovery options.

### Cybersecurity and ICT-related risks
- Digitalization increases exposure to cyber risks; financial services have been heavily targeted.
- Government units engaged in financial activities are exposed to cyber risks and have been victims of attacks.
- Working remotely for long periods increases vulnerability to cyber-attacks, which can be conducted at relatively low cost due to evolving hacking tools.
- BCP measures should be capable of defending, responding, and recovering against unauthorized access to ICT systems, communication platforms, and other digital applications, and should protect privacy where technology is used for issuing government securities or making cash transfers directly to individuals.

### Practical approach and objectives of the note
- The note aims to:
  - Discuss evolving challenges and solutions to business continuity planning arising from recent technological advances and emerging threats.
  - Develop and present a simplified and practical approach to developing a BCP for cash and debt management that saves scarce resources.
- The approach includes templates that can be adapted by treasuries to draft and implement BCPs focused on cash and debt management, and can be extended to other treasury functions or applied within a ministry-wide context where units rely on support services from other agencies.

*Source: Conclusion section of tnmea2021010 (Technical Notes and Manuals 21/03 | 2021).*

### Box 2. Cyber Risks for Public Financial Institutions

### Box 2. Cyber Risks for Public Financial Institutions

### Documented incidents and attack characteristics
- Central Bank of Bangladesh (February 2016)
  - Attack method: unauthorized transactions from an official computer; attempts to deliver money via SWIFT to various accounts in different countries.
  - Timeline: started Thursday, February 4 and continued on Friday, February 5 (a public holiday in Bangladesh, but a working day in the United States and Europe).
  - Actions taken by attackers: sending 35 payment instructions worth of US$951 million to the Federal Reserve Bank of New York.
  - Outcome: the first 5 transactions were completed, but the remaining 30 were blocked partly because of failures made by the attackers (such as a spelling mistake in the payment transaction, which prevented the automatic system from completing the transaction). Between February 5 to 9, attackers were able to withdraw US$81 million in total under fictitious identities.
- Central Bank of Malaysia (March 2018)
  - Attack method: attempted unauthorized fund transfers using falsified SWIFT messages.
  - Outcome: Bank Negara Malaysia (BNM) stated all unauthorized transactions were stopped through prompt action in strong collaboration with SWIFT, other central banks and financial institutions. BNM did not experience any financial loss in this incident. There was also no disruption to other payment and settlement systems that BNM operates.
- Norfund (March 2020)
  - Institution: Norfund—Norwegian state-owned investment fund for developing countries.
  - Attack method: serious case of fraud of US$10 million through a data breach; defrauders manipulated and falsified information exchange between Norfund and a borrowing institution over time in a way that was realistic in structure, content and use of language.
  - Timeline and detection: the fraud took place on March 16 but discovered on April 30 when the scammers initiated a new fraud attempt.
- Observed vulnerabilities exploited across incidents
  - International bank account monitoring.
  - Network and physical security.
  - Credentials.
  - Weekend protocols.

### Implications for government cash and debt management
- Integration risk
  - Many government cash and debt management functions are highly integrated to banking infrastructure through their FMIS, enabling electronic funds transfers, increasing exposure to cyber risks.
- Counterparty and business continuity risk
  - Many sovereign treasuries have agreements with the central bank and private banks to act as a fiscal agent for the treasury; these agents are key counterparties in cash and debt management operations.
  - Coordinated efforts are needed to ensure ICT solutions and cyber security measures are implemented in a harmonized way across fiscal agents and counterparties.
  - Financial and technological connections between cash and debt management and the banking sector should be incorporated into business continuity policies to contain the impact of a possible disruption in one of the key counterparties and to strengthen resilience of cash and debt management operations.
- National coordination for major threats
  - For major threats, coordination is needed on a national or federal level (example context: COVID-19 lockdowns and government directives that BCPs had to comply with, including work-at-home directives).

### Policy and operational recommendations
- Establish cyber-security governance and culture
  - Create and maintain an effective cyber-security governance framework and foster a cyber security culture across institutions and counterparties.
- Vulnerability management and incident response
  - Maintain an effective vulnerability management program.
  - Develop and document an incident response plan.
- Harmonize ICT and cyber security measures with fiscal agents and banks
  - Coordinate with central bank and private banks acting as fiscal agents to harmonize ICT solutions and cyber security measures.
  - Incorporate dependencies on these counterparties into business continuity policies.
- National/federal level coordination for major threats
  - Coordinate directives, guidelines, and compliance requirements across government and critical financial infrastructure participants.
- Leverage mitigation and operational options (categories cited)
  - Prevention or avoidance: reduce or eliminate probability of events via systems and procedures.
  - Transference: pass risks to third parties via insurance/reinsurance, outsourcing, or financial arrangements.
  - Containment: limit impact through controls and escalation procedures, including an Incident Management Team (IMT).
  - Acceptance and recovery: resume operations using disaster recovery plans when events occur.
- Teleworking as a mitigation enabler
  - Use secure and encrypted internet connections, tele-conferencing platforms, and cloud storage to enable teleworking and reduce dependence on alternate physical operations sites.
  - Support telework arrangements with regulatory frameworks and robust ICT infrastructure to ensure statutory and operational viability.

### Key figures and timelines (as reported)
- 35 payment instructions worth of US$951 million (Central Bank of Bangladesh attack).
- First 5 transactions completed; remaining 30 blocked (Bangladesh incident).
- Between February 5 to 9 attackers withdrew US$81 million in total under fictitious identities (Bangladesh incident).
- March 2018: attempted SWIFT-based unauthorized transfers at Central Bank of Malaysia; no financial loss to BNM.
- US$10 million fraud via data breach at Norfund; fraud took place on March 16 and was discovered on April 30 (2020).

