Scenario testing for football clubs: how to stress-test against severe but plausible disruption
A plan that has never been tested against a realistic adverse scenario is a hypothesis, not a capability. That is the principle at the heart of the fourth and final discipline in the operational resilience framework, and it is the one that most decisively separates genuine resilience from a document sitting in a drawer. Football has already experienced the exact category of disruption this article describes, more than once, and more recently than most boards realise.
This article is the sixth in our series on Operational Resilience for Football clubs. You can find other articles in this series here.
Why testing is the discipline that reveals the truth
The first five articles in this series worked through four connected disciplines: identifying important business services, setting genuine impact tolerances, mapping the people and third parties each service depends on, and holding suppliers to a resilience standard. All four of those disciplines can be completed on paper. None of them tells a club anything about whether its resilience actually works until it has been tested against something that genuinely hurts.
This is precisely the gap the FCA identified in its own supervisory review of firms working through PS21/3. Firms that had built thorough self-assessment documents were, in a meaningful number of cases, found to have provided limited evidence that they had actually tested their response plans -- relying instead on the theoretical existence of a recovery process to demonstrate that they could remain within their impact tolerances. The regulator's conclusion was blunt: a plan is not evidence of resilience. A tested plan is.
A plan that has never been tested against a realistic adverse scenario is a hypothesis, not a capability.
What makes a scenario "severe but plausible"
The standard the Financial Conduct Authority applies, and the one football clubs should adopt, is deliberately calibrated. A scenario should be severe: serious enough to genuinely test whether the club's impact tolerances hold, not a minor inconvenience the existing process would absorb without difficulty. And it should be plausible: grounded in a realistic category of event, not a remote or exotic possibility that offers little practical value in preparing the organisation. The four scenarios that follow meet both tests, and -- critically for a football club's own board -- none of them is speculative. Each maps directly onto a real, documented category of incident that has already occurred in professional football.
Scenario one: a cyberattack disabling ticketing and access control on a matchday
This is not a hypothetical designed for dramatic effect. The UK's National Cyber Security Centre published a report in 2020 documenting a ransomware attack on an English Football League club that crippled the club's corporate IT systems to the extent that it disabled the turnstile system entirely, coming close to forcing the cancellation of a league fixture -- an outcome that would have cost the club hundreds of thousands of pounds in lost matchday income, entirely separate from any ransom payment.
Tested properly against this scenario, a club should be asking: does our access-control and ticketing infrastructure sit on the same network as our wider corporate IT systems, such that a ransomware attack targeting finance or administrative systems could also take down turnstiles? Do we have a genuinely tested manual fallback -- not merely a documented one -- capable of processing the club's typical matchday attendance through a controlled, safe entry process within the impact tolerance set out in the third article of this series? And critically: has this fallback ever actually been rehearsed, under time pressure, by the people who would need to run it on the day?
Scenario two: a ransomware event during a transfer window, disrupting player and financial data
This scenario also has a documented real-world precedent, and a financial one at that. The same NCSC report referenced above separately documented a different English Football League club facing a £5 million ransom demand from cyber attackers. Separately, hackers have targeted football clubs directly during live transfer negotiations: in one documented case, attackers compromised a Premier League club director's email account during an active transfer deal, attempting to redirect the transfer fee -- reported at approximately $1.2 million -- into bank accounts under their control. A closely comparable scheme succeeded in full against a Serie A club official in 2018, resulting in the theft of more than $1.75 million from a streaming platform payment.
Tested against this scenario, a club should be examining the specific vulnerability the second article in this series identified as one of football's most time-critical important business services: player registration and transfer processing. If a ransomware event locked the club out of its own financial and registration systems on the day before a transfer deadline, could the club still complete a deal within the fixed, unforgiving window this series' third article described in detail? Could payment instructions be verified through a channel independent of the compromised system, to prevent exactly the kind of business email compromise fraud documented above? A club that has never tested this specific intersection, cyber disruption landing during the highest-pressure days of a transfer window, does not know the answer.
Scenario three: the sudden insolvency of a critical outsourced supplier
Unlike the first two scenarios, this one does not have a single documented football precedent to point to directly -- which is precisely why it belongs in a genuine severe-but-plausible testing programme rather than being dismissed as unlikely. Supplier insolvency is a well-established category of business disruption risk across every sector that relies on outsourcing, and the fourth and fifth articles in this series established just how concentrated football's own supplier market genuinely is: a small number of stewarding, catering and ticketing technology operators serving a large proportion of the league simultaneously.
Tested properly, this scenario asks the exit-planning question from the previous article in the sharpest possible terms: if the club's stewarding provider, its catering operator, or its ticketing platform ceased trading with no notice, could the club deliver a safe matchday within days rather than weeks? Has an alternative supplier ever actually been approached, even informally, to establish realistic onboarding timescales -- or is the assumption that one exists untested? This is the scenario most likely to expose whether a club's substitutability planning is genuine or aspirational.
Scenario four: a data breach exposing player medical records
This scenario, too, has real and recent precedent in professional football, and it illustrates why data protection sits within an operational resilience programme as its own important business service, not merely as a general IT security concern. A ransomware attack on a major European football club in 2024 resulted in confirmed theft of company data including financial documents, player medical records, and confidential customer, employee and business information. Separately, a ransomware attack on a national football governing body in 2023 resulted in the confirmed theft of data relating to more than 1.2 million people connected to the organisation -- including, in some categories, medical details and disciplinary records spanning more than two decades -- with the organisation ultimately confirming it had paid a ransom to prevent the data's publication.
