All regulations & standards
Europe & UK · Regulation & standard

EBA ICT & Security Risk Guidelines scenario testing with simulations

What is EBA ICT & Security Risk Guidelines?

The EBA Guidelines on ICT and security risk management require regular testing of business continuity plans, including scenario-based assessments. Supervisors still reference them alongside DORA.

iluminr simulations let teams rehearse the decisions EBA ICT & Security Risk Guidelines cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.

Build a 12-month EBA ICT & Security Risk Guidelines programOpen in the catalogue

Simulations mapped to EBA ICT & Security Risk Guidelines

A boardroom at night, illustrating the Green Light: AI Board Governance MicrosimulationAI RiskGreen Light: AI Board GovernanceThis Microsimulation builds your awareness of director accountabilities when a company deploys AI into customer-facing operations. You will be asked to evaluate an AI deployment proposal under commercial pressure, navigate conflicting advice from executives, and test how governance, documentation and disclosure expectations apply when things go wrong. The scenario is based on real-world AI governance and D&O risk patterns faced by organizations across sectors.Phone call in the dark, illustrating the Bracing for Impact: Communications Test MicrosimulationCyber & DataBracing for Impact: Communications TestTest your organization's ability to send timely Emergency Notifications in response to a sophisticated, self-learning malware threat that targets critical infrastructure.AI neural network visualization, illustrating the Breached: AI IP Leak MicrosimulationAI RiskBreached: AI IP LeakRespond to a sensitive data leak involving AI-generated content, focusing on incident assessments, situational awareness, and securing communication protocols.Lightning storm over a city, illustrating the Connectivity Down: Severe Weather MicrosimulationThird-Party & TechnologyConnectivity Down: Severe WeatherRespond to severe weather-induced operational disruptions, including widespread internet outages, by verifying role responsibilities and ensuring continuity in communications and operations.Data center servers in the dark, illustrating the Core Platform Outage: Rollback MicrosimulationThird-Party & TechnologyCore Platform Outage: RollbackA critical platform update turns into a live-fire incident as a scheduled patch unexpectedly brings down key systems. Participants must navigate real-time service degradation, mounting customer pressure, and rollback decisions under duress. This Microsimulation tests cross-functional coordination, incident escalation, and communication flow - providing vital validation of operational resilience, rollback protocols, and regulatory compliance readiness.Code on a dark screen, illustrating the Data Breach: Major Leak MicrosimulationCyber & DataData Breach: Major LeakA massive data breach has struck some of the world’s largest organizations, including your own, leading to the potential compromise of sensitive personal information. The breach has exposed the names, phone numbers, and addresses of millions of customers, raising immediate concerns about privacy, identity theft, and the security of your data handling practices.Digitally distorted face, illustrating the Deepfake Threat: Cyber Attack MicrosimulationAI RiskDeepfake Threat: Cyber AttackYour organization grapples with an AI-driven cyber-attack, where advanced deepfake technology is being used to generate highly convincing fraudulent communications. This attack triggers a governance breakdown, posing severe risks to the organization’s reputation and operational integrity. --- [EngUS] Your organization grapples with an AI-driven cyber-attack, where advanced deepfake technology is being used to generate highly convincing fraudulent communications. This attack triggers a governance breakdown, posing severe risks to the organization’s reputation and operational integrity.A broken chain, illustrating the Exit Plan: Vendor Insolvency MicrosimulationThird-Party & TechnologyExit Plan: Vendor InsolvencyA critical third-party vendor has filed for insolvency, causing both operational and data losses. Can your team execute the exit plan under pressure?Code on a dark screen, illustrating the Extortion: Ransomware Invasion MicrosimulationCyber & DataExtortion: Ransomware InvasionAddress a widespread ransomware attack demanding cryptocurrency payments, focusing on stakeholder communication and restoring operational control.Code on a dark screen, illustrating the Inside Job: Data Breach MicrosimulationCyber & DataInside Job: Data BreachNavigate the high-stakes initial response to a sophisticated insider threat that has compromised sensitive organizational data, testing your incident response protocols when the threat comes from within.AI neural network visualization, illustrating the Poisoned: Data Corruption MicrosimulationAI RiskPoisoned: Data CorruptionAssess and mitigate the impact of a sophisticated data poisoning cyber-attack that has corrupted critical operational data and disrupted decision-making processes.Ripples spreading across dark water, illustrating the Ripple Effect: Fourth-Party Fallout MicrosimulationThird-Party & TechnologyRipple Effect: Fourth-Party FalloutA critical system failure has occurred in your supply chain, creating significant operational impacts. Your third-party vendor experienced a service outage caused by a vulnerability introduced through an undetected AI-driven update in their supplier's systems. This failure has cascaded through your supplier's network, resulting in widespread service disruptions that are now affecting your business operations and customers.Trading screens in the dark, illustrating the Trading Halt: Ransomware Chaos MicrosimulationCyber & DataTrading Halt: Ransomware ChaosAddress a major ransomware attack causing a service outage, suspected to be state-sponsored, by coordinating with cybersecurity experts and effectively communicating with stakeholders.Shipping containers at a port, illustrating the Trapped: Vendor Modern Slavery MicrosimulationThird-Party & TechnologyTrapped: Vendor Modern SlaveryNavigate the ethical, legal, and operational challenges posed by a tech supplier embroiled in a modern slavery scandal, focusing on incident assessment and communication strategies.Data center servers in the dark, illustrating the Vendor Outage: System Down MicrosimulationThird-Party & TechnologyVendor Outage: System DownRespond to a critical vendor cyber-attack that has disrupted essential services, focusing on business impact assessment, data review, and immediate contingency actions.AI neural network visualization, illustrating the Fairplay: AI Bias in a Critical Service MicrosimulationAI RiskFairplay: AI Bias in a Critical ServiceAddress the fallout from AI-driven bias in critical business services, focusing on managing stakeholder concerns and reassessing operational fairness.Emergency lights at night, illustrating the Digital Deceit: Workplace Threat MicrosimulationAI RiskDigital Deceit: Workplace ThreatA deepfake video falsely depicting the CEO making controversial remarks has been traced back to an employee's corporate laptop credentials. The video is circulating online, causing backlash, and prompting an urgent response to mitigate reputational damage and address the misuse of AI. --- Formerly titled 'Deepfake: Workplace Safety'Code on a dark screen, illustrating the Double Tap: Cyber Attack MicrosimulationCyber & DataDouble Tap: Cyber AttackA major information services provider faces a cyber crisis, leading to system outages, regulatory scrutiny, and eroded client trust. Participants will manage rapid response adjustments, client communication, and rebuilding credibility under intense pressure.Code on a dark screen, illustrating the Evolved: Adaptive Malware MicrosimulationCyber & DataEvolved: Adaptive MalwareA sophisticated form of malware has caused disruption across global health services, telecommunication and technology providers.AI neural network visualization, illustrating the Trained: AI Bias in Hiring MicrosimulationAI RiskTrained: AI Bias in HiringA tech company gets shutdown over AI bias allegations, disrupting global recruitment processes.Phone call in the dark, illustrating the Vished: Customer & Regulatory Impacts MicrosimulationCyber & DataVished: Customer & Regulatory ImpactsA convincing voice-phishing call gives attackers a foothold, with consequences for customers and regulators. Assess the incident, identify the critical business functions at risk, and work through your regulatory obligations.Code on a dark screen, illustrating the Wage Gap: Data Breach Fallout MicrosimulationCyber & DataWage Gap: Data Breach FalloutAddress the aftermath of a data breach revealing pay inequity, focusing on stakeholder engagement, implementing corrective measures, and restoring organizational trust.AI neural network visualization, illustrating the Agent Autonomous: Customer Service MicrosimulationAI RiskAgent Autonomous: Customer ServiceDeveloped to explore the adoption of Agentic AI as part of a severe but plausible threat impacting a Critical Operation.AI agent profile cards over a glowing network, illustrating the Agent Down MicrosimulationAI RiskAgent Down: AI Agent FailureA forward-thinking Microsimulation that explores the potential impacts and response priorities associated with agentic AI in critical services.AI neural network visualization, illustrating the AI Lies: Fact vs Fiction MicrosimulationAI RiskAI Lies: Fact vs FictionAI-generated misinformation about your organization spreads faster than you can verify it. Separate fact from fiction, decide what to say publicly, and protect trust while the story is still moving.Red warning sign reading breached, illustrating the Plan Under Pressure: Cyber Incident MicrosimulationCyber & DataPlan Under Pressure: Cyber IncidentA confirmed disruption is unfolding. You're drawn into the early response and asked whether a formal plan should be activated.Red padlocks over streams of code, illustrating the Account Takeover: Containment & Response MicrosimulationCyber & DataAccount Takeover: Containment & ResponseA suspected account compromise points to a data breach. Contain it, escalate it and coordinate across functions.Glowing AI brain and doorway in a purple digital space, illustrating the Model Switch: AI Service Outage MicrosimulationAI RiskModel Switch: AI Service OutageAn issue affecting a foundational AI service triggers a wave of questions. Decide what matters, what doesn't and what to do next.AI chip connected to glowing data nodes, illustrating the AI Washing: Claims Under Scrutiny MicrosimulationAI RiskAI Washing: Claims Under ScrutinyYour AI claims to investors and customers come under scrutiny. Decide what you can stand behind, and what you correct.