*Source: tnmea2021010 - Box 2. Cyber Risks for Public Financial Institutions (Technical Notes and Manuals 21/03 | 2021).*

### Box 4. ICT Solutions for Business Continuity under Teleworking

### Box 4. ICT Solutions for Business Continuity under Teleworking

### Country examples of ICT measures for teleworking
- Brazil:
  - Debt management operations relied on a virtual private network (VPN) with an external dedicated server and backup that was set up a year before the pandemic and tested in February 2020.
  - Issuance and debt service functions were executed remotely, using web-access to central securities depositories and web-based version of Bloomberg services.
  - Press reports and meeting were held virtually. 1
- Korea:
  - Korea Public Finance Information Services (KPFIS), managing the dBrain system (i.e., the IFMIS), used the Government VPN system to allow users to handle administrative affairs like an office as long as the user has an internet connection at home or abroad.
  - Authorities used cloud-based work data storage, established infrastructure for creating and editing documents remotely, strengthened and expanded chat services, and increased the use of portal announcements (notices and bulletins) via dBrain (digital budget accounting system). 2
- Portugal:
  - The Portuguese Treasury and Debt Management Agency, IGCP, set up VPN access to systems and acquired licenses to hold virtual meetings.
  - The firewall and network infrastructure were updated.
  - New hardware requirements (laptops, access points, webcams, microphones) were gradually met allowing all staff remote access to government systems. 3
- Turkey:
  - The Ministry of Treasury and Finance set up VPN access and remote desktop connections (for critical staff in the first place, then extended to all staff), established safe internet connection and put professional webcams/microphones to numerous meeting rooms for virtual meetings.
- USA:
  - The US Treasury maintained and tested “hot” fail-over operational sites. 4
- Common operational adjustments:
  - Authorities increased VPN capacity and bandwidth to deal with increased volume of users on VPN networks and to minimize latency issues and embraced a number of new virtual meeting technologies.
  - An example is the “Telework Enhancement Act of 2010” in USA, which requires executive agencies to incorporate telework into their “continuity of operations” plans and employees and managers to complete interactive telework training.

### Cybersecurity guidance and recommended controls for remote work
- High-level guidance:
  - To reap the benefits of ICT solutions without increasing risk exposure, treasuries need to implement strong security measures and identify critical information assets and infrastructure upon which they depend and have a documented ICT policy.
  - Experience suggests cyber risks are better mitigated by containing the threat at its source.
- Recommended measures to support the cybersecurity of remote work: 5
  - Authorities should quickly and effectively implement good practices and international technical standards applicable for secure remote working (e.g. NIST 800-46 Rev 2, BSI IT-Grundschutz Compendium, COBIT 2019, ISO 27000 series).
  - Remote access services and user profiles should be only activated when required.
  - Cloud usage should be based on detailed risk assessments.
  - Teleconferences should be run on vetted platforms and protected from unauthorized access.
  - Additional awareness campaigns on cybersecurity should be launched for all employees.
  - Robust controls over configurations at both ends of the remote connection should be implemented to prevent potential malicious use.
  - Entities should implement additional security controls for critical functions that are normally not allowed to work remotely.
  - Supervisors should reinforce the message that remote work increases cybersecurity risk, which must be addressed with strong controls.

### Devolution, fail-over sites, and continuity planning
- Devolution:
  - Devolution: setting up under a statutory delegation, executive order or power of attorney to transfer responsibilities from the primary staff of the treasury to other designated staff, alternate location, sub-ordinate agency or third party such as the central bank or other government agency the authority to undertake activities until the primary staff are able to resume these activities following a major incident.
  - Devolution would be activated through a significant incident such as the government’s declaration of a state of emergency.
  - For these instances, the authority should be very tightly defined with clear assignment of functions and time-periods to ensure that strong governance is maintained and there is no risk of fraud or corruption.
  - Devolution is a relatively complex risk mitigation strategy; a devolution plan can be prepared as a separate document to the BCP to provide the direction and guidance to the treasury that operations continue during any emergency with minimal disruption to essential functions. 20
- Fail-over sites:
  - “Fail-over” refers to switching to a stand-by system upon failure of the primary system.
  - A “hot” site is a near duplicate of the original site of the organization, with full computer systems and complete backups of data.
  - A “cold” site is a backup facility with little or no hardware equipment installed. 4

*Box 4. ICT Solutions for Business Continuity under Teleworking — tnmea2021010*

### Box 5. Devolution

### Box 5. Devolution

### Definition and rationale
- Devolution involves the transference of a critical operation to another party which could be permanent or for a limited period under a statutory delegation, executive order or power of attorney in order that this operation can continue following an incident without the involvement of the primary staff responsible for cash and debt management operations.
- Devolution can be more suitable for organizations with field and regional offices.
- The central bank is a main partner in cash and debt management as it is the fiscal agent and holder of main accounts, and therefore a natural candidate for devolution of cash and debt management functions.

### Operational considerations, triggers, and legal framework
- When using devolution as a risk mitigation option, the treasury should:
  - prepare a training program for the staff of the devolution partner on critical functions;
  - ensure that they have access to necessary ICT structure.
- Triggers, roles and responsibilities should be clearly defined.
  - Active triggers include a deliberate decision by the management of the treasury.
  - Passive triggers define conditions under which the partner organization assumes responsibilities.
- In many countries, devolution can necessitate amendments to finance and treasury legislation or regulations. These amendments can include delegations to cover activation and authorizations, including authorized personnel or signatories with procedures established and approved for all third parties.
- It is advisable that joint tests are conducted with key third-party providers to ensure that all parties understand their respective roles and can operate following an incident.

### Devolution examples
- Domestic securities issuance: assigning the authority to the central bank to conduct the auction of government treasury bills or bonds without the need for the treasury to be directly involved.
- Debt service payments: assigning the authority to the central bank or regional treasury offices to make debt service payments, particularly when the designated signatories and/or payment systems are unavailable when the payment deadline falls due.

### International practice and exercises
- The US Treasury conducts regular devolution exercises across the organizations involved in managing the treasury auctions. Plans foresee the devolution of certain activities to other units of the treasury should the primary unit for that task be not available due to a business disruption. While this has not been needed during 2020, plans are in place and are ready to be acted on should significant issues arise (in addition to work-from-home), such as technology failures or an inability to communicate between policymakers and operational staff.
- On October 24, 2020, an industry-wide testing was conducted to assess and verify the ability of firms, markets and utilities in the securities industry to operate through a crisis using a combination of primary, backup and recovery facilities and backup communications capabilities. As part of the test, a government securities auction was simulated (SIFMA, 2020).
- The US Treasury has in place a requirement that primary dealers maintain and test a geographically dispersed disaster recovery site and also perform functions from remote sites (at home) other than the disaster recovery site. In 2013, after a hurricane that led to business disruptions in financial firms in the New York area, primary dealers were asked to ensure that they had back-up sites outside Manhattan (OECD, 2020b).

