惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
Last Week in AI
Last Week in AI
腾讯CDC
The Cloudflare Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
MyScale Blog
MyScale Blog
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
I
InfoQ
雷峰网
雷峰网
人人都是产品经理
人人都是产品经理
Blog — PlanetScale
Blog — PlanetScale
Y
Y Combinator Blog
H
Help Net Security
T
Tailwind CSS Blog
美团技术团队
aimingoo的专栏
aimingoo的专栏
博客园 - 三生石上(FineUI控件)
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
P
Proofpoint News Feed

Citrix Blogs

What’s left for humans? – Citrix Blogs Why this moment feels different – Citrix Blogs Introducing Citrix Platform for Public Sector – Citrix Blogs how our partnership with Google has matured secure access for the browser era – Citrix Blogs When session recording stops scaling – Citrix Blogs A conversation with Cletis Earle – Citrix Blogs Imprivata Ready Certification validates Citrix Unicon: A practical guide for healthcare IT – Citrix Blogs Skills are all you need – Citrix Blogs UHMC customers now have expanded Citrix Secure Private Access entitlement – Citrix Blogs How CIOs turn post‑merger disorder into a synergy engine – Citrix Blogs why your AI strategy is focused on the wrong layer – Citrix Blogs Securing high privileged admin access doesn’t have to be complicated – Citrix Blogs What will knowledge work be in 18 months? Look at what AI is doing to coding right now. – Citrix Blogs Untangling spaghetti – Citrix Blogs Workers’ “second brains” break every assumption about how we secure knowledge work – Citrix Blogs Taming integration chaos (the core of M&A failure) – Citrix Blogs OpenClaw and Moltbook preview the changes needed with corporate AI governance – Citrix Blogs Three years. Five Use Cases. A Leader: Citrix – Citrix Blogs The hard truths about hospital consolidation: An M&A guide for IT leaders – Citrix Blogs Why Citrix is the most complete EUC platform – Citrix Blogs Sign in once, get more done: Why continuous identity is a strategic advantage – Citrix Blogs Everyone’s worried about the wrong AI security risk – Citrix Blogs Security by design, proven by action with Citrix NetScaler – Citrix Blogs The invisible 80%—what corporate-led AI transformations can’t see – Citrix Blogs Workers don’t want to build automations. They want to delegate. – Citrix Blogs speed vs. security – Citrix Blogs AI will be THE interface to knowledge work. Here’s how we’ll get there. – Citrix Blogs Why I joined Citrix — and what it means for healthcare leaders – Citrix Blogs How the most successful CIOs are building successful merger and acquisition approaches – Citrix Blogs IT admits workers control AI. Workers admit they use it to leave at 5. – Citrix Blogs
Six practical steps for rethinking resilience architectur...
Chad Davis · 2026-06-16 · via Citrix Blogs

Six practical steps for rethinking resilience architecture in financial services and insurance for the modern era

This blog is the third post in a three‑part series on operational resilience in financial services. Read part one and part two.

Financial services and insurance (FSI) organizations are under increasing pressure to demonstrate that they can maintain continuity of critical operations during disruption. Regulators expect it. Customers demand it. Boards are accountable for it. And hybrid multi-cloud environments have made it harder than ever to deliver.

Most institutions already have resilience plans—but those plans were built for a different era. They assume predictable failure modes, linear recovery processes, and infrastructure‑centric continuity. Today’s environment requires a rethinking of those plans, not just incremental updates.

This final blog in our three-part series focuses on how FSI institutions can adjust their resilience architecture through six steps in order to better align with modern regulatory expectations and hybrid‑cloud realities.

Step 1: Reassess critical workflows and their dependency chains

Recent regulatory scrutiny, changing failure patterns, and greater dependence on hybrid cloud and third-party services have exposed gaps in traditional resilience plans. In short, FSIs are facing new disruption challenges.

Instead of assuming existing plans are complete, institutions should revisit:

  • Which workflows are truly critical
  • Which dependencies are most fragile
  • Which teams must remain productive during disruption
  • Where access failures create the greatest regulatory exposure

This is not a mapping exercise—it’s a risk recalibration.

