The network team and the incident response team have rarely reported to the same person. Gartner’s Predicts 2026: Cybersecurity Program Rebrands to Cyber Resilience expects that to change: by 2028, half of CISOs will be asked to own disaster recovery on top of incident response. For the finance and insurance firms Ahead works with in Japan, that pulls network resilience into a line the security organization now answers for.
1) The outages driving this are third-party and infrastructure failures, not just attacks
Most of the disruptions pushing this change are not cyberattacks. They are ordinary infrastructure and third-party vendor failures, which is why recovery can no longer sit apart from security. Two 2025 incidents make the point. In January, a power outage at FIS Global, a core banking vendor, locked Capital One customers out of their accounts for roughly three days. In May, an outage at Fiserv, another major processor, disrupted more than 60 applications, including the Zelle payments network, across Bank of America, Capital One, and Navy Federal at once. In both cases the cause was a supplier’s infrastructure, not an attacker, yet the impact on customers was the same as any security incident. That is the gap disaster recovery ownership is meant to close, and in both cases the institutions affected had built their network and their recovery plans as largely unconnected exercises.
The scale of the problem goes well beyond a few high-profile names: between January 2023 and February 2025, nine major UK banks reported at least 158 IT failure incidents totaling over 803 hours of downtime, roughly 33 days, according to figures compiled from UK regulatory disclosures. Spread across nine institutions in two years, that is a systemic reliability problem, not a run of bad luck at one firm, and it is why regulators have stopped treating recovery as an internal matter and started asking banks to prove it works.
2) Regulators now require recovery testing
This is not confined to Europe. The EU’s Digital Operational Resilience Act, or DORA, now requires financial entities to test critical systems and recovery processes at least once a year, which means proving that failover works rather than just documenting that it exists, with an auditor able to ask for the evidence. Japan’s Financial Services Agency has moved the same way: its operational resilience framework calls for business continuity testing, mapping of interdependencies, and third-party dependency management, and the FSA has made operational and third-party resilience a top supervisory theme after a run of incidents at financial institutions and their providers. For context on the stakes, IBM put the global average cost of a data breach at $4.88 million in 2024, and financial institutions typically sit above that average.
3) What this changes in practice
A recovery plan is only proven by testing failover under real transaction load. What has changed is where responsibility for that testing lies. A single point of failure, any component whose failure takes a critical service offline, used to be judged mainly on the uptime the infrastructure team reports to the business. Under the CISO, it also has to meet the continuity standard the board and regulators can hold the firm to. Firms should put network and security on shared recovery metrics before a regulator or an outage forces it.
Where Ahead fits
This is the work Ahead Group does for finance and insurance clients in Japan: designing network redundancy and validating it against the obligations the business is held to. That means finding the single points of failure on paths that touch critical services, testing failover under load instead of assuming it works, and documenting the result so it holds up when an FSA examiner or auditor asks for evidence. The FIS and Fiserv outages showed how a supplier’s failure becomes the institution’s problem, so mapping those third-party dependencies before they fail is part of the same job. If you are planning infrastructure changes and need the recovery design to meet that standard, learn more about our Managed Services. Managed Services – Ahead Group