### Related mitigation and ICT options (as presented in the Box)
- Straight-through-processing: making use of treasury and integrated financial management information systems that provide electronic processing from issuance to settlement (referred to as straight-through-processing or STP) with interfaces and connectivity to SWIFT and other payment systems.
- Software-as-a Service (SaaS): contracting a third-party software provider to host treasury systems and associated data in order to reduce IT support costs by outsourcing software maintenance and support to the SaaS provider under a subscription arrangement with a monthly or annual fee. Hardware support can also be outsourced (infrastructure-as-a-service).
  - Examples: the federal and some state governments in Australia and the central government and local government funding agency in New Zealand are using SaaS for their core treasury debt management system.
- Data centers: entering into an arrangement with a third party to host an alternate data center (which can be for the treasury alone, shared with the MoF, or for the whole of government) to enable replication of treasury systems and associated data.
  - Frequency of replication depends on time criticality: real-time mirroring may be required for active liability management and trading activities; most treasuries can operate with less frequent replication (often daily with the transfer of debt data to the data center overnight).
  - Ideally, connections to the alternate data center should be triangulated (through the central bank or another agency of the government) to minimize the risk of single point-to-point failure.
  - Increasing use of cloud storage solutions reduces the need for replication of debt management systems and associated data at an alternate data center.
- Contingent financial resources: issuing catastrophe (CAT) bonds, establishing a national catastrophe or contingency fund, or entering into a disaster risk financing and insurance (DRFI) program to provide a ready source of funds to respond immediately in the event of a major local or national disaster. Availability of contingent financing options reduce the time criticality of government auctions.

### Prerequisites and complementary measures for effective devolution
- Incorporating telework into the BCP.
- Upgrading ICT infrastructure.
- Establishing incident management and back-up teams for activation of the Disaster Recovery Plan (DRP).
- Installing and implementing tools and systems to identify and contain cyber-attacks.
- Reviewing and updating legal and regulatory frameworks, including orders of succession, delegations of authority, and service level agreements with the central bank and other key third parties.
- Conducting joint tests with key third-party providers.

### Selection of mitigation strategies and trade-offs
- Selection depends on scenario, impact, time criticality, budget constraint and availability of services in the jurisdiction.
- Preferred option is prevention or avoidance primarily through internal controls and replication of systems and data.
- If prevention is difficult or expensive, functions can be transferred to third parties (devolution).
- For major incidents beyond the treasury’s control, containment becomes the priority; if the incident escalates, the Incident Management Team (IMT) will activate the BCP.
- Cost-recovery time trade-off: cost to shorten recovery time can require significant investment in ICT systems, training etc. Example: cost of establishing and maintaining an alternate site for staff may not be justified relative to a “work from home” arrangement, which raises ICT security concerns that can be alleviated through secure and encrypted channels of communication and cloud storage.

### Table 3 (Mitigation Strategy Identification Example) — processes, scenarios, mitigation options
- Process: Debt Servicing
  - S1 Physical Infrastructure Inaccessible
    - Activation of DRP
    - Alternate site
    - Teleworking
    - Devolution
  - S2 ICT System Failure
    - Install backup or redundant systems
    - Alternate data center and replication
    - Activation of ICT DRP
    - Devolution
    - Software-as-a-Service
  - S3 Staff Unavailability
    - Alternate staff
    - Devolution
    - Teleworking
  - S4 Key Counterparty/Service Provider Failure
    - Straight-through-processing
    - Joint-tests

### Integration with BCP development and maintenance
- Devolution considerations are part of broader BCP development steps, including:
  - Step 3 (Developing the BCP): Activation procedures; management roles and incident management team; scenario planning; return to normalcy criteria.
  - Step 4 (Implementing and Maintaining the BCP): Budget provision; acceptance by senior management and business units; required approvals; integration into day-to-day operations through policy updates, training and regular testing.
- Activities to embed the BCP:
  - Communication: workshops to generate understanding and buy-in; explanation of the communication tree for incidents outside normal hours or when premises are inaccessible.
  - Training: initial and ongoing training plans for all business units, inclusion of senior management, and BCP training for new recruits and third parties where devolution is involved.
  - Scenario tests: in-house classroom exercises based on actual incidents and BIA scenarios.
  - Simulated live tests: simulated or actual live tests of operations at an alternative site.
- Tests should include preparedness of main counterparts, including the central bank and auction participants.

### Operational and procedural implications
- Business process reengineering may be necessary for mitigation options to be workable (for example, electronic signatories replacing physical signatures during BCP activation).
- Many governments still rely on manual approval processes; modern FMIS systems can enable automated workflows but may only be accessible from primary and secondary sites, not through VPN from homes.
- Decision making, command and approval processes can be reconsidered to enable continuity; some ex-ante controls could be simplified when the BCP is activated, replacing some pre-approval requirements with ex-post audits within a short timeframe.
- Business Process Analysis (BPA) is useful to identify effective mitigation strategies; improvements from BPA can reduce likelihood and impact of risks and help reduce mitigation costs.

### Practical recommendations and lessons from country experience
- Prepare and train devolution partners; ensure ICT access and legal delegations.
- Conduct joint tests and live simulations with counterparties and market participants.
- Use contingency financing to reduce time-critical pressures on auctions.
- Maintain the BCP as a live document with regular updates and tests.
- Short reference documents (e.g., pocket cards) are useful for staff during disruptions.
- Business impact analysis can be simplified focusing on time criticality of key processes.
- Not all processes must continue under all conditions; non-time-critical processes can be delayed.
- Maintain responsibility for BCP across all treasury staff; testing builds confidence and identifies deficiencies.

*Source: Box 5. Devolution, Technical Notes and Manuals 21/03 | 2021*

### ANNEX I. BCP TEMPLATE

### ANNEX I. BCP TEMPLATE

### Distribution List and References
- Include an up-to-date list of all plan locations and persons supplied with a copy of the plan.
- References and related documents: include all documents that have a bearing on your Business Continuity Plan.
- Template header example:
  - <insert name of the treasury> Business Continuity Plan
  - Date: dd/mm/yyyy

### SECTION 1 — Executive Summary and Objectives
- Executive Summary: the plan in miniature (usually one page or shorter); sufficient for a reader to get acquainted with the plan without reading the full document.
- Objectives (example): The objectives of this plan are to:
  - undertake risk management assessment
  - define and prioritize critical functions
  - detail immediate response to a critical incident
  - detail strategies and actions to be taken to enable treasury to continue operations
  - review and update the plan on a regular basis
- Appendices: record copy number, name, location, and relevant document titles.

