Scenario testing for football clubs: how to stress-test against severe but plausible disruption

A plan that has never been tested against a realistic adverse scenario is a hypothesis, not a capability. That is the principle at the heart of the fourth and final discipline in the operational resilience framework, and it is the one that most decisively separates genuine resilience from a document sitting in a drawer. Football has already experienced the exact category of disruption this article describes, more than once, and more recently than most boards realise.

This article is the sixth in our series on Operational Resilience for Football clubs. You can find other articles in this series here.

Lagom Article Header CTA
Lagom Sports Compliance

This article is brought to you by Lagom Sports Compliance -- the leading governance, risk, compliance and anti-financial crime consultancy built exclusively for professional football. We help clubs, agents and leagues navigate the IFR, UEFA licensing and EU AML obligations with proportionate, practitioner-led support.

Want to talk through what this means for your club?

Why testing is the discipline that reveals the truth

The first five articles in this series worked through four connected disciplines: identifying important business services, setting genuine impact tolerances, mapping the people and third parties each service depends on, and holding suppliers to a resilience standard. All four of those disciplines can be completed on paper. None of them tells a club anything about whether its resilience actually works until it has been tested against something that genuinely hurts.

This is precisely the gap the FCA identified in its own supervisory review of firms working through PS21/3. Firms that had built thorough self-assessment documents were, in a meaningful number of cases, found to have provided limited evidence that they had actually tested their response plans -- relying instead on the theoretical existence of a recovery process to demonstrate that they could remain within their impact tolerances. The regulator's conclusion was blunt: a plan is not evidence of resilience. A tested plan is.

Plan Not A Capability Callout

A plan that has never been tested against a realistic adverse scenario is a hypothesis, not a capability.

What makes a scenario "severe but plausible"

The standard the Financial Conduct Authority applies, and the one football clubs should adopt, is deliberately calibrated. A scenario should be severe: serious enough to genuinely test whether the club's impact tolerances hold, not a minor inconvenience the existing process would absorb without difficulty. And it should be plausible: grounded in a realistic category of event, not a remote or exotic possibility that offers little practical value in preparing the organisation. The four scenarios that follow meet both tests, and -- critically for a football club's own board -- none of them is speculative. Each maps directly onto a real, documented category of incident that has already occurred in professional football.

Scenario one: a cyberattack disabling ticketing and access control on a matchday

This is not a hypothetical designed for dramatic effect. The UK's National Cyber Security Centre published a report in 2020 documenting a ransomware attack on an English Football League club that crippled the club's corporate IT systems to the extent that it disabled the turnstile system entirely, coming close to forcing the cancellation of a league fixture -- an outcome that would have cost the club hundreds of thousands of pounds in lost matchday income, entirely separate from any ransom payment.

Tested properly against this scenario, a club should be asking: does our access-control and ticketing infrastructure sit on the same network as our wider corporate IT systems, such that a ransomware attack targeting finance or administrative systems could also take down turnstiles? Do we have a genuinely tested manual fallback -- not merely a documented one -- capable of processing the club's typical matchday attendance through a controlled, safe entry process within the impact tolerance set out in the third article of this series? And critically: has this fallback ever actually been rehearsed, under time pressure, by the people who would need to run it on the day?

Scenario two: a ransomware event during a transfer window, disrupting player and financial data

This scenario also has a documented real-world precedent, and a financial one at that. The same NCSC report referenced above separately documented a different English Football League club facing a £5 million ransom demand from cyber attackers. Separately, hackers have targeted football clubs directly during live transfer negotiations: in one documented case, attackers compromised a Premier League club director's email account during an active transfer deal, attempting to redirect the transfer fee -- reported at approximately $1.2 million -- into bank accounts under their control. A closely comparable scheme succeeded in full against a Serie A club official in 2018, resulting in the theft of more than $1.75 million from a streaming platform payment.

Tested against this scenario, a club should be examining the specific vulnerability the second article in this series identified as one of football's most time-critical important business services: player registration and transfer processing. If a ransomware event locked the club out of its own financial and registration systems on the day before a transfer deadline, could the club still complete a deal within the fixed, unforgiving window this series' third article described in detail? Could payment instructions be verified through a channel independent of the compromised system, to prevent exactly the kind of business email compromise fraud documented above? A club that has never tested this specific intersection, cyber disruption landing during the highest-pressure days of a transfer window, does not know the answer. 

