๐ŸŒโš ๏ธ

Zero Hour

A core banking migration. A vendor failover that never fires.
Six and a half hours later, the Board wants answers.

๐Ÿ“‹ Mission

2:14 AM, Saturday. Vaibhav Bank is mid-way through Project Udaan โ€” a weekend cutover migrating its core banking system to a new cloud platform run through NexaCore Technologies, its primary infrastructure vendor.

NexaCore's failover system fails to activate. ATMs, UPI, and POS transactions go dark across four zones. Six hours later, digital payments are still down โ€” and three things are unfolding at once: a deepfake voice-clone is phishing panicked customers for OTPs, the overflow AI bot is auto-confirming refunds it has no authority to process, and most branch staff on duty have never actually run the manual fallback procedure.

You have until 9 AM Monday โ€” market open, and a scheduled RBI supervisory call โ€” to give the Board a full picture and a remediation plan.

The number that explains everything: 3.25ร—
Figure out what it is. Figure out what it means.

๐ŸŽญ Your Role Briefing
โฑ๏ธ Game Flow
Phase 1: Investigation (20 min) โ€” unlock evidence, run the Impact Tolerance calculator
Phase 2: War Room (25 min) โ€” ask questions, debate
Phase 3: Vote on the remediation package
Phase 4: Reveal what really happened
๐ŸŽฏ Remember
Stay in character during the War Room.
Figure out what 3.25ร— means โ€” before the room does.
Every function did roughly what it was designed to do. That's exactly the problem.
๐Ÿ” Investigation Phase
Unlock evidence. Find what the incident dashboard alone won't tell you.
20:00
TIME REMAINING
๐Ÿงฎ Impact Tolerance Breach Calculator โ€” The Number That Explains Everything

๐Ÿ“ Evidence Cards โ€” Click to unlock

Each card reveals a piece of the story. The full picture only emerges when all cards are open.

โš–๏ธ Who Is Most Accountable?

Rank each party. You can update this in the War Room.

๐Ÿ›๏ธ Emergency War Room
Every role must speak. Every claim must be backed by a number.
25:00
TIME LEFT
6.5 hrs
Total Outage Duration
4 / 4
Zones Affected
0
Confirmed Data Breach Records (so far)
3.25ร—
Impact Tolerance Breach (hidden until calculated)
Every box above is a real, verifiable fact. None of them, alone, tells you whether this was a bad night or a governance failure. That's what the War Room is for.

Cross-Examination Questions

0/10 addressed
๐Ÿ—ณ๏ธ Cast Your Vote
The Board must decide the remediation package โ€” before the 9 AM RBI call.

๐Ÿ“Š Live Class Vote (simulated)

Cast your vote first to unlock the reveal.

๐ŸŒ
PROJECT UDAAN
6.5 hour outage ยท 4 zones ยท Impact Tolerance breach 3.25ร— ยท risk accepted 8 months earlier

The Speed vs Resilience Debate โ€” Resolved

COO's Claim
We hit our go-live date; the business case demanded it, and the migration is fundamentally sound
Measured: project delivery. Resilience impact: not considered a project metric.
Head of Operational Risk's Claim
This was a known, correctly identified risk that materialised exactly as flagged eight months earlier
Measured: risk identification accuracy. Compensating control: never attached.
The actual answer: Both were completely true, at the same time โ€” and neither, alone, explains the outage.

The migration's business case was real. The timeline pressure was real. The risk was also correctly identified eight months in advance, rated High, and escalated properly.

The failure was not the decision to proceed. It was accepting a correctly identified High risk with no compensating control and no review date attached. Speed and resilience are not inherently opposed โ€” a bank can hit its deadlines and still require every accepted risk to carry a condition.

This is exactly what a disciplined Risk Acceptance process โ€” not just an RCSA โ€” is built to prevent.

Eight months before Zero Hour, the RCSA process worked exactly as intended: it identified NexaCore as a single point of failure and rated the risk High.

Then a Risk Acceptance Committee reviewed it, downgraded it to Medium, and accepted it โ€” to avoid delaying a migration that was already under timeline pressure. No compensating control was attached. No review date was set. Nobody's name was recorded as personally accountable if it materialised.

Correctly identifying a risk and then accepting it without any condition attached is not risk management. It is risk transfer to chance โ€” dressed up in the language of governance.

If that acceptance had carried even one condition โ€” a review date, a compensating control, a named accountable owner โ€” Zero Hour was, on the balance of the evidence, preventable.

The 5-Step Check Every Risk Acceptance Should Pass:
1. Does this acceptance have an expiry or review date?
2. Is there at least one compensating control attached?
3. Is a specific, named owner recorded as accountable if it materialises?
4. Has this same risk been accepted before โ€” and has anything actually changed since?
5. Does the accepted Impact Tolerance match what Operations and Business Continuity actually believe they can survive?
A risk acceptance without a condition isn't a decision.
It's a bet the bank didn't know it was placing.
๐Ÿ“– Faculty Debrief
Discussion questions, answer keys, course connections.

๐Ÿ“‹ Your Full Decision Record

๐Ÿงฎ Impact Tolerance Lab โ€” Live Calculations

Play Again with a Different Role

The Vendor Risk Manager's experience is very different from the Head of Operational Risk's.