Mapping is indicative. Confirm scope against your own obligations.

Frequently asked questions

What is EBA ICT & Security Risk Guidelines?

The EBA Guidelines on ICT and security risk management require regular testing of business continuity plans, including scenario-based assessments. Supervisors still reference them alongside DORA.

How do simulations help with EBA ICT & Security Risk Guidelines?

Simulations let teams rehearse the decisions EBA ICT & Security Risk Guidelines cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.

Which iluminr simulations map to EBA ICT & Security Risk Guidelines?

Simulations mapped to EBA ICT & Security Risk Guidelines include Green Light: AI Board Governance, Bracing for Impact: Communications Test, Breached: AI IP Leak, Connectivity Down: Severe Weather, Core Platform Outage: Rollback and Data Breach: Major Leak, among others.

Who should take part?

These simulations are most often run with Risk, Technology & Security, Executive & Board and Legal.

Can I build a 12-month EBA ICT & Security Risk Guidelines testing program?

Yes. The iluminr program builder suggests a 12-month plan of simulations for EBA ICT & Security Risk Guidelines. You can add or remove scenarios and export the plan as a PDF for your board.

Can we customize these simulations?

Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.

Is this mapping legal or compliance advice?

No. The mapping between simulations and EBA ICT & Security Risk Guidelines is indicative. Confirm scope against your own obligations.

More in Europe & UK