What Does the FCA Expect from UK Financial Firms on Cyber Security?

The Financial Conduct Authority (FCA) expects regulated firms to manage cyber risks effectively, protect customers and maintain appropriate systems and controls. For financial services organisations, this means more than preventing cyber attacks. Firms must also understand how security incidents could disrupt important business services, affect customers and create wider operational risks.

The exact requirements depend on a firm’s activities, regulatory status and applicable rules. However, governance, risk management, third-party oversight, incident response and operational resilience are important considerations for many firms. With the FCA continuing to review how organisations manage disruption and emerging threats, financial firms should regularly assess whether their controls remain effective.

Why Is Cyber Security a Priority for UK Financial Services?

Banks, insurers, payment providers, investment firms and fintech businesses rely on interconnected systems to process transactions, manage customer accounts and deliver essential services. A cyber incident can therefore affect more than an individual organisation. It may interrupt payments, expose sensitive information, undermine customer confidence or disrupt other businesses that depend on its services.

Common threats include ransomware, credential theft, Business Email Compromise (BEC), insider threats, distributed denial-of-service attacks and compromises involving third-party suppliers.

Financial firms should consider these threats in the context of their own operations. For example, a compromised finance employee’s account could lead to fraudulent payments, while a cloud service outage could prevent customers from accessing essential services.

Understanding the wider cyber threat landscape helps organisations identify relevant risks and prioritise security measures based on their potential business impact.

What Are the FCA’s Main Cyber Security Expectations?

The FCA does not prescribe one universal cyber security framework for every regulated firm. Its expectations arise from applicable regulatory requirements, including relevant systems and controls rules, alongside requirements that apply to particular firms and activities.

Organisations should establish a risk management approach that reflects their size, complexity, services and exposure to cyber threats. Key areas to review include:

  • Governance and accountability: Senior management should understand material cyber risks, oversee appropriate controls and ensure responsibilities are clearly defined.
  • Risk assessment: Firms should identify vulnerabilities, assess the likelihood and potential impact of cyber incidents, and prioritise remediation.
  • Access and information security: Appropriate authentication, access restrictions, monitoring and data protection measures should be in place.
  • Third-party oversight: Firms should understand the risks associated with outsourced services, technology providers and other critical dependencies.
  • Incident response: Documented procedures should support effective detection, escalation, containment and recovery.
  • Testing and improvement: Security controls and response arrangements should be reviewed and tested regularly.

A cyber security risk assessment can help identify technical weaknesses that may contribute to wider business risks. However, a technical assessment alone does not demonstrate compliance with every applicable FCA requirement. Firms also need suitable governance, documented processes and evidence that identified issues are being addressed.

How Does Operational Resilience Affect Financial Firms?

Operational resilience is a major part of the FCA’s regulatory approach. It concerns an organisation’s ability to prevent, adapt to, respond to and recover from operational disruption while continuing to deliver important business services.

For firms within the scope of the FCA’s operational resilience rules, the transition period ended on 31 March 2025. These firms were required to complete the necessary mapping and testing and ensure they could remain within their impact tolerances for important business services.

This involves identifying services whose disruption could cause intolerable harm to consumers or threaten market integrity, setting appropriate impact tolerances, understanding the resources supporting those services and testing how they would withstand severe but plausible scenarios. Firms must also address identified vulnerabilities and maintain appropriate governance and self-assessment processes.

The FCA’s March 2026 review highlighted areas for continued improvement, including clearer accountability, better evidence of testing, meaningful impact tolerances and stronger oversight of remediation activities.

Financial organisations can explore these expectations further in Gradeon’s guide to operational resilience and board accountability.

Operational resilience should not be treated simply as a disaster recovery exercise. Firms need to understand the impact of disruption on customers and services, including dependencies on people, technology, information and external providers.

How Should Financial Firms Manage Third-Party Cyber Risks?

Financial organisations increasingly rely on cloud platforms, payment processors, software providers and managed IT services. Although these relationships can improve efficiency, they may also introduce vulnerabilities outside the firm’s direct control.

The FCA expects firms to manage relevant outsourcing and third-party risks appropriately. Where operational resilience rules apply, firms must understand how external providers and other dependencies support their important business services.

Practical measures include:

  • Assessing a provider’s security and resilience before engagement.
  • Defining security, incident notification and recovery responsibilities in contracts.
  • Reviewing supplier access to sensitive systems and information.
  • Monitoring material changes in supplier risk and service performance.
  • Understanding alternative arrangements if a critical provider becomes unavailable.
  • Maintaining appropriate oversight of remediation and contractual obligations.

A supplier’s failure does not automatically remove a regulated firm’s responsibility for meeting its own applicable obligations. Organisations should therefore understand which external dependencies could affect customers or prevent important business services from operating within their impact tolerances.

What Are the FCA’s Expectations for Cyber Incident Reporting in 2026?

Financial firms should maintain clear procedures for identifying, escalating and reporting incidents. The appropriate response depends on the incident’s nature, severity, business impact and the regulatory requirements applicable to the firm.

