How FCA firms should manage cyber risk: operational resilience, SYSC governance, reporting material incidents, the ICO 72-hour rule and NCSC controls.

Cyber security is no longer just an IT concern for FCA-regulated firms. It sits at the heart of how the regulator judges whether a firm can keep serving its customers when something goes wrong. A ransomware outbreak, a compromised supplier or a data breach can stop a firm delivering the services people rely on, and the FCA expects boards to treat that possibility as a foreseeable business risk rather than a rare accident.
The regulatory picture pulls together several strands. The FCA's operational resilience rules require firms to keep important business services running through severe but plausible disruption, including cyber attacks. The Senior Management Arrangements, Systems and Controls sourcebook (SYSC) puts responsibility for adequate systems and controls squarely on senior management. Principle 11 obliges firms to tell the FCA about material cyber incidents. And separately, the Information Commissioner's Office (ICO) requires reporting of personal data breaches, in most cases within 72 hours.
This guide explains what those expectations mean in practice, how they fit together, and how the National Cyber Security Centre (NCSC) frameworks give firms a tested way to build the controls the FCA wants to see. The aim is to help compliance and operations teams turn a fragmented set of obligations into a single, coherent approach to managing cyber risk.
The FCA frames cyber security as part of operational resilience, which it defines as the ability of firms and the financial sector to prevent, adapt and respond to, and recover and learn from operational disruption. Cyber attacks are called out explicitly as one of the disruptions firms must be ready for, alongside IT outages and third-party failures.
Under the operational resilience rules, in-scope firms must identify their important business services, set impact tolerances that define the maximum tolerable disruption without causing intolerable harm, map the people, processes, technology and third parties that support those services, and test their ability to stay within tolerance through severe but plausible scenarios. The FCA's rules and guidance came into force on 31 March 2022, with firms expected to have completed mapping and testing to demonstrate they can remain within impact tolerances by 31 March 2025.
Cyber risk does not sit outside this framework. It is one of the most likely causes of a firm breaching its impact tolerances, which is why the FCA encourages scenario testing that includes a broad range of cyber threats. Firms are also expected to invest in the response and recovery capabilities they will need when prevention fails, and to learn lessons from incidents and near misses.
The regulator's supervisory work reinforces the point. Its Cyber Coordination Groups bring firms together to share good and poor practice, and its assessment tools, such as the self-assessment questionnaires used across the sector, give firms a structured way to benchmark their maturity. The consistent message is that resilience is an ongoing discipline rather than a one-off project: threats evolve, firms change their systems and suppliers, and controls that were adequate last year may not be adequate today.
The FCA's expectations start with governance. SYSC 3.1.1 requires a firm to take reasonable care to establish and maintain such systems and controls as are appropriate to its business, and SYSC 3.2.6 requires effective systems and controls for compliance with the regulatory system. Cyber security controls fall squarely within that duty, so a weak security posture is a systems and controls failing, not merely a technical shortcoming.
Accountability is personal as well as corporate. Under the Senior Managers and Certification Regime, the individual performing the Chief Operations function (SMF24) is responsible for managing the firm's internal operations or technology, which includes cyber security. Where a cyber incident reveals that a senior manager did not take reasonable steps to prevent a breach, that individual can face regulatory scrutiny.
In practice this means the board and senior management need a clear view of the firm's cyber risks, the controls in place, and the residual exposure. Cyber security should be a standing item at board or risk committee level, supported by management information that lets non-technical directors understand where the firm stands and what decisions they are being asked to make.
The NCSC provides the practical building blocks that support the FCA's outcome-focused expectations. Its 10 Steps to Cyber Security is aimed at medium to large organisations with someone dedicated to managing cyber security, and it breaks the task of protecting an organisation into ten components. The ten steps are risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management, and supply chain security.
For a baseline of technical hygiene, the NCSC's Cyber Essentials scheme is described as the minimum standard of cyber security recommended by the government for organisations of all sizes. It is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Certification is available as Cyber Essentials, which combines self-assessment with an independent audit, and Cyber Essentials Plus, which adds more rigorous independent technical testing.
