TECH NEWS
How long until all the lights go out at your bank?
A major cyberattack is no longer a question of "if", but "when": is your organisation capable of resuming its critical operations within 24 hours?
June 18, 2026

It is only a matter of time until a Luxembourg Bank gets hacked and all the lights go out. Initially, clients, especially those that check their balance 20 times a day, will assume that it is a technical blip and the app will get back to normal. After an hour, the telephone help desk will be overloaded, and most callers advised to call back later, without realising that their life savings may have been transferred to an account in south east-Asia. After four hours, the cyber-attack will be on every news website, the CSSF will be sending faxes in CAPITAL LETTERS and despite reassurances that your money is insured, expect queues around buildings as people try, unsuccessfully to withdraw their cash.
Nowadays there is an expectation that cyber-attacks are almost inevitable and both this reason and the infamous DORA and NIS2 regulations, many Luxembourg banks are now expected to demonstrate they can continue critical operations even during a major cyber incident.
The thinking of CISOs has shifted from “Can we stop every attack?” to “How quickly can we recover?”.
So….. can your bank resume a minimum viable service in 24 hours?
When a bank suffers a major cyberattack, the first priority is containment. Security teams must quickly identify the source of the attack and isolate affected systems before the threat can spread further. This may involve disconnecting compromised servers, blocking malicious traffic and disabling affected user accounts. While these actions can temporarily impact operations, they help prevent a much larger crisis.
At the same time, a dedicated incident response team should be activated. This typically includes cybersecurity specialists, infrastructure experts, legal advisers, communications professionals and senior management. Clear rules about who decides what, is essential.
Once the threat has been contained, attention turns to recovery. Modern banks increasingly rely on immutable backups, cloud-based recovery environments and disaster recovery platforms that allow critical services to be restored rapidly. Rather than rebuilding an entire infrastructure from scratch, organisations can prioritise the systems that customers need most, such as online banking, payment processing and customer support channels.
Communication is equally important. Customers, employees, partners and regulators need timely and accurate information. A lack of communication can quickly lead to speculation and reputational damage. Transparency does not mean sharing every technical detail, but it does mean providing regular updates and demonstrating that the situation is under control.
The role of testing should not be underestimated. The banks that recover fastest are usually those that have already rehearsed the scenario. Tabletop exercises, cyber simulations and business continuity testing help teams understand their responsibilities before a real crisis occurs. In many cases, the ability to recover within 24 hours is determined months or even years before the attack takes place.
For today’s banks, cyber resilience is no longer just an IT issue. It is a business imperative.
Join us on the 25th of June to share your views on Cyber resilience.