A core banking migration. A vendor failover that never fires.
Six and a half hours later, the Board wants answers.
2:14 AM, Saturday. Vaibhav Bank is mid-way through Project Udaan โ a weekend cutover migrating its core banking system to a new cloud platform run through NexaCore Technologies, its primary infrastructure vendor.
NexaCore's failover system fails to activate. ATMs, UPI, and POS transactions go dark across four zones. Six hours later, digital payments are still down โ and three things are unfolding at once: a deepfake voice-clone is phishing panicked customers for OTPs, the overflow AI bot is auto-confirming refunds it has no authority to process, and most branch staff on duty have never actually run the manual fallback procedure.
You have until 9 AM Monday โ market open, and a scheduled RBI supervisory call โ to give the Board a full picture and a remediation plan.
The number that explains everything: 3.25ร
Figure out what it is. Figure out what it means.
Each card reveals a piece of the story. The full picture only emerges when all cards are open.
Rank each party. You can update this in the War Room.
Cast your vote first to unlock the reveal.
Eight months before Zero Hour, the RCSA process worked exactly as intended: it identified NexaCore as a single point of failure and rated the risk High.
Then a Risk Acceptance Committee reviewed it, downgraded it to Medium, and accepted it โ to avoid delaying a migration that was already under timeline pressure. No compensating control was attached. No review date was set. Nobody's name was recorded as personally accountable if it materialised.
Correctly identifying a risk and then accepting it without any condition attached is not risk management. It is risk transfer to chance โ dressed up in the language of governance.
If that acceptance had carried even one condition โ a review date, a compensating control, a named accountable owner โ Zero Hour was, on the balance of the evidence, preventable.
The Vendor Risk Manager's experience is very different from the Head of Operational Risk's.