Scenario three: the sudden insolvency of a critical outsourced supplier

Unlike the first two scenarios, this one does not have a single documented football precedent to point to directly -- which is precisely why it belongs in a genuine severe-but-plausible testing programme rather than being dismissed as unlikely. Supplier insolvency is a well-established category of business disruption risk across every sector that relies on outsourcing, and the fourth and fifth articles in this series established just how concentrated football's own supplier market genuinely is: a small number of stewarding, catering and ticketing technology operators serving a large proportion of the league simultaneously.

Tested properly, this scenario asks the exit-planning question from the previous article in the sharpest possible terms: if the club's stewarding provider, its catering operator, or its ticketing platform ceased trading with no notice, could the club deliver a safe matchday within days rather than weeks? Has an alternative supplier ever actually been approached, even informally, to establish realistic onboarding timescales -- or is the assumption that one exists untested? This is the scenario most likely to expose whether a club's substitutability planning is genuine or aspirational.

Scenario four: a data breach exposing player medical records

This scenario, too, has real and recent precedent in professional football, and it illustrates why data protection sits within an operational resilience programme as its own important business service, not merely as a general IT security concern. A ransomware attack on a major European football club in 2024 resulted in confirmed theft of company data including financial documents, player medical records, and confidential customer, employee and business information. Separately, a ransomware attack on a national football governing body in 2023 resulted in the confirmed theft of data relating to more than 1.2 million people connected to the organisation -- including, in some categories, medical details and disciplinary records spanning more than two decades -- with the organisation ultimately confirming it had paid a ransom to prevent the data's publication.

Tested against this scenario, a club should be asking questions that go beyond standard IT security practice: if player medical data were exfiltrated and the club faced a genuine extortion demand, who at board level is authorised to make that decision, and against what criteria? What is the club's notification obligation to players, to the relevant data protection authority, and to any competition body, and within what timeframe? Has the club's incident response plan for this specific scenario -- as opposed to a generic data breach -- actually been rehearsed with the people who would need to execute it, including whoever holds ultimate responsibility for the decision on whether to pay?

Genuine Testing Box

What genuine testing looks like, and what it does not

The FCA\'s own observations on this point, drawn from reviewing thousands of firms\' self-assessment documents, are directly applicable to football. A tabletop discussion in a boardroom, in which senior leaders talk through what they would theoretically do in a given scenario, is a useful starting point -- but it is not, on its own, genuine scenario testing. It tests whether the plan sounds coherent when narrated. It does not test whether the plan actually works under the specific pressure and confusion a real incident creates.

Genuine testing requires actually attempting the fallback process -- running the manual matchday entry procedure with real stewards under realistic time pressure, actually contacting the alternative supplier identified in exit planning to confirm the onboarding timeline is real rather than assumed, actually rehearsing the specific decision-making sequence a board would need to follow within hours of a genuine extortion demand. Each of the four incidents referenced above happened to organisations that, before the event, would very likely have described themselves as prepared. Testing is what closes the gap between describing preparedness and possessing it.

How testing connects back to the whole programme

Scenario testing is not a standalone exercise. It is the discipline that validates, or exposes the weakness of, everything else this series has covered. A test that reveals a club cannot remain within the impact tolerance it set for matchday access control means either the tolerance was unrealistic, or the mapping and mitigation behind that service is inadequate, or both -- and either finding sends the club back to revisit the earlier work with genuine evidence in hand, rather than the assumption it started with.

This is also why testing should happen at least annually, and immediately after any material change to an important business service, its supplier arrangements, or the systems underpinning it. A test conducted once, filed away, and never repeated has the same fundamental weakness as an untested plan: it tells the club what was true on the day of the test, not what remains true today.

The final article in this series turns to the domain where much of the risk in the four scenarios above ultimately concentrates: cyber and data resilience specifically, and why it deserves board-level governance in its own right rather than treatment as a delegated technical function. 

Testing is the only way to find out before the fact rather than during it.

Lagom Sports Compliance works with football clubs across governance, risk, compliance and operational resilience. If your club has not yet genuinely tested its resilience against severe but plausible disruption, we would welcome a conversation about what that process looks like for your club.

Lagom Article Header CTA
Lagom Sports Compliance

This article is brought to you by Lagom Sports Compliance -- the leading governance, risk, compliance and anti-financial crime consultancy built exclusively for professional football. We help clubs, agents and leagues navigate the IFR, UEFA licensing and EU AML obligations with proportionate, practitioner-led support.

Want to talk through what this means for your club?

Frequently asked questions: scenario testing for football clubs

Previous
Previous

Football M&A regulatory due diligence: what prospective buyers should be looking at in light of new regulations

Next
Next

August 2026 Events with Lagom Sports Compliance