### SECTION 2 — Business Impact Analysis (BIA)
- BIA output should be a table as in Annex Table 2.2 and cover at least these critical cash and debt management operations:
  - Debt Servicing (loans, securities, guarantees, on-lending)
  - Execution of Payment Requests (by public entities)
  - Daily Cash Flow Planning
  - Security Issuances via Auctions
  - Loan Contracting
- Complement BIA with Business Process Analysis as in Annex III; output should be a table as in Annex Table 3.1.

### SECTION 3 — Risk Mitigation
- Treasury selects the most cost effective and suitable risk treatment approach for each debt management function assessed via BIA, using options described at Step 2: Identify mitigation options of Section IV.
- See Table 3 for evaluation of several mitigation strategy options under different scenarios.
- Policy requirements:
  - Adopt approved mitigation strategies to manage/prevent incidents affecting essential/critical activities, processes and systems.
  - No essential/critical new business activities, processes and systems should be introduced until mitigation strategies have been implemented and tested.
  - The compliance manager is responsible for maintaining and ensuring compliance with BCP requirements.

### SECTION 4 — Incident Management Team, Response, and Recovery
- Incident Management Team:
  - Establish an incident management team to manage relocation and/or recovery if an incident impacts essential/critical treasury activities or necessitates relocation from the treasury office.
  - Use an incident management structure to ensure:
    - the efficient flow of information;
    - consistent decision making; and
    - effective communication of decisions.
- Emergency center:
  - If building evacuation or denial of access occurs, establish an emergency center at the evacuation assembly area or at a suitable alternate site.
  - Partial incidents may permit relocating affected staff to meeting rooms or other vacant space with support units' assistance.
- Response phases:
  - Evacuation and Containment: actions to contain the incident, assure staff safety, prevent further damage or loss and secure the treasury office.
  - Assessment and Decision: incident management team evaluates magnitude and decides course of action and/or recovery location; restore operations using standard operating policies and procedures if incident can be isolated and contained.
  - Information delivery: ensure staff are aware of their roles and receive clear, regular recovery information (return home or relocate to alternate site(s)).
  - Objective: minimize risk to treasury business activities by reducing or halting activities until recovery infrastructure is established; primary objective to re-establish critical activities within recovery time objectives.
  - Include an initial action plan (pocket card) as per Annex V.
- Recovery:
  - Defined as return to pre-emergency conditions; performing critical activities as soon as possible is primary focus.
  - Recovery planning should support ‘worst case’ scenarios and be modifiable according to degree of loss.
  - Recovery process includes:
    - developing strategies to recover business activities in the quickest possible time
    - identifying resources required to recover treasury’s operations
    - documenting previously identified RTO’s
    - listing person(s) responsible for each task and the expected completion date

### SECTION 5 — Rehearse, Maintain, and Review
- Rehearse the BCP regularly (training exercises) to ensure relevance and utility during an emergency.
- All new staff should receive basic business continuity training as part of orientation/induction.
- Assign training and maintenance tasks to a specific unit/manager.
- Exemplary maintenance activities and timeframes:
  - BCP documentation review and update: Six monthly
  - Technology recovery test: Six monthly
  - Staff familiarity training: Annually
  - Scenario (white board) testing: At least six monthly
  - Full test (simulated incident): At least annually
- Practical points:
  - Prepare a training schedule for all people who may be involved in an emergency at the site.
  - Pay attention to staff changes; use staff titles rather than individual names where possible.
  - Amend plan when organizational structure or suppliers/contractors change.
  - After an incident, review plan performance and identify improvements.
- Record templates:
  - Training Schedule: table for training date, training type, comments (example entry: dd/mm/yyyy — Evacuation drill — All personnel evacuated and accounted for within acceptable timeframe).
  - Review Schedule: table for review date, reason for review, changes made (example entry: dd/mm/yyyy — New personnel in new roles — Plan updated to reflect changes to roles and responsibilities).

---

### ANNEX II. BUSINESS IMPACT ANALYSIS METHODOLOGY

### BIA components
- A BIA needs to cover at least four components:
  - identification of possible scenarios/threats
  - evaluation of impacts on processes
  - estimation of likelihood of possible scenarios/threats
  - assessment of time criticality of disruptions

### Scenarios and duration categories
- Use impact and duration to assess threats; employ 3 basic time frames: hours (Intraday), days (Short-term), weeks (Medium-term).
- Annex Table 2.1 categorizes 12 scenarios under four main scenario themes (S1–S4) and three duration columns:
  - S1 Physical Infrastructure Inaccessible: S1.1 (Intraday), S1.2 (Short-term), S1.3 (Medium-term)
  - S2 ICT System Failure (main system): S2.1, S2.2, S2.3
  - S3 Staff Unavailability: S3.1, S3.2, S3.3
  - S4 Key Counterparty/Service Provider Failure: S4.1, S4.2, S4.3

### Impact, Likelihood, and Time Criticality scaling (3x3)
- Impact definitions:
  - High: Risks will cause extensive damage and have a long-term effect
  - Medium: Risks may cause considerable loss or damage
  - Low: Risks have minimal/minor damage and have no long-term effect
- Likelihood definitions:
  - High: Likely to occur often
  - Medium: May occur intermittently
  - Low: Not expected to occur but possible
- Time Criticality assessed via Maximum Tolerable Period of Disruption (MTPD) using three MTPD bands:
  - MTPD<1 day, meaning the process needs to be recovered in a few hours
  - 1≤MTPD≤5 days, meaning the process needs to be recovered in a few days
  - 5<MTPD≤30 days, meaning the process needs to be recovered in a few weeks
- Time Criticality score assignment against disruption durations (Intraday, Short-term, Medium-term):
  - Low if MTPD>Duration of Disruption
  - Medium if MTPD=Duration of Disruption
  - High if MTPD<Duration of Disruption
- Example logic:
  - A process with 1≤MTPD≤5 days: Low for intraday disruption; High for medium-term disruption.

