ECB CROE scenario testing with simulations
The ECB’s Cyber Resilience Oversight Expectations set out how financial market infrastructures should build, test and evidence cyber resilience.
iluminr simulations let teams rehearse the decisions ECB CROE cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.
Simulations mapped to ECB CROE
Mapping is indicative. Confirm scope against your own obligations.
Frequently asked questions
What is ECB CROE?
The ECB’s Cyber Resilience Oversight Expectations set out how financial market infrastructures should build, test and evidence cyber resilience.
How do simulations help with ECB CROE?
Simulations let teams rehearse the decisions ECB CROE cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.
Which iluminr simulations map to ECB CROE?
Simulations mapped to ECB CROE include Bracing for Impact: Communications Test, Data Breach: Major Leak, Extortion: Ransomware Invasion, Inside Job: Data Breach, Trading Halt: Ransomware Chaos and Double Tap: Cyber Attack, among others.
Who should take part?
These simulations are most often run with Technology & Security, Risk, Compliance and Legal.
Can I build a 12-month ECB CROE testing program?
Yes. The iluminr program builder suggests a 12-month plan of simulations for ECB CROE. You can add or remove scenarios and export the plan as a PDF for your board.
Can we customize these simulations?
Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.
Is this mapping legal or compliance advice?
No. The mapping between simulations and ECB CROE is indicative. Confirm scope against your own obligations.