Step 2: Establish a separate, stable access layer

The lesson from recent major outages—including the global CrowdStrike disruption that took down millions of Windows systems and affected banks, payments, and other critical services—is that institutions cannot rely on the same tightly coupled access path they use in normal operations. When identity, endpoint, network, or cloud dependencies fail together, recovery becomes slower, riskier, and harder to govern. A resilient access layer must be decoupled from the systems that typically fail. This is where the completely independent Citrix access plane provides unique value.

The Citrix platform’s access environment is:

  • Separate from identity providers
  • Separate from cloud control planes
  • Separate from network routing dependencies
  • Delivered across multiple sites and clouds

This ensures that even when upstream systems degrade, the institution still has a controlled, governed access path for employees and fixers.

Step 3: Implement continuity controls that reduce regulatory exposure

Continuity controls shouldn’t force you to choose between system availability and compliance. In high-stakes environments like FSI call centers, maintaining this balance is critical. Every minute a call center agent is stranded is a direct hit to customer trust.

When a disruption happens and the call center loses secure access to core systems, agents are unable to authenticate callers, retrieve customer records, or process time-sensitive transactions. Simply bypassing security protocols to get agents back online isn’t an option, as it immediately triggers severe regulatory exposure and data security risks. The goal is to keep the queue moving without dropping your guardrails.

To mitigate these risks, the specific continuity controls offered by the Citrix platform include:

  • Session and access continuity (cached access and session persistence)
  • Authentication continuity controls (long-lived tokens)
  • Endpoint security controls (safe browser isolation)
  • Infrastructure resiliency controls (multi-site delivery)

These controls ensure that a sudden operational outage in your environment doesn’t escalate into a catastrophic compliance breach.

Step 4: Centralize visibility across the entire access path

Institutions need unified visibility across very different user populations, from offshore developers and branch employees to call center agents handling time-sensitive account holder interactions. When disruption hits, triage breaks down quickly if teams can see only fragments of the access path for each persona. Unified visibility helps accelerate root-cause analysis, coordinate response, and satisfy regulatory scrutiny.

The Citrix platform provides:

  • End‑to‑end session insight
  • Correlation to upstream dependencies
  • Real‑time performance telemetry
  • Evidence for post‑incident reporting

This shortens restoration time and strengthens audit readiness.

Step 5: Build repeatable, auditable recovery workflows

This step matters more now because under regulations such as DORA, digital operational resilience is no longer treated as only an IT issue. The management body is expected to oversee it directly, and accountability can extend to the board itself.

Recovery must be predictable, governed, and defensible.

The Citrix platform provides an automated, programmatic approach to rollback and recovery, eliminating human error when stress levels are highest. Additionally, session recordings from the platform ensure critical evidence will be captured and available for audits.

Step 6: Validate against evolving regulatory expectations

FSI institutions are already operating under intense resilience scrutiny. This step is about staying on top of evolving supervisory expectations. To meet this challenge head-on, Citrix is continuously investing in our solution offerings—ensuring you have the modern, robust capabilities needed to validate controls, preserve evidence, and keep your resilience practices tightly aligned with requirements, like those associated with DORA, FFIEC, NIS2, and OCC. This continuous alignment ensures your architecture remains thoroughly defensive and audit-ready at a moment’s notice.

For FSI institutions, resilience is no longer just about recovery plans in a binder. It is about building an architecture that can preserve governed access, support controlled operations, and produce defensible evidence under stress. These six steps provide a practical framework for doing that—helping institutions stay aligned with evolving expectations, while using the Citrix platform to strengthen continuity, visibility, recovery, and validation.

If you’re ready to rethink your resilience architecture, the next step is a health check meeting with Citrix where you can include a discussion around resilience modernization and a possible workshop. Contact your Citrix account team to learn more.

Chad Davis

Chad Davis is Principal Marketing Manager, FSI, at Citrix.