### Combined Risk Score calculation (3-scale approach)
- For each process and scenario answer:
  1) What is the impact of the scenario on the process?
  2) What is the likelihood of the scenario happening?
  3) How is the time criticality of the process?
- Combined Risk Score format: concatenation of Impact-Likelihood-Time Criticality (e.g., HiMeHi, HiMeMe, MeMeHi).
- Criteria for deeming a process critical:
  - Combined score has at least 2 High factors (e.g., HiHiLo, MeHiHi), or
  - 1 High factor and 2 Medium factors (e.g., MeHiMe, MeMeHi).
- BCP coverage: critical processes and relevant scenarios need to be covered; rapid recovery procedures required when time criticality is High (indicated by the last two letters).
- Alternatives:
  - Detailed approach: identify risks as HiHi, HiMe, MeMe etc. via Annex Table 2.3 risk assessment matrix; processes with a risk score of 9 and 6 can be identified as critical.
  - A 5x5 scale can be used if desired.

### Additional analytical tools
- Annex Table 2.2: Combined Risk Score Calculation template for processes P1...P(n) across scenarios S1.1...S4.3; capture Impact, Likelihood, Time Criticality, Combined Risk Score.
- More granular time criticality analysis:
  - Assess MTPDs and RTOs for each step of critical processes at high frequency (Annex Table 2.4).
  - Granularity example for bond auction process provided in Annex Table 2.5 with exact stage timings and RTOs (e.g., Auction 08:00–10:30 Receive Bids — MTPD 1 hour — RTO 15 mins; Post-auction T + 1 Settle Auction — MTPD 6 hours — RTO 2 hours).
- BIA is iterative: review regularly (i.e. quarterly, yearly) and/or whenever necessary to reflect changing conditions.

---

### ANNEX III. PROCESS ANALYSIS TEMPLATE/EXAMPLE

### Process Analysis and Workflow (Annex Table 3.1 example)
- Example process: External Securities Servicing Process
  - Unit Responsible: Debt Transactions Unit
  - Key elements to capture in template:
    - Inputs of the Process
    - Person Responsible
    - Workflow
    - Control Criteria
    - Required Action/Resource
    - Output of the Process
    - Critical Resources
    - Performance Criteria
    - Processes Affected by / Affecting the Process
    - Risks of the Process
- Example workflow steps (extracted from the template example):
  - Send payment notice (Fiscal agent and paying agent → Back office desk officer)
  - Check payment advice; Approve payment advice; Send payment advice to accountant general
  - Check payment order; Authorize payment order; Send payment order to Central Bank
  - Setup payment in SWIFT; Check payment in SWIFT; Authorize payment in SWIFT; Send payment information to DMO; Receive payment confirmation
- Example critical resources and systems:
  - Staff, Infrastructure, Systems
  - Debt Recording System, IFMIS, Central Bank Information System, SWIFT Software
- Example risks (as listed in the template):
  - System failures
  - Network failures
  - Counterparty failures (Central Bank)
  - Disruptions longer than 4 hours
  - Staff mistakes
- Template purpose:
  - Assess relevant inputs/outputs, critical resources, performance criteria, inter-process impacts, and risks.
  - Clarify person in charge for each step, map process, establish control criteria, and identify necessary actions/resources to identify vulnerabilities and improvements.

*Source: Authors — ANNEX I. BCP TEMPLATE (Technical Notes and Manuals 21/03 | 2021)*

### Annex II meets the BIA requirements of the ISO 22301:2019 standards.

### Annex II meets the BIA requirements of the ISO 22301:2019 standards.

### Business Impact Analysis (BIA) alignment and scope
- Reference: clause “8.2.2 Business Impact Analysis” of the ISO 22301:2019 standards.
- Note: Compliance with ISO 22301:2019 is distinct from meeting BIA requirements; compliance can only be assessed by relevant ISO accredited institutions after inspection.
- Key principle: The whole end-to-end process must be considered for risk identification and mitigation, even when specific steps are outside the treasury’s direct control (example: use of central bank as fiscal and paying agent).
- Identified risk example: If the central bank (acting as fiscal/paying agent) fails to make a payment by the due date despite a timely payment order, the treasury retains ultimate responsibility and faces reputational and financial impacts. This is categorized as a “Key Counterparty / Service Provider Failure” scenario (see Section IV and Table 1).

### External Securities Servicing Process — process analysis and critical resources
- Process name: External Securities Servicing Process.
- Unit Responsible: Debt Transactions Unit.
- Process description: Preparation of payment orders and fulfilling all prior steps to complete payment obligations of the Treasury in full and on time.
- Inputs / Outputs / Workflow highlights:
  - Inputs: Issuance info; Payment notices; Exchange rates; Interest rates; Payment order.
  - Outputs: Delivery of payment order without any delays and mistakes; Payment confirmation.
  - Workflow control criteria / required actions:
    - Send payment notice.
    - Check/approve payment advice.
    - Check/authorize Payment Order.
    - Setup payment in SWIFT.
    - Check/authorize payment in SWIFT.
    - Send payment information to DMO.
- Critical resources (as listed):
  - Staff: Back office: Desk Officer, Supervisor; Head of DMO; Accounting Unit: Desk officer, supervisor, accountant general.
  - Infrastructure: Computers with access to systems and common drives (VPN).
  - Systems: Debt Recording System; IFMIS; Central Bank Information System; SWIFT Software; Electronic delivery mechanisms between systems.
  - Information artifacts: Info at the Debt Recording System; Approve on Debt Recording System which delivers it to Accounting Unit electronically; Approve on IFMIS which delivers it to Central Bank electronically; Electronic delivery of the payment confirmation to Accounting Unit; Crosscheck with Central Bank Registry; Check balance of the payment account.
- Processes affected by / affecting:
  - Debt servicing process of Central Bank.
  - External securities issuance process.
- Risks of the process (explicitly listed):
  - System failures.
  - Network failures.
  - Counterparty failures (Central Bank).
  - Disruptions longer than 4 hours.
  - Staff mistakes.
  - Identified scenario handling: treat as “Key Counterparty / Service Provider Failure” in contingency planning.