Tested against this scenario, a club should be asking questions that go beyond standard IT security practice: if player medical data were exfiltrated and the club faced a genuine extortion demand, who at board level is authorised to make that decision, and against what criteria? What is the club's notification obligation to players, to the relevant data protection authority, and to any competition body, and within what timeframe? Has the club's incident response plan for this specific scenario -- as opposed to a generic data breach -- actually been rehearsed with the people who would need to execute it, including whoever holds ultimate responsibility for the decision on whether to pay?
What genuine testing looks like, and what it does not
The FCA\'s own observations on this point, drawn from reviewing thousands of firms\' self-assessment documents, are directly applicable to football. A tabletop discussion in a boardroom, in which senior leaders talk through what they would theoretically do in a given scenario, is a useful starting point -- but it is not, on its own, genuine scenario testing. It tests whether the plan sounds coherent when narrated. It does not test whether the plan actually works under the specific pressure and confusion a real incident creates.
Genuine testing requires actually attempting the fallback process -- running the manual matchday entry procedure with real stewards under realistic time pressure, actually contacting the alternative supplier identified in exit planning to confirm the onboarding timeline is real rather than assumed, actually rehearsing the specific decision-making sequence a board would need to follow within hours of a genuine extortion demand. Each of the four incidents referenced above happened to organisations that, before the event, would very likely have described themselves as prepared. Testing is what closes the gap between describing preparedness and possessing it.
How testing connects back to the whole programme
Scenario testing is not a standalone exercise. It is the discipline that validates, or exposes the weakness of, everything else this series has covered. A test that reveals a club cannot remain within the impact tolerance it set for matchday access control means either the tolerance was unrealistic, or the mapping and mitigation behind that service is inadequate, or both -- and either finding sends the club back to revisit the earlier work with genuine evidence in hand, rather than the assumption it started with.
This is also why testing should happen at least annually, and immediately after any material change to an important business service, its supplier arrangements, or the systems underpinning it. A test conducted once, filed away, and never repeated has the same fundamental weakness as an untested plan: it tells the club what was true on the day of the test, not what remains true today.
The final article in this series turns to the domain where much of the risk in the four scenarios above ultimately concentrates: cyber and data resilience specifically, and why it deserves board-level governance in its own right rather than treatment as a delegated technical function.
Testing is the only way to find out before the fact rather than during it.
Lagom Sports Compliance works with football clubs across governance, risk, compliance and operational resilience. If your club has not yet genuinely tested its resilience against severe but plausible disruption, we would welcome a conversation about what that process looks like for your club.
Frequently asked questions: scenario testing for football clubs
-
Scenario testing is the practice of actively stress-testing an organisation's ability to remain within its impact tolerances for a given important business service under severe but plausible disruption, rather than assuming a documented plan would work if needed. It is distinct from a tabletop discussion or narrative walkthrough: genuine scenario testing involves actually attempting the fallback process, actually contacting alternative suppliers to confirm onboarding timescales, and actually rehearsing the decision-making a real incident would require, in order to reveal whether a resilience plan is a tested capability or an untested assumption.
-
A severe but plausible scenario is one calibrated to be serious enough to genuinely test whether an organisation's impact tolerances hold under real pressure, while remaining grounded in a realistic category of event rather than a remote or exotic possibility. The standard, adapted from the FCA's operational resilience framework, deliberately excludes both minor disruptions the existing process would absorb without difficulty and hypothetical extremes with little practical preparation value.
-
Yes. The UK's National Cyber Security Centre documented a ransomware attack on an English Football League club that disabled the club's turnstile system and came close to forcing the cancellation of a league fixture, in a report published in 2020. The same period saw a separate English club face a multi-million-pound ransom demand, hackers attempt to redirect a transfer fee during a live negotiation at a Premier League club by compromising a director's email account, a major European club suffer a ransomware attack resulting in confirmed theft of player medical records and financial data, and a national football governing body confirm it paid a ransom after attackers stole data relating to more than a million people connected to the organisation. These are documented, independently reported incidents, not hypothetical constructions.
-
A tabletop discussion, in which senior leaders talk through a scenario and describe what they would theoretically do, tests whether a plan sounds coherent when narrated. It does not test whether the plan actually functions under the specific pressure, confusion and time constraint a genuine incident creates. Regulatory observation of financial services firms working through equivalent testing obligations found that firms relying primarily on tabletop discussion, rather than genuinely attempting fallback processes and rehearsing real decision sequences, had significantly less reliable evidence of their actual resilience than firms that had tested more actively.
-
Scenario testing should be conducted at least annually for each important business service, and repeated immediately after any material change to that service, its supplier arrangements, or the underlying systems it depends on. A test conducted once and never repeated only demonstrates what was true on the day it was run, not what remains true as circumstances change -- new suppliers, new technology, and new personnel can all invalidate a testing result that was accurate when it was originally produced.
-
A negative test result is not a failure of the resilience programme -- it is the programme working as intended, by surfacing a genuine vulnerability before a real incident does. The appropriate response is to revisit the underlying work: reassess whether the impact tolerance itself was realistic, examine whether the mapping and mitigation behind the affected service is adequate, and, where necessary, invest in closing the specific gap the test identified. Boards should treat scenario test failures as a governance signal requiring documented remediation, not as an isolated technical finding to be quietly addressed.