St Georges Strategy

Signals / Operational resilience

Failure paths, fallback evidence, and customer impact

The exploded resilience page behind the weekly brief. It turns outages and control failures into internal tests of ownership, telemetry, tolerance, and recovery.

Curated memory

Still material

These signals remain live after editorial review. Most stay for up to 90 days; exceptional structural anchors can remain for six months with a recorded reason.

  1. 90-day windowReviewed 9 Jul

    Worldpay outage shows processor failure can become customer harm

    Payments / Guardian / 2026-06-23
  2. 90-day windowReviewed 9 Jul

    HSBC Australia's $35m scam-protection penalty keeps complaint ageing in the resilience narrative

    Enforcement / ASIC / 2026-06-18
  3. Longer-term anchorReviewed 9 Jul

    FCA one-year review finds mapping still leans on technology over people, facilities, and third parties

    Primary / FCA / 2026-03-27
  4. Longer-term anchorReviewed 9 Jul

    FCA one-year review: firms still lack clear, tested methodologies for setting impact tolerances

    Primary / FCA / 2026-03-27
  5. 90-day windowReviewed 9 Jul

    Patch SLAs are compressing as AI changes vulnerability discovery

    Cyber resilience / Wired / 2026-06-11

Why it made the weekly brief

The editorial judgement

Resilience signals matter when they reveal an internal control test: whether a firm understands its customer-visible failure paths and can evidence recovery under stress.

So what

Availability is not the same as service continuity

A platform can be technically up while customers cannot pay, trade, access, complain, or recover. The test is the journey, not the component.

Who cares

COO, CIO, CISO, payments, complaints, conduct, and resilience teams

Operational resilience belongs across business services, customer outcomes, third parties, cyber, incident response, and governance.

Evidence needed

Dependency maps, tolerance tests, telemetry, and rehearsed fallback

The weekly brief should push readers toward evidence that failure paths have been tested, not simply documented.

Resilience evidence checklist

What the reader should ask for

Resilience pages should end in practical evidence prompts that can be handed to a service owner or control owner.

Archive and source trail

How this topic should compound over time

Resilience is especially valuable as an archive because incidents repeat in patterns. The archive should preserve the pattern, not only the incident.