### Modified workflow under Business Continuity Planning (BCP)
- Rationale: Increased digitization/digitalization, ICT developments, and COVID-19 precedents warrant modifying process flows to depend less on physical infrastructure.
- Approach:
  - Shorten and optimize process flows in the BCP rather than replicating the same workflow at an alternate operations site.
  - Provide a modified version of Annex Table 3.1 (Annex Table 3.2) that drops/unifies several steps and reduces critical resources.
  - Pre-authorize necessary regulations/authorizations in advance to enable flexible handling of distressed conditions.

### Incident Management Team (IMT) structure and roles
- Leadership and composition:
  - IMT is best headed by the head of risk management (often head of the middle office).
  - IMT draws from risk management and liaises with business units (heads of directorates or critical representatives).
  - IMT liaises with executive (heads of the treasury and the MoF) for approvals/authorizations when required.
  - Support units/resources (ICT, personnel, media liaison) can be called from MoF or treasury.
- Organogram elements (as presented in Annex Figure 4.1):
  - Incident Management Team (Treasury) — Head of Risk Management.
  - Business Units — Heads of Directorates / Directorate Representatives.
  - Executive — Head of Treasury; MoF Executive.
  - Support: Treasury Systems Administrator; Treasury IMT staff; MoF Media Liaison Person; MoF ICT staff; Administration (Admin/HR staff); Building Services; Floor Representatives.
- IMT responsibilities (examples from pocket-card and role descriptions):
  - Ensure the Business Continuity Plan has been activated.
  - Oversee implementation of response and recovery sections.
  - Determine need for and activate alternate operation site and continuity tasks.
  - Communicate with key stakeholders as needed.
  - Ensure BCP activation meets statutory regulations and arrange delegated authorities for devolution of functions.
  - Oversee recovery of critical systems and determine need for alternate system access.

### Pocket card, emergency kit, and operational preparedness
- Pocket card purpose: Foldable A4 content to credit-card size for staff; Side 1: general info for all treasury staff; Side 2: business-unit-specific info (contacts, checklist).
- Emergency contact categories listed (examples):
  - AFTER HOURS EMERGENCIES; OTHER EMERGENCY CONTACTS; FIRE ALARM; EARTHQUAKE; ESSENTIAL NUMBERS; EVACUATION ASSEMBLY AREA; FIRST AID AND CIVIL DEFENSE.
- Emergency kit contents (explicit items):
  - Computer back-up tapes/disks/USB memory sticks or flash drives.
  - Spare keys/security codes.
  - Message pads and flip chart.
  - Marker pens (for temporary signs).
  - General stationery (pens, paper, etc).
  - Mobile telephone with credit available, plus charger.
- Document checklist to store with kit:
  - Business Continuity Plan.
  - List of employees with contact details: home and mobile numbers, e-mail addresses, next-of-kin contact details.
  - Procedure manuals.
  - Lists of customer and supplier details.
  - Contact details for emergency services, utility companies, local authorities.
  - Building site plan (including gas, electricity and water shut off points).
  - Evacuation plan.
  - Latest stock and equipment inventory.
  - Bank account details.
- Notes on kit handling:
  - Store safely on-site and off-site.
  - Ensure items are checked regularly, kept up-to-date, and in good working order.
- Evacuation and on-premises guidance (selected instructions retained verbatim):
  - If you are on the premises after hours and an evacuation is ordered, ensure that the Director or delegate is informed.
  - If you are denied access to the premises when you arrive at work, go to the evacuation assembly area and await further instructions.
  - If you hear of an incident affecting the premises, remain at home. Make contact with Director or delegate if possible. Prepare for possible relocation to another site.
  - Conclude phone calls immediately.
  - Take with you only essential portable items that may facilitate off-site recovery that are not a hindrance to evacuation.
  - Escort visitors to exit.
  - Ensure doors are closed behind you.
  - Evacuate the premises using nearest exit.
  - Assemble outside premises.
  - DO NOT disperse – await instructions.

### Scenarios for BCP testing and live simulated tests
- Guidance: Simulated live tests should be conducted in real-time when possible; avoid testing during significant or critical activities unless safeguards exist. Tests should evolve as information is released in sequence.
- Scenario 1: System Failure
  - Event: System crash at 4:00pm affecting all treasury servers.
  - IT assessment: It will take the rest of the day and all night at least to replace the servers and reinstall OS, applications and data from the most recent back-up source.
  - Complication: Head and Deputy Head of IT and Head of the Risk Management Unit are out of the building at the time of the incident.
- Scenario 2: Building Evacuation
  - Event time: 11:00 am.
  - Municipal authorities require complete evacuation due to potential risk of an explosion.
  - Impact: Several blocks cordoned off; authorities expect it may take more than one day to safeguard the area.
  - Context: Incident occurs on the day of a government securities auction.
- Scenario 3: Damage to Premises
  - Event: Overnight fire causing serious damage (smoke and water); fire authorities will not allow access due to structural risk.
  - Staff arriving at 7:30 am first become aware of the damage.
- Scenario 4: Local Pandemic
  - Reference: Similar to H1N1 virus of 2009.
  - Staff behavior: Some staff opt to stay at home; staff showing signs are sent home.
  - Impact: By the end of the week, at least 50% of staff are affected or have opted to stay at home.
  - Isolation: Staff required to stay at home for at least 14 days from diagnosis.
- Scenario 5: COVID-19 Pandemic
  - Event: Several staff test positive following a meeting where all staff were present.
  - Authorities' measures:
    - Staff that test positive relocated to a quarantine facility set up by government.
    - Staff not positive required to isolate at home or at government isolation facility.
  - Duration: Staff required to stay in isolation for 2 weeks.
  - Testing cadence: They are tested every 3 days and any that return a positive test are transferred to the quarantine area.
  - Result: No staff in the treasury able to return to work in the office for 2 weeks.
  - Connectivity: Staff will have internet and phone connectivity at the quarantine facility.
  - Premises: Health authorities require treasury’s premises to be thoroughly sanitized and cleaned.

