Skip to content
Monday 10 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,862.50
-0.35%
DAX
26,323.88
+0.02%
CAC 40
8,726.03
+0.13%
STOXX 50
6,535.62
+0.18%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Wednesday 18 March 2026 5:00 am  |  Updated:  Tuesday 17 March 2026 5:18 pm

FCA tightens cyber reporting rules as UK firms face rising risk

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
law firms, are the "current flavour of the month" for cyberattacks

The City watchdog has moved to tighten cyber and operational resilience rules for financial firms, as attacks grow more frequent and increasingly spread through third-party providers.

The Financial Conduct Authority (FCA) confirmed new requirements to standardise how firms report incidents and manage third-party risks, in a bid to improve visibility over disruptions ranging from cyber attacks to cloud outages.

The changes are designed to give regulators faster, clearer data when incidents hit, as well as to help firms understand what they need to report, and when.

“Resilience is being tested like never before,” said Mark Francis, director of specialists and wholesale sell-side at the FCA. “These changes give firms clearer rules and practical guidance to better manage disruption.”

The overhaul follows a series of high-profile outages and a sharp rise in supply chain exposure.

The FCA announced that over 40 per cent of cyber incidents reported in 2025 involved a third party, showing just how deeply financial services currently rely on external providers.

Recent disruptions at major infrastructure firms such as AWS and Cloudflare have reinforced those concerns, exposing single failures cascading across multiple businesses.

Under the new regime, firms will report through a single portal shared with the Bank of England and Prudential Regulation Authority, replacing a more fragmented system.

Reporting thresholds and definitions have also been clarified, while most firms will be able to submit shorter reports.

The rules will come into force in March 2027, with firms given a year to prepare.

Read more

FCA eyes tougher AI rules as Brits turn to chatbots for financial advice

An all-party parliamentary group said on Tuesday that the FCA's treatment of both internal and external whistleblowers was “alarming”.

Supply chain risks

The move comes as cyber risk shifts away from direct attacks towards weaker links in company supply chains, a trend increasingly affecting UK businesses beyond financial services.

Government data and industry research suggest the threat is both persistent and evolving.

Cyber incidents continue to hit a large proportion of UK organisations, while attackers are using AI tools to identify vulnerabilities faster and at greater scale.

IBM recently reported a 44 per cent rise in attacks exploiting internet-facing systems, with missing login protections and software flaws among the most common entry points.

At the same time, basic security gaps remain widespread. A separate study by SailPoint found 77 per cent of UK firms fail to deactivate accounts belonging to former employees promptly, creating an open door for credential abuse.

The growing complexity of digital operations is compounding the problem.

Businesses are now managing thousands of new identities each month, including not just employees and contractors, but also automated systems and AI agents, stretching already outdated security processes.

The government’s Cyber Security and Resilience Bill, currently moving through Parliament, mirrors this shift.

It expands oversight to include data centres and critical suppliers, and introduces stricter reporting timelines, including initial notifications within 24 hours of an incident.

Jake Ives, head of security at Intersys, said: “If a business provides services to a larger organisation, it automatically becomes a target”, warning that attackers often exploit weaker suppliers to reach higher-value systems.

Read more

The FCA has finally woken up to the AI revolution

FCA reception area highlighting UKs shift to market-led innovation post-Brexit in financial regulations debate

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Cyber
  • cyber attack
  • cyber risk
  • FCA
  • Financial Conduct Authority
  • financial services
  • outage
  • phishing
  • Regulation UK
  • regulator
  • watchdog

Trending Articles

  • Back to basics: Sainsbury’s gradual retreat from the British high street

  • Nottingham Forest owner Marinakis sues Crystal Palace for defamation

  • Thames Water faces fresh threat to survival after pensions regulation breach

  • Hargreaves Lansdown orders staff back to office

  • As it happened: Intel, Arm shares slide; Oil climbs higher

More from Morning Wire

  • FCA eyes tougher AI rules as Brits turn to chatbots for financial advice

    AI
    An all-party parliamentary group said on Tuesday that the FCA's treatment of both internal and external whistleblowers was “alarming”.
  • The FCA has finally woken up to the AI revolution

    Opinion
    FCA reception area highlighting UKs shift to market-led innovation post-Brexit in financial regulations debate
  • Zilch, Clearscore among five UK scale-ups to get dedicated FCA support

    Tech
    PhilandSean ZilchCo founders discussing business strategy in an office setting, highlighting innovative leadership and tea...
  • U.K. Firms Make Cyber Resilience Measurable

    Business Wire
  • City watchdog eyes rules overhaul for UK asset managers

    Regulation
    The FCA has appointed Liam Coleman interim chair of the FOS.
  • Questions raised over FCA’s new short-selling rules 

    News
    The FCA has been urged to show change in its motor finance redress scheme.
  • FCA crypto crackdown will ‘wipe out’ bad actors, says Coinbase boss 

    Crypto
    UK regulators banned the Coinbase ad
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook