IBM Z and LinuxONE - IBM LinuxONE Ecosystem

IBM LinuxONE Ecosystem

IBM LinuxONE Ecosystem

Explore IBM LinuxONE ecosystem to partner, learn and connect


#Servers
#IBMLinuxONE
#Enterpriseserver
 View Only

We Passed the DR Test, But Can We Survive a Real Cyber‑Attack?-How Do You Manage Third Party Risk?

By imran jalil posted 04/27/26 04:22 AM

  

A conversation with a bank’s head of operational resilience and why third‑party risk is the missing piece

Last week, I sat down with the head of operational resilience at a major bank. Over tea, he shared a frustration that I have heard from many financial institutions.

“Imran, we have all the SAMA BCM policies in place. We test our disaster recovery twice a year. The reports look good. But I’ll be honest when a real ransomware attack hits, or when one of our critical vendors fails, I’m not sure our recovery plan will hold together.”

He explained the real problem. His bank runs critical functions across hundreds of x86 servers, but that is only part of the story. The bank also relies on dozens of third‑party vendors for cloud services, payment processing, and model development. Each vendor introduces its own failure points, security gaps, and compliance risks.

“SAMA’s BCM framework and Cybersecurity Framework both require us to manage third‑party risk,” he said. “But with this sprawling vendor ecosystem, how do I prove that my vendors can meet my recovery objectives? How do I ensure their security gaps don’t become my gaps?”

I leaned in. “What if I told you there is a platform that gives you hardware‑enforced proof not just promises  for every single one of those problems, including third‑party oversight?”

The Third‑Party Risk Blind Spot

SAMA has made third‑party risk management (TPRM) a non‑negotiable pillar of its regulatory framework. The SAMA Cybersecurity Framework (Section 3.4) explicitly mandates that member organizations manage third‑party cyber security across contracts, due diligence, and ongoing monitoring. The SAMA Outsourcing Rules govern the entire vendor engagement process, requiring a thorough review of the vendor’s operational, financial, legal, and reputational risks plus a robust business continuity plan, especially for overseas vendors, where enhanced due diligence is required.

Research

A 2025 Dun & Bradstreet survey found that 91% of financial services firms experienced negative effects from third‑party relationships, with average losses exceeding $700,000. A separate Ncontracts 2025 survey found that over one‑third of large banks manage more than 1,000 vendors, creating “vendor sprawl” that makes TPRM nearly impossible to manage manually.

Yet, despite the rising risks, only 8% of financial institutions feel fully compliant with DORA’s two toughest requirements: digital operational resilience testing and ICT third‑party risk management. In the UK, the PRA’s Operational Resilience framework and the Critical Third Party (CTP) regime impose parallel obligations.

Challenge The Hidden Gap How IBM LinuxONE Helps
Trust in vendor security controls Vendors may claim compliance, but you cannot enforce their controls. Hardware‑enforced security at your end. Confidential computing encrypts data at rest, in transit, and in use even if a vendor’s infrastructure is compromised, your data remains unreadable.
Audit‑ready vendor evidence

Vendor logs, compliance reports, and evidence for SAMA must be manually assembled often with gaps.

One LinuxONE replaces hundreds of servers fewer systems to audit, fewer vendors to manage.

SAMA’s vendor due diligence

Manual due diligence over vendors, subcontractors and flow‑down clauses is resource‑intensive.

Less vendor footprint means fewer due‑diligence files and contracts to maintain.

Resilience testing (TLPT style)

Complex orchestration across vendor systems leaves scattered, unverifiable logs.

Telum II AI accelerator enables real‑time anomaly detection. GDPS automation cuts recovery time to <1 hour.

The Turning Point

I pulled out a napkin and drew a quick comparison bringing third‑party risk directly into the operational resilience picture.

Operational Resilience Challenge Typical x86 Environment IBM LinuxONE Solution
Third‑party vendor footprint Dozens of vendors, hundreds of servers, overlapping risk exposures. One LinuxONE replaces hundreds of servers fewer vendors, simpler due diligence, leaner audit trail.
Prove RTO < 4 hours Manual failover across servers and vendor dependencies; slow, error‑prone. GDPS automation RTO as low as 1 hour, fully automated, even in multi‑vendor dependencies.
Immutable audit trail for vendor actions Software logs from multiple vendors can be altered or deleted. Journaled file systems every recovery action logged unalterably, directly mapping to SAMA’s demand for tamper‑evident logs.
Insider threat / vendor overreach Administrators and vendor staff may have unfettered access to recovery data. Secure Service Containers vendor staff are locked out; your data stays under your control, even during vendor‑led maintenance.
SAMA third‑party due diligence Manual tracking of vendor risks, fourth parties, and flow‑down clauses. One platform reduces the number of vendors under SAMA oversight, simplifying due diligence.

My friend stared at the napkin. “So you’re telling me that by consolidating onto one platform, I reduce my third‑party risk exposure and the platform gives me immutable proof that I can use for SAMA vendor audits?”

“Exactly,” I said. “And that’s a message your entire C‑suite needs to hear.”

The Expertise You Need to Master Third‑Party Risk

He looked at me. “What do my people actually need to know to make sense of this?”

I shared a quick competency checklist that every TPRM team in a bank should have:

Domain of Expertise What It Includes
Regulatory literacy Deep familiarity with SAMA Outsourcing Rules, CSF Section 3.4, PDPL, and NCA essential controls
Risk assessment methodology Vendor‑scoping, inherent risk scoring, residual risk calculation, and materiality determination
Security control validation Ability to assess vendor security documentation, penetration test reports, SOC2/ISO certs, and to run technical validation
Data protection & cross‑border Mapping of data flows, encryption at rest/in transit, data processing agreements, and foreign legal risk assessment
Vendor due diligence framework A structured questionnaire and evidence collection process aligned to NIST CSF 2.0 / CRI Profile
Continuous monitoring Automated tools (SSC, Mondoo, etc.) and manual processes for periodic vendor reassessment

“Most banks don’t have that mix,” I added. “That’s where you come in as a consultant.”

The Bottom Line for Banks and Consultants

SAMA demands that financial institutions manage third‑party risk as a first‑class discipline from risk assessment and contract clauses down to oversight of subcontractors (fourth parties). IBM LinuxONE doesn’t replace your vendor management program; it drastically reduces the number of vendors you need to manage, while the hardware‑enforced audit trails give you the proof regulators require.

  • Fewer vendors, simpler due diligence consolidation shrinks your third‑party attack surface.

  • Hardware‑enforced, immutable audit trails for every recovery action, directly mappable to SAMA’s vendor compliance expectations.

  • Secure Service Containers lock out vendor staff from your most sensitive recovery data.

For the consultant in the room, this is a service to sell a resilience gap analysis that includes third‑party dependencies. For the bank, this is a foundation that finally makes operational resilience provable, not just planned.

If you want to stop hoping that your vendors won’t fail and start proving that you can recover the platform exists. The question is how soon you can start the conversation.

👇 Read the full LinuxONE series for more technical insights:
🔗 https://community.ibm.com/community/user/blogs/imran-jalil

What is the single biggest third‑party risk gap in your financial institution today? Let me know in the comments.

#SAMA #BCM #OperationalResilience #ThirdPartyRisk #TPRM #DORA #IBMZ #LinuxONE #SaudiArabia #FinancialInstitutions #RiskManagement #BusinessContinuity

0 comments
57 views

Permalink