14,000 charities lost online banking to someone else's flaw
Your continuity plan almost certainly assumes your bank works. Not the money in it, the access to it: the ability to log in on the 28th and run payroll. That assumption is doing a lot of quiet load-bearing, and it is not yours to guarantee.
Ask the 14,000 charities banking with CAF Bank. Their online banking has been unavailable since 24 July and, as The Register reported on 28 July, it will stay down until further notice. Some of them have been unable to run payroll, cut off from their own accounts.
What happened
CAF Bank, owned by the Charities Aid Foundation, saw reports of suspicious activity on some customer accounts. It investigated, found a previously undetected vulnerability in how third-party software connects to its online banking portal, and switched the portal off while it works with its technology partner on a fix.
Chief executive Alison Taylor was straightforward about it: "We are working with external experts to fix an issue we identified with third-party software related to our online banking portal. The core bank is not affected." Customer money is safe, core banking is unaffected, and the bank says it detected the problem early and told customers about any attempted fraud. Phone support is running and time-sensitive payments such as payroll are being prioritised. Taylor declined to say whether customers will be compensated.
Read that decision on its own terms, because it is the right one. A bank that finds a hole between a supplier's software and its own front door, and turns the front door off rather than leave it ajar, is behaving properly. The alternative was keeping a service running while suspicious activity continued through it. Nobody should want the other choice.
That is what makes this worth writing about. This is not a story about negligence. It is a story about what happens to you when a supplier does the right thing.
The bit that applies to you
Nothing in any of those 14,000 charities failed. Their passwords were fine, their staff clicked nothing, their own systems were untouched. They lost access to their money for a week and more because of a flaw in software two steps removed from them, sitting between their bank and their bank's supplier.
Most continuity planning does not reach that far. It covers your own systems going down, and it usually covers a supplier going bust. It rarely covers a supplier that is entirely solvent, entirely functional, and has deliberately switched off the one part you use, indefinitely, for a good reason.
The indefinite part is what hurts. An outage with a stated end time is an inconvenience you can plan around. "Until further notice" means you cannot tell on day one whether this is a two-day problem or a three-week one, so you cannot decide whether to invoke a workaround or wait. Charities in this position have had to work out how to pay staff without account access, in the same week they found out.
Worth noting that CAF Bank's customers had a rough run last year too, when a new banking platform launched and customers could not log in or transact. The bank apologised at the time. That history is not the cause of this incident, but it is relevant to a different question: how much of your operational capability sits with one provider, and what your position is if that provider has a bad year.
The four questions
This is a short exercise and you can do it without any technical help.
Which suppliers can stop us operating by switching something off? Not going bankrupt: switching off. Your bank's online portal, your payroll bureau, your accounting platform, your booking or order system, your card processor. The list is usually shorter than people expect and more concentrated than they are comfortable with.
For each one, what do we do on day three? Specifically. Not "contact them". If your online banking is gone for a fortnight, do you know whether your bank can take payment instructions by phone, what it needs to authorise them, and who in your organisation is a recognised signatory? CAF Bank's customers found out that answer under pressure. You can find it out on a quiet afternoon.
Who tells us, and how fast? These 14,000 charities learned by email from their bank. Would you notice a message like that in time to act, and does it reach a person who can make a decision, or an inbox nobody owns?
What does the contract actually say? Most terms for this kind of service promise very little about availability and even less about compensation. Read one. It will recalibrate how much of your plan you are comfortable resting on a supplier's goodwill.
None of this stops your bank taking its portal offline. It changes how much that costs you when it does. The same logic runs underneath the concentration risk the UK has already named in cloud services: the failure that gets you is rarely your own, and the plan has to account for that.
How Steelwise can help
Working out which suppliers can stop you operating, and what you would actually do on day three, is the kind of review that takes an afternoon and changes what you do in a bad week. Get in touch.
Further reading
- NCSC: Supply chain security guidance
- NCSC: Business continuity and disaster recovery planning
- Charity Commission: Charities and risk management