A documented process should establish who assesses an incident, who makes reporting decisions, how relevant information is recorded and how communications are managed. Firms should also consider whether an incident triggers separate obligations relating to data protection, payment services or other applicable regulatory regimes.

An important development for 2026 is the FCA’s new incident and third-party reporting framework, confirmed on 18 March 2026. The new requirements are scheduled to come into force on 18 March 2027, giving firms time to prepare for the changes.

Financial organisations should review the FCA’s official operational resilience guidance and relevant reporting guidance to understand the requirements applicable to them. They should not assume that the future reporting rules are already in force or that every incident must be reported through the same process.

Preparation should include reviewing reporting thresholds, assigning responsibilities, checking internal escalation routes and ensuring that relevant teams can gather accurate information promptly.

Why Should Financial Firms Test Their Incident Response Plans?

A documented incident response plan is useful only if people understand their responsibilities and can follow the process under pressure. Testing helps organisations identify gaps in decision-making, communication and recovery arrangements before a real incident occurs.

Exercises should reflect realistic scenarios for the firm’s business model. These might include ransomware affecting payment systems, a compromised executive account, a cloud service outage or a third-party provider becoming unavailable.

A useful exercise should test:

  • How incidents are detected and escalated.
  • Who has authority to make urgent decisions.
  • How technical teams coordinate with senior management.
  • How customers, suppliers and regulators are informed where required.
  • Whether recovery arrangements support important business services.
  • How lessons are documented and turned into corrective actions.

Gradeon’s guide to conducting a cyber tabletop exercise explains how organisations can practise their response to realistic incidents and identify improvements.

Testing should also connect to the firm’s wider operational resilience programme where relevant. Findings need clear owners, target dates and appropriate oversight rather than remaining as observations in an exercise report.

How Can Financial Firms Strengthen Identity and Access Management?

Compromised credentials can give attackers access to customer information, internal systems and financial processes. Strong identity and access management controls help reduce this risk, particularly where employees, contractors and external providers have access to sensitive environments.

Financial organisations should consider implementing multi-factor authentication, applying least-privilege access, reviewing privileged accounts and removing unnecessary permissions. Monitoring should also help identify unusual sign-in activity and suspicious changes to account settings.

Payment processes require additional attention. Employees should independently verify unusual payment requests and changes to supplier bank details rather than relying solely on email instructions. These procedures can help reduce the risk of fraud even when an attacker bypasses some technical controls.

Regular penetration testing can help firms evaluate whether security weaknesses could be exploited in practice. The scope should reflect the systems and risks being assessed, and identified issues should be prioritised and remediated appropriately.

Common Mistakes Financial Firms Should Avoid

Even organisations with established security policies can have gaps between documented controls and how those controls operate in practice.

Common problems include treating cyber security as solely an IT responsibility, failing to account for critical supplier dependencies, leaving excessive user permissions in place and testing response plans too infrequently.

Other weaknesses include incomplete incident records, unclear reporting responsibilities and remediation plans without accountable owners or realistic deadlines.

Firms should also avoid treating a framework, certification or successful technical test as proof that all regulatory obligations have been met. Such measures can support a broader control environment, but they do not replace an assessment of the firm’s own regulatory responsibilities and operational risks.

Frequently Asked Questions

Does the FCA require a specific cyber security framework?

No single framework is mandatory for every FCA-regulated firm. Organisations should identify the rules and guidance that apply to their activities and implement systems and controls appropriate to their risks. A recognised framework may help structure the programme, but using one does not automatically demonstrate compliance.

Do all financial firms have the same operational resilience obligations?

No. The FCA’s operational resilience rules apply to specified categories of firms. Organisations should confirm whether they fall within scope and identify any additional requirements arising from their regulatory status or other applicable regimes.

How often should financial firms review cyber security controls?

Controls should be reviewed regularly and when material changes occur, such as new technology, significant supplier changes, emerging threats or changes to business operations. Testing, monitoring, incident findings and risk assessments should inform ongoing improvements.

What should a financial firm do after a cyber incident?

The firm should activate its incident response procedures, assess the impact, contain the incident where possible and begin appropriate recovery activities. It should preserve relevant evidence, communicate with affected stakeholders where appropriate and assess its regulatory reporting obligations. Reporting decisions should be based on the applicable rules and circumstances of the incident.

What changes to FCA incident reporting should firms prepare for in 2026?

The FCA confirmed new incident and third-party reporting requirements on 18 March 2026, with implementation scheduled for 18 March 2027. Firms should use the preparation period to review their reporting processes, responsibilities and ability to collect the required information.

Building Stronger Cyber Resilience in Financial Services

Meeting the FCA’s cyber security expectations requires an ongoing approach that connects governance, technical security, supplier oversight and operational resilience. Financial firms should understand the requirements that apply to their activities, identify vulnerabilities that could affect customers and important business services, and maintain evidence that controls are operating effectively.

Regular testing, clear accountability and timely remediation help organisations prepare for disruption rather than relying solely on preventive measures. By reviewing regulatory developments and improving their security arrangements continuously, financial firms can strengthen their resilience and support the reliable delivery of services to customers.