- Simulated Live Test #1
  - Event: Substation explosion at 9:45 am causing central city power outage.
  - Restoration estimate: At least 1 week to repair and restore electricity completely.
  - Treasury constraints: Diesel supply for generator very low; expected to last 3-4 hours.
  - Operational decision: Generator reserved to power the two computer server rooms while diesel lasts to enable IT to run critical systems and prepare to relocate to the data center.
  - Telecom impact: Inner-city mobile telephone transmitting towers affected; mobile phone coverage limited. Usage to be minimized (text rather than voice).
  - Wider economic impact: Businesses and food outlets affected due to refrigeration losses.
  - Action: Treasury called an emergency meeting to activate the BCP.
- Simulated Live Test #2
  - Event: Serious explosion on treasury premises around 5 .30pm on a working day.
  - Staff distribution at event time: Around 50% in office; 25% had left for the day; 25% out on business or on leave.
  - Immediate consequences:
    - Dense smoke; windows blown out; records and equipment strewn.
    - Half of staff present injured, some critically; others possibly killed.
    - Building alarms and sprinklers operating; evacuation initiated.
  - Response timeline:
    - By 5:50 pm fire service and ambulances have arrived and cleared injured staff.
    - Building sealed pending investigation; cordoned off for at least 72 hours.
    - IMT convened at assembly area to activate disaster recovery plan and relocation strategy in consultation with Executive team.
    - By 8:00 am the following morning IMT advised explosion was caused by a bomb; police and media actively seeking information; premises cordoned off.
  - Personnel impact: Several staff members confirmed dead; uninjured staff accounted for at assembly area; injured treated or admitted to hospital.
  - Communications: Staff who had left office may return to area after media/social reports; IMT notifies staff of developments and assigns functions.

*Source: tnmea2021010 - Annex II meets the BIA requirements of the ISO 22301:2019 standards.*

