UK Financial Sector Completes SIMEX26 Cloud Outage Simulation Involving 38 Systemically Important Firms
On 8 October 2026, the Cross-Market Operational Resilience Group (CMORG), chaired by the Bank of England and UK Finance, completed its biennial simulation exercise known as SIMEX26, focused this year on a global cloud services disruption scenario. The exercise brought together 38 of the largest and most systemically important banks and market infrastructure operators, alongside HM Treasury and the Financial Conduct Authority. It was hosted by London Stock Exchange Group and opened by Economic Secretary to the Treasury Lucy Rigby. A live meeting of the Bank-chaired Cross Market Business Continuity Group also took place as part of the exercise, with that body providing strategic direction to the sector's collective response to systemic incidents. The scenario was not informed by any specific threat but was developed with industry experts. The Bank of England stated it now expects firms to take action based on the exercise to further strengthen their resilience and ability to respond to severe operational and cyber scenarios. Deputy Governor for Prudential Regulation and CEO of the Prudential Regulation Authority, Katharine Braddick, described the exercise as 'an important demonstration of the UK financial sector's commitment to operational resilience'. Previous SIMEX exercises, in 2022 and 2024, examined cyber-attacks against a major bank and critical infrastructure disruption outside the financial sector. SIMEX26 builds on CMORG's broader programme, which has recently included strengthening third-party engagement and resilience, enabling secure innovation in response to AI and other emerging technologies, and enhancing cyber preparedness.
Why this matters
Cloud concentration risk, meaning the financial system's dependence on a small number of major cloud providers, has become one of the most actively monitored systemic risks for UK and European regulators. By making a global cloud disruption the central scenario for SIMEX26, the Bank of England and its partners are signalling that this is now a top-tier threat requiring sector-wide rehearsal, not just firm-level contingency planning. For systemically important institutions, the Bank's statement that it 'expects firms to take action' based on the exercise is a clear regulatory signal that operational resilience gaps identified during the simulation will be followed up. This matters for compliance and legal teams at major banks and market infrastructure operators who must translate exercise findings into documented remediation plans.
On the Ground
The legal work generated here sits across financial regulation and banking practice. Regulatory lawyers will be advising clients on how SIMEX26 findings interact with existing operational resilience obligations, and on what documentation the Bank of England and FCA may expect to see as follow-up. Technology and outsourcing specialists will review cloud service agreements and third-party resilience provisions. A trainee supporting this type of regulatory matter would assist with: preparing regulatory notification drafts, updating compliance gap analysis memos, reviewing outsourcing and cloud contract schedules, and maintaining remediation tracker documents.
Interview prep
Question you might get
“How do operational resilience exercises like SIMEX26 translate into legal obligations for participating banks, and what follow-up should in-house counsel expect from the regulators?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeMy notes
saved