Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Starmer agrees investment deal with Japan as EU deal questioned

      UK and Japan leaders discuss bilateral trade agreements at a high-level government meeting in London.

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Adidas, Burberry and so much Beckham: The six best 2026 World Cup ad campaigns

      A screenshot capturing a significant moment from a news broadcast on June 11, 2026, at 12:17 PM, highlighting key details.

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      The best places to eat sandwiches in Lisbon, from bifanas to pregos

      Bifana do Afonsos famous bifana sandwich showcasing tender pork in a freshly baked roll with savory sauce.

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Wednesday 18 March 2026 5:00 am  |  Updated:  Tuesday 17 March 2026 5:18 pm

FCA tightens cyber reporting rules as UK firms face rising risk

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
AI is also reshaping the cyber threat landscape

The City watchdog has moved to tighten cyber and operational resilience rules for financial firms, as attacks grow more frequent and increasingly spread through third-party providers.

The Financial Conduct Authority (FCA) confirmed new requirements to standardise how firms report incidents and manage third-party risks, in a bid to improve visibility over disruptions ranging from cyber attacks to cloud outages.

The changes are designed to give regulators faster, clearer data when incidents hit, as well as to help firms understand what they need to report, and when.

“Resilience is being tested like never before,” said Mark Francis, director of specialists and wholesale sell-side at the FCA. “These changes give firms clearer rules and practical guidance to better manage disruption.”

The overhaul follows a series of high-profile outages and a sharp rise in supply chain exposure.

The FCA announced that over 40 per cent of cyber incidents reported in 2025 involved a third party, showing just how deeply financial services currently rely on external providers.

Recent disruptions at major infrastructure firms such as AWS and Cloudflare have reinforced those concerns, exposing single failures cascading across multiple businesses.

Under the new regime, firms will report through a single portal shared with the Bank of England and Prudential Regulation Authority, replacing a more fragmented system.

Reporting thresholds and definitions have also been clarified, while most firms will be able to submit shorter reports.

The rules will come into force in March 2027, with firms given a year to prepare.

Read more

‘We cannot regulate cyber threats away,’ top lawyer warns

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

Supply chain risks

The move comes as cyber risk shifts away from direct attacks towards weaker links in company supply chains, a trend increasingly affecting UK businesses beyond financial services.

Government data and industry research suggest the threat is both persistent and evolving.

Cyber incidents continue to hit a large proportion of UK organisations, while attackers are using AI tools to identify vulnerabilities faster and at greater scale.

IBM recently reported a 44 per cent rise in attacks exploiting internet-facing systems, with missing login protections and software flaws among the most common entry points.

At the same time, basic security gaps remain widespread. A separate study by SailPoint found 77 per cent of UK firms fail to deactivate accounts belonging to former employees promptly, creating an open door for credential abuse.

The growing complexity of digital operations is compounding the problem.

Businesses are now managing thousands of new identities each month, including not just employees and contractors, but also automated systems and AI agents, stretching already outdated security processes.

The government’s Cyber Security and Resilience Bill, currently moving through Parliament, mirrors this shift.

It expands oversight to include data centres and critical suppliers, and introduces stricter reporting timelines, including initial notifications within 24 hours of an incident.

Jake Ives, head of security at Intersys, said: “If a business provides services to a larger organisation, it automatically becomes a target”, warning that attackers often exploit weaker suppliers to reach higher-value systems.

Read more

UK ministers tell UK businesses to ‘step up’ cyber defences

The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

People & Organisations

  • Cyber
  • cyber attack
  • cyber risk
  • FCA
  • Financial Conduct Authority
  • financial services
  • outage
  • phishing
  • Regulation UK
  • regulator
  • watchdog

Trending Articles

  • Starmer agrees investment deal with Japan as EU deal questioned

  • Elon Musk becomes world’s first trillionaire after SpaceX mega float

  • US and Iran agree to peace deal’s text, negotiators say

  • Thames Water, energy grid, rent prices: Burnham drums up public control agenda

  • Trump ban on AI access to foreign users forces Anthropic to suspend models

More from CityAM

  • ‘We cannot regulate cyber threats away,’ top lawyer warns

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • IMF warns AI cyberattacks could trigger global financial crisis

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Cyberattacks hit UK businesses with £3.7bn in legal costs last year

    Business
    The board unaminously agreed to extend Norman's position as Chair
  • City watchdog eyes new laws for claimant firms accused of ‘harm’

    Legal
    The FCA launched a consultation on the regime for hedge funds and alternative investment managers.
  • Number of claims management firms halves after FCA clampdown

    Regulation
    The FCA has been urged to show change in its motor finance redress scheme.
  • ‘Dual squeeze’: FCA approvals for e-money licences plummet

    Fintech
    Klarna IPO announcement showcased on Times Square billboard, highlighting fintech growth and market anticipation
  • Cryptoasset approvals surge as FCA softens stance

    Crypto
    IG has pursued a new deal in its bid to beef up its crypto capabilities
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • News
  • Markets & Economics
  • Politics
  • Opinion
  • Life&Style
  • Personal Finance

Follow us for breaking news and latest updates

  • Facebook
  • X
  • Instagram
  • LinkedIn
Copyright 2026 CityAM Limited