### REFERENCES

### tnmea2021010 - REFERENCES

### References
- Adelmann F., Elliot J., Ergen I., Gaidosch T., Jenkinson N., Khiaonarong T., Morozova A., Schwarz N., Wilson C., 2020, Cyber Risk and Financial Stability: It’s a Small World After All. IMF Discussion Note SDN/20/07, Washington, DC. https://www.imf.org/en/Publications/Staff-Discussion-Notes/Issues/2020/12/04/Cyber-Risk-and-Financial-Stability-Its-a-Small-World-After-All-48622.
- Adelmann F., Gaidosch T., 2020, Cybersecurity of Remote Work During the Pandemic, IMF Monetary and Capital Market, Special Series on COVID-19. International Monetary Fund. Washington, DC. https://www.imf.org/~/media/Files/Publications/covid19-special-notes/en-special-series-on-covid-19-cybersecurity-of-remote-work-during-pandemic.ashx.
- Allison C., 2019, Anatomy of a Bank Heist – What Exactly Happened when $81 million Disappeared from a Bangladeshi Bank, and What Does it Mean for SWIFT? March 1, 2019, accessed on November 11, 2020. https://fin.plaid.com/articles/anatomy-of-a-bank-heist.
- Australian Government Department of Health, 2019, Australian Health Management Plan for Pandemic Influenza. https://www1.health.gov.au/internet/main/publishing.nsf/Content/519F9392797E2DDCCA257D47001B9948/$File/w-AHMPPI-2019.PDF.
- Australia National Audit Office (ANAO), 2014, Australia National Audit Office Report No.6 2014-15 Performance Audit, Business Continuity Management. https://www.anao.gov.au/sites/default/files/ANAO_Report_2014-2015_06.pdf.
- Australian Office of Financial Management (AOFM), 2016. Australian Office of Financial Management Annual Report 2015-16. October. Canberra. https://www.aofm.gov.au/sites/default/files/2019-05/aofm-annual-report-2015-16.pdf.
- Bank for International Settlements (BIS), 2021a, Basel Committee on Banking Supervision, Principles for Operational Resilience. March 2021. Basel. https://www.bis.org/bcbs/publ/d516.pdf.
- Bank for International Settlements (BIS), 2021b, Basel Committee on Banking Supervision, Revisions to the Principles for the Sound Management of Operational Risk. March 2021. Basel. https://www.bis.org/bcbs/publ/d515.pdf.
- Bank for International Settlements (BIS), 2021c, BIS Bulletin no:37. COVID-19 and Cyber Risk in the Financial Sector. 14 January 2021. https://www.bis.org/publ/bisbull37.pdf.
- Bank Negara Malaysia (BNM), 2018, Bank Negara Malaysia Press Release 29 Mar 2018. Kuala Lumpur. https://www.bnm.gov.my/-/cybersecurity-incident-involving-the-use-of-falsified-swift-messages.
- Brondolo, J, Aslett, J, and Komoso, A., 2020, Tax Administration: Designing a Business Continuity Plan for an Epidemic, IMF Technical Notes and Manuals TNM 2020001, International Monetary Fund, Washington DC. https://www.imf.org/en/Publications/TNM/Issues/2020/11/10/Tax-Administration-Designing-a-Business-Continuity-Plan-for-an-Epidemic-49838.
- Business Continuity Management (BCM) Institute, 2020, BCM Institute Glossary, accessed on: November 15, 2020. https://www.bcmpedia.org/wiki/Maximum_Tolerable_Period_of_Disruption_(MTPOD).
- Check Point Research. 2020. Cyber Attack Trends: 2020 Mid-Year Report. July 2020. https://research.checkpoint.com/2020/cyber-attack-trends-2020-mid-year-report/.
- Federal Emergency Management Agency (FEMA), 2018, Federal Emergency Management Agency National Continuity Programs, Continuity Guidance Circular 2018. Hyattsville. https://www.fema.gov/sites/default/files/2020-10/continuity-guidance-circular-2018.pdf.
- Federal Emergency Management Agency (FEMA), 2019a, Business Process Analysis and Business Impact Analysis User Guide. July 2019. https://www.fema.gov/sites/default/files/2020-07/fema_BPA-BIA-Users-Guide_070119.pdf.
- Federal Emergency Management Agency (FEMA), 2019b, Federal Emergency Management Agency National Continuity Programs, Devolution Plan/Annex Template and Instructions 2019. Hyattsville. https://www.fema.gov/emergency-managers/national-preparedness/continuity/toolkit/brochures.
- Financial Stability Board, 2018, Cyber Lexicon. 12 November 2018. https://www.fsb.org/2018/11/cyber-lexicon /.
- Government of Canada, 2013. Office of Critical Infrastructure Protection and Emergency Preparedness. A Guide to Business Continuity Planning. Ottawa. https://www.gov.mb.ca/emo/pdfs/bcont_e.pdf.
- Government of France, 2013, Secrétariat Général de la Défense et de la Sécurité Nationale. Guide Pour Réaliser un Plan de Continuité D’activité. Paris. http://www.sgdsn.gouv.fr/uploads/2016/10/guide-pca-sgdsn-110613-normal.pdf.
- Hämäläinen, M., Mäntylä, V., and Putkonen, P., 2018, Case Study: Bangladesh Bank Heist, ELEC-E7470—Cybersecurity Course Notes, Aalto University. https://www.coursehero.com/file/37803306/Bangladesh-Bank-Heistpdf/. Accessed on October 26, 2020.
- International Monetary Fund, 2017, State-Contingent Debt Instruments for Sovereigns. IMF Policy Paper. May 2017. Washington D.C. https://www.imf.org/en/Publications/Policy-Papers/Issues/2017/05/19/pp032317state-contingent-debt-instruments-for-sovereigns.
- International Organization for Standardization (ISO), 2019, ISO 22301:2019, ISO Security and resilience—Business continuity management systems—Requirements. https://www.iso.org/standard/75106.html.
- Korea Public Finance Information Service (KFPIS), 2020, Korea Public Finance Information Service, KPFIS Response to COVID 19: Learning from dBrain Operational Resiliency during Pandemic, 16 June 2020. https://olc.worldbank.org/content/10korea-office-bbl-kpfis-response-covid-19-learning-dbrain-resilience-0.
- Lindstedt, D. and Armour, M., 2017, Adaptive Business Continuity: A New Approach, A Rothstein Publishing Collection eBook. https://www.rothstein.com/adaptive-business-continuity/.
- Magnusson, T., Prasad, A., and Storkey, I., 2010, Guidance for Operational Risk Management in Government Debt Management. March. The World Bank, Washington, DC. https://openknowledge.worldbank.org/handle/10986/27822.
- New Zealand Government, 2015, The Guide to the National Civil Defence Emergency Management Plan. https://www.civildefence.govt.nz/assets/guide-to-the-national-cdem-plan/Guide-to-the-National-CDEM-Plan-2015.pdf.
- New Zealand Ministry of Health, 2017, New Zealand Influenza Pandemic Plan: A framework for action. August. Wellington. https://www.health.govt.nz/system/files/documents/publications/influenza-pandemic-plan-framework-action-2nd-edn-aug17.pdf.
- Nkhata S., 2017, Debt Records and Operational Risk – Support Available from International Organizations. Presentation at the 11th UNCTAD Debt Management Conference. November 13-15, 2017. Geneva. https://unctad.org/system/files/non-official-document/2017_p9_nkhata.pdf.
- Norfund. 2020. Press Release from Norfund. 13 May 2020. Oslo. https://www.norfund.no/app/uploads/2020/05/Press-release-13052020.pdf.
- OECD, 2020a, OECD Sovereign Borrowing Outlook. OECD Publishing. Paris. https://www.oecd.org/finance/Sovereign-Borrowing-Outlook-in-OECD-Countries-2020.pdf.
- OECD, 2020b, Virtual Joint Meeting of the Working Party on Debt Management and Global Forum on Public Debt Management, Agenda Item 4, Operational Risk Management and Business Continuity, 12 November 2020. Paris. https://www.oecd.org/daf/fin/public-debt/Joint-Meeting-WPDM-Global-Forum-PDM-2020-Agenda.pdf.
- OECD, 2021, OECD Sovereign Borrowing Outlook. OECD Publishing. Paris. https://www.oecd.org/daf/fin/public-debt/Sovereign-Borrowing-Outlook-in-OECD-Countries-2021.pdf.
- Pan-Canadian Public Health Network, 2018, Canadian Pandemic Influenza Preparedness: Planning Guidance for the Health Sector. Canada. https://www.canada.ca/content/dam/phac-aspc/migration/phac-aspc/cpip-pclcpi/assets/pdf/report-rapport-02-2018-eng.pdf.
- Proite A., Secunho L., Cabral R., 2020, Debt Management Under Extreme Circumstances: Brazil’s Reactions to Covid-19 Early Events. Presentation at the World Bank Webinar. 9 April 2020. The World Bank. Washington, DC.
- Securities Industry and Financial Markets Association (SIFMA), 2020, Press Release. SIFMA Statement on Successful Completion of Industry-Wide Business Continuity Test. October 26, 2020. New York. https://www.sifma.org/resources/news/sifma-statement-on-successful-completion-of-industry-wide-business-continuity-test/.
- Storkey I., 2011, Operational Risk Management and Business Continuity Planning for Modern State Treasuries, IMF Technical Notes and Manuals TNM 1105, Washington, DC. https://www.imf.org/en/Publications/TNM/Issues/2016/12/31/Operational-Risk-Management-and-Business-Continuity-Planning-for-Modern-State-Treasuries-25298.
- The Guardian, 2016, Spelling mistake prevented hackers taking $1bn in bank heist, March 10, 2016, accessed on: November 11, 2020. https://www.theguardian.com/business/2016/mar/10/spelling-mistake-prevented-bank-heist.
- The World Bank, 2020, Debt Management Facility: 10-Year Retrospective 2008-2018. The World Bank. December. Washington, DC. http://documents1.worldbank.org/curated/en/387981607701888048/pdf/Debt-Management-Facility-10-Year-Retrospective-2008-2018.pdf.
- Turkey Ministry of Treasury and Finance, 2014, Public Debt Management Report (PDMR). Republic of Turkey, July 2014, Ankara. https://ms.hmb.gov.tr/uploads/sites/2/2018/12/Public-Debt-Management-Report-2014.pdf.
- Uganda Ministry of Finance, Planning and Economic Development. 2020. Press Release. Ministry of Finance Business Continuity Plan for COVID-19. March 27, 2020. Kampala. https://www.finance.go.ug/sites/default/files/press/MoFPED%20-BCP%20Advisory%20%20%281%29.pdf.
- United Kingdom Department of Health, 2012, Health and Social Care Influenza Pandemic Preparedness and Response. April 2012. London. https://assets.publishing.service.gov.uk/government/uploads/system/uploads/attachment_data/file/213696/dh_133656.pdf.

*tnmea2021010 - REFERENCES.*

---


_Source: https://www.imf.org/-/media/files/publications/tnm/2021/english/tnmea2021010.pdf_
