On 8 October 2026 the Bank of England and UK Finance ran SIMEX26, a sector-wide crisis exercise built around a global disruption to cloud-based services. Thirty-eight of the largest banks and market infrastructure operators took part, and the Bank now expects them to act on what the exercise showed.

What the exercise covered

The Cross-Market Operational Resilience Group (CMORG) ran the biennial exercise. According to the Bank of England’s news release, the group is chaired by the Bank and UK Finance, with HM Treasury, the Financial Conduct Authority and the wider financial sector taking part. The Economic Secretary to the Treasury opened the exercise and the London Stock Exchange Group hosted it.

The release describes it as a wide-ranging crisis management exercise. It also included a live meeting of the Bank-chaired Cross Market Business Continuity Group, which sets strategic direction for the sector’s collective response to systemic incidents. The scenario was not informed by any specific threat information. It was developed with a range of industry experts.

Advertisement

Simplified Management — Advertisement

The release gives no findings, no scenario duration and no list of which services failed in the simulation. It states one expectation: the Bank “expects firms to take action based on the exercise to further strengthen their resilience and ability to respond to severe operational and cyber scenarios.” That sentence is the only forward obligation the release attaches to the exercise.

This year the scenario names the cloud

The Bank’s SIMEX 24 release, published on 2 October 2024, said that exercise tested the sector’s ability to respond to a major infrastructure failure that would require a total shut down and restart of the sector. The SIMEX26 release says the 2022 and 2024 exercises considered cyber-attacks against a major bank and critical infrastructure disruption outside the financial sector.

SIMEX26 names a specific dependency: the cloud-based services that firms rent rather than run. In our read, that naming is the change. Earlier scenarios described a failure of infrastructure in general terms. This one describes a global disruption to a service layer that sits under many firms at once, so the question shifts from how one bank recovers to how the sector coordinates when many firms lose the same thing together.

Why the cloud scenario connects to existing rules

The Bank’s page on the operational resilience of the financial sector lists IT system outages and third-party supplier failure among the threats firms must plan for. It sets out three asks. Firms identify their important business services. They set impact tolerances, which state to what extent a service could continue after a severe but plausible disruption. They then test that they can stay within those tolerances.

The page also says the operational resilience policy, SS1/21, requires a written self-assessment of compliance. It describes the aim as documenting a firm’s resilience journey and identifying risks that could stop it delivering important business services within tolerance. The Bank says it reviews each firm’s scenario testing details, results and assurance that the firm can remain within its impact tolerances.

A sector exercise tests something a single firm’s self-assessment cannot. A firm can show it stays within tolerance when its own provider has a bad day. A global cloud disruption removes that assumption, because the firm’s counterparties, market infrastructures and customers are affected in the same hour. The Bank’s page names the goal directly: “firms and the Bank work to ensure that when systemic operational risks crystallise, they do not impact the UK’s financial stability.”

What the authorities said

Katharine Braddick, Deputy Governor of Prudential Regulation at the Bank of England and CEO of the Prudential Regulation Authority, said: “This was an important demonstration of the UK financial sector’s commitment to operational resilience.” She added that preparedness “is essential to safeguarding financial stability.”

David Postings, Chief Executive of UK Finance, said: “Maintaining resilience across the financial sector is critical to supporting confidence, stability, and growth in the UK economy.”

Neither statement says the sector performed to a measured standard, and the release publishes no pass mark. Whether SIMEX26 produces published findings, as opposed to private feedback to participating firms, is not stated in the release.

The third-party regime sits beside the exercise

Exercises test the firms. A separate UK framework addresses the suppliers. HM Treasury’s policy paper on its approach to designating critical third parties, published on 21 March 2024, outlines the end-to-end process for designating critical third parties to UK financial services. The process starts with a recommendation from the financial regulators and runs through engagement with the supplier, the regulators and other relevant organisations before a designation decision. The paper also describes how a designation can be removed.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The SIMEX26 release does not mention the designation regime, and this article does not claim the two are formally linked. They are two tools aimed at the same dependency. One rehearses the response when a supplier fails. The other sets up a route for regulators to oversee that supplier.

What it means for the finance leader

These are our reading of the sourced material, not guidance from the Bank. Three practical points follow for anyone who runs payments, treasury or operations at a UK-regulated firm.

First, check what your impact tolerance assumes about your cloud supplier. The Bank’s own framework asks firms to say how far a service could continue after severe but plausible disruption. A tolerance written around a single outage at one provider does not describe the SIMEX26 scenario, which was global.

Second, map the dependencies behind each important business service to the layer where they share infrastructure. The exercise involved 38 institutions at the same time. If your processor, your settlement agent and your own systems all sit on the same underlying services, the tolerance you reported may be the weakest point in the chain.

Third, expect follow-up. The Bank says it expects firms to act on the exercise. In our read, participating firms will want any actions from the exercise on record in their next self-assessment, and firms that did not take part face the same supervisory framework. Our feature on the UK and EU move to T+1 settlement on 11 October 2027 covers another deadline competing for the same operations teams, and the PRA’s proposal to index 128 thresholds to nominal GDP shows the same regulator reworking its rulebook in parallel.

What to watch

Watch for three things. Whether the Bank or UK Finance publishes a summary of lessons from SIMEX26. Whether supervisors cite the exercise in firm-specific feedback. And whether the next CMORG programme update changes the Sector Response Framework, the structure the Bank says is exercised through SIMEX to coordinate the industry’s response to severe disruption. The Bank’s 2024 release describes that framework as a key component exercised through SIMEX.

Until then the public record is short. A date, a participant count, a scenario type and an expectation that firms act. For a sector that writes its resilience plans around severe but plausible events, a global cloud disruption is now on the list of events it has rehearsed together.

Source: Bank of England, CMORG holds sector-wide cloud outage simulation exercise