fsi-cyber-resilience

Implement cyber resilience with air-gapped backup and automated network isolation for core-banking workloads.

6|Updated Jun 23, 2026
One-click install
npx skills add https://github.com/aws-samples/sample-fsi-reference-architecture-jp --skill fsi-cyber-resilience
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: fsi-cyber-resilience
Source: https://github.com/aws-samples/sample-fsi-reference-architecture-jp/tree/main/skills/fsi-cyber-resilience
Command: npx skills add https://github.com/aws-samples/sample-fsi-reference-architecture-jp --skill fsi-cyber-resilience

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This skill addresses the critical need for financial institutions to maintain business continuity and recover rapidly during cyber events like ransomware or DDoS attacks.

Core Features & Use Cases

  • Logically Air-gapped Backup: Implements secure, immutable backup storage in an isolated Data Bunker account to prevent ransomware propagation.
  • Automated Network Isolation: Uses Amazon GuardDuty and Lambda to dynamically isolate compromised workloads via Network ACLs.
  • Cross-Account Recovery: Provides a structured, multi-account architecture for restoring services into a clean environment using AWS Resource Access Manager.

Quick Start

Use the fsi-cyber-resilience skill to review the architectural requirements and operational procedures for implementing a logically air-gapped backup vault and automated network isolation for your core-banking workload.

Frequently Asked Questions about fsi-cyber-resilience

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I implement logically air-gapped backups for core-banking workloads to prevent ransomware propagation?

Logically air-gapped backups prevent ransomware propagation by using immutable backup storage in an isolated Data Bunker account. This skill provides reference architecture to securely isolate backup vaults from your production core-banking environment.

How does automated network isolation work for compromised AWS workloads?

Automated network isolation uses Amazon GuardDuty to detect threats and Lambda to dynamically isolate compromised workloads by modifying Network ACLs. This skill provides implementation guidance for configuring this automated response.

Can I use AWS Resource Access Manager for cross-account recovery in financial institutions?

Yes, AWS Resource Access Manager enables cross-account recovery by providing a structured multi-account architecture to restore services into a clean environment. This skill outlines the operational procedures for this recovery process.

What is the best way to satisfy FSA and FISC cyber-security guidelines for data protection on AWS?

Satisfying FSA and FISC cyber-security guidelines requires implementing logically air-gapped backups, cross-account restore, and automated network isolation. This skill provides the reference architecture to meet these data protection requirements.

Do I need a multi-account AWS environment to achieve cyber resilience for Japanese financial institutions?

Yes, a multi-account AWS environment is required to achieve cyber resilience for Japanese financial institutions. This skill uses an isolated Data Bunker account for backups and cross-account recovery to satisfy FSA guidelines.

When do I need automated network isolation for incident response in financial workloads?

Automated network isolation is needed during cyber events like ransomware or DDoS attacks to maintain business continuity in financial workloads. This skill implements GuardDuty and Lambda to dynamically isolate compromised resources.