All regulations & standards
Canada · Regulation & standard

OSFI B-13 scenario testing with simulations

What is OSFI B-13?

OSFI Guideline B-13 on technology and cyber risk expects federally regulated financial institutions to scenario-test disaster recovery capabilities against severe but plausible events.

iluminr simulations let teams rehearse the decisions OSFI B-13 cares about against severe-but-plausible scenarios, and keep a record of who decided what, and when. Run them as Microsimulations, full-scale simulations, or facilitated by our team of experts.

Build a 12-month OSFI B-13 programOpen in the catalogue

Simulations mapped to OSFI B-13

Phone call in the dark, illustrating the Bracing for Impact: Communications Test MicrosimulationCyber & DataBracing for Impact: Communications TestTest your organization's ability to send timely Emergency Notifications in response to a sophisticated, self-learning malware threat that targets critical infrastructure.Lightning storm over a city, illustrating the Connectivity Down: Severe Weather MicrosimulationThird-Party & TechnologyConnectivity Down: Severe WeatherRespond to severe weather-induced operational disruptions, including widespread internet outages, by verifying role responsibilities and ensuring continuity in communications and operations.Data center servers in the dark, illustrating the Core Platform Outage: Rollback MicrosimulationThird-Party & TechnologyCore Platform Outage: RollbackA critical platform update turns into a live-fire incident as a scheduled patch unexpectedly brings down key systems. Participants must navigate real-time service degradation, mounting customer pressure, and rollback decisions under duress. This Microsimulation tests cross-functional coordination, incident escalation, and communication flow - providing vital validation of operational resilience, rollback protocols, and regulatory compliance readiness.Code on a dark screen, illustrating the Data Breach: Major Leak MicrosimulationCyber & DataData Breach: Major LeakA massive data breach has struck some of the world’s largest organizations, including your own, leading to the potential compromise of sensitive personal information. The breach has exposed the names, phone numbers, and addresses of millions of customers, raising immediate concerns about privacy, identity theft, and the security of your data handling practices.A broken chain, illustrating the Exit Plan: Vendor Insolvency MicrosimulationThird-Party & TechnologyExit Plan: Vendor InsolvencyA critical third-party vendor has filed for insolvency, causing both operational and data losses. Can your team execute the exit plan under pressure?Code on a dark screen, illustrating the Extortion: Ransomware Invasion MicrosimulationCyber & DataExtortion: Ransomware InvasionAddress a widespread ransomware attack demanding cryptocurrency payments, focusing on stakeholder communication and restoring operational control.Code on a dark screen, illustrating the Inside Job: Data Breach MicrosimulationCyber & DataInside Job: Data BreachNavigate the high-stakes initial response to a sophisticated insider threat that has compromised sensitive organizational data, testing your incident response protocols when the threat comes from within.Ripples spreading across dark water, illustrating the Ripple Effect: Fourth-Party Fallout MicrosimulationThird-Party & TechnologyRipple Effect: Fourth-Party FalloutA critical system failure has occurred in your supply chain, creating significant operational impacts. Your third-party vendor experienced a service outage caused by a vulnerability introduced through an undetected AI-driven update in their supplier's systems. This failure has cascaded through your supplier's network, resulting in widespread service disruptions that are now affecting your business operations and customers.Trading screens in the dark, illustrating the Trading Halt: Ransomware Chaos MicrosimulationCyber & DataTrading Halt: Ransomware ChaosAddress a major ransomware attack causing a service outage, suspected to be state-sponsored, by coordinating with cybersecurity experts and effectively communicating with stakeholders.Shipping containers at a port, illustrating the Trapped: Vendor Modern Slavery MicrosimulationThird-Party & TechnologyTrapped: Vendor Modern SlaveryNavigate the ethical, legal, and operational challenges posed by a tech supplier embroiled in a modern slavery scandal, focusing on incident assessment and communication strategies.Data center servers in the dark, illustrating the Vendor Outage: System Down MicrosimulationThird-Party & TechnologyVendor Outage: System DownRespond to a critical vendor cyber-attack that has disrupted essential services, focusing on business impact assessment, data review, and immediate contingency actions.Code on a dark screen, illustrating the Double Tap: Cyber Attack MicrosimulationCyber & DataDouble Tap: Cyber AttackA major information services provider faces a cyber crisis, leading to system outages, regulatory scrutiny, and eroded client trust. Participants will manage rapid response adjustments, client communication, and rebuilding credibility under intense pressure.Code on a dark screen, illustrating the Evolved: Adaptive Malware MicrosimulationCyber & DataEvolved: Adaptive MalwareA sophisticated form of malware has caused disruption across global health services, telecommunication and technology providers.Phone call in the dark, illustrating the Vished: Customer & Regulatory Impacts MicrosimulationCyber & DataVished: Customer & Regulatory ImpactsA convincing voice-phishing call gives attackers a foothold, with consequences for customers and regulators. Assess the incident, identify the critical business functions at risk, and work through your regulatory obligations.Code on a dark screen, illustrating the Wage Gap: Data Breach Fallout MicrosimulationCyber & DataWage Gap: Data Breach FalloutAddress the aftermath of a data breach revealing pay inequity, focusing on stakeholder engagement, implementing corrective measures, and restoring organizational trust.Red warning sign reading breached, illustrating the Plan Under Pressure: Cyber Incident MicrosimulationCyber & DataPlan Under Pressure: Cyber IncidentA confirmed disruption is unfolding. You're drawn into the early response and asked whether a formal plan should be activated.Red padlocks over streams of code, illustrating the Account Takeover: Containment & Response MicrosimulationCyber & DataAccount Takeover: Containment & ResponseA suspected account compromise points to a data breach. Contain it, escalate it and coordinate across functions.

Mapping is indicative. Confirm scope against your own obligations.

Frequently asked questions

What is OSFI B-13?

OSFI Guideline B-13 on technology and cyber risk expects federally regulated financial institutions to scenario-test disaster recovery capabilities against severe but plausible events.

How do simulations help with OSFI B-13?

Simulations let teams rehearse the decisions OSFI B-13 cares about against severe-but-plausible scenarios. iluminr keeps a record of who decided what, and when, which you can use as evidence of testing.

Which iluminr simulations map to OSFI B-13?

Simulations mapped to OSFI B-13 include Bracing for Impact: Communications Test, Connectivity Down: Severe Weather, Core Platform Outage: Rollback, Data Breach: Major Leak, Exit Plan: Vendor Insolvency and Extortion: Ransomware Invasion, among others.

Who should take part?

These simulations are most often run with Technology & Security, Risk, Executive & Board and Compliance.

Can I build a 12-month OSFI B-13 testing program?

Yes. The iluminr program builder suggests a 12-month plan of simulations for OSFI B-13. You can add or remove scenarios and export the plan as a PDF for your board.

Can we customize these simulations?

Yes. Run any template as is, tailor the roles, plans, critical services and injects to your organization, or build your own from scratch with the iluminr builder.

Is this mapping legal or compliance advice?

No. The mapping between simulations and OSFI B-13 is indicative. Confirm scope against your own obligations.

More in Canada