Neither framework is mandated by the FCA, but both map cleanly onto the identify, protect, detect, respond and recover lifecycle the regulator expects. Adopting them gives a firm a defensible, recognised basis for its controls and a common language for discussing cyber risk with the board, auditors and the regulator.
| Framework | Owner | Focus | Best suited to |
|---|---|---|---|
| 10 Steps to Cyber Security | NCSC | Ten components covering the full cyber risk lifecycle | Firms with dedicated security resource |
| Cyber Essentials | NCSC | Five technical controls, self-assessment plus audit | Baseline hygiene for firms of any size |
| Cyber Essentials Plus | NCSC | Same five controls with independent technical testing | Firms wanting assured verification |
| Operational resilience | FCA | Keeping important business services within impact tolerance | All in-scope FCA firms |
When a cyber incident occurs, FCA firms have a reporting duty that is distinct from any data protection obligation. Under Principle 11 of the Principles for Businesses, a firm must deal with the FCA in an open and cooperative way and disclose anything of which the FCA would reasonably expect notice. That includes material cyber events. SUP 15.3 sets out the general notification framework that supports this.
The FCA points to several factors that make an incident reportable. An incident may be material where it results in a significant loss of data, affects the availability or control of the firm's IT systems, or involves unauthorised access to information systems or the presence of malicious software. Disruption to the provision of financial services, or an impact on a large number of customers, also weighs towards notification.
In the current regime, firms should contact their named FCA supervisor or use the firm notification form, and dual-regulated firms should also notify the Prudential Regulation Authority. Firms should not wait until they have completed their investigation before making contact. The FCA has confirmed new incident and third-party reporting rules that come into force on 18 March 2027, introducing a more standardised framework with clearer thresholds and definitions, so firms should track that change and update their procedures ahead of the deadline.

Where a cyber incident involves personal data, a separate obligation to the ICO can be triggered under the UK GDPR. A firm must assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. If it is, the breach must be reported to the ICO without undue delay and, where feasible, no later than 72 hours after the firm becomes aware of it.
The 72-hour clock starts when the firm discovers the breach, not when it actually happened, and it runs continuously, including weekends and bank holidays. If the risk to individuals is high, the firm must also inform the affected individuals without undue delay. The ICO makes clear that firms should not wait until they have all the facts: reporting can be done in phases under Article 33(4), so the priority is to notify within the deadline even if the picture is still incomplete.
The two regimes run in parallel. A single ransomware incident can require both an FCA notification under Principle 11 and an ICO notification under the UK GDPR, on different tests and different timelines. Firms should design their incident playbooks to assess both obligations at the same time, so neither deadline is missed while attention is focused on containment.
| Obligation | Regulator | Trigger | Timeframe |
|---|---|---|---|
| Material cyber incident | FCA | Significant data loss, IT unavailability or unauthorised access | Report to your FCA supervisor as soon as you become aware |
| Personal data breach | ICO | Breach likely to result in a risk to individuals' rights and freedoms | Without undue delay, where feasible within 72 hours |
| High-risk data breach | ICO | Breach likely to result in a high risk to individuals | Inform affected individuals without undue delay |
The obligations above overlap, so the most efficient response is a single programme rather than separate silos for security, resilience and data protection. Start by identifying the firm's important business services and the data and systems that underpin them, then use a recognised framework such as the NCSC 10 Steps to structure the controls that protect them. Cyber Essentials provides a sensible baseline to certify against.
Detection and response are where many firms are weakest. Logging and monitoring, tested incident response plans, and pre-agreed decision routes for regulatory notification turn a chaotic scramble into a managed process. Scenario testing, including realistic cyber attack simulations, is the practical way to confirm the firm can stay within its impact tolerances and to expose gaps before an attacker does.
Third parties deserve particular attention. The FCA has noted that a large share of reported cyber incidents involve a third party, so supplier due diligence, contractual security requirements and clarity over who reports what are all essential. A cyber programme that ends at the firm's own perimeter is an incomplete one. Managing all of this within a single compliance framework helps evidence to the board and the regulator that cyber risk is owned, understood and controlled.
For FCA-regulated firms, cyber security is a governance and resilience issue as much as a technical one. The regulator expects firms to identify their important business services, protect and monitor the systems behind them, respond effectively when incidents occur, and recover within impact tolerance. Senior management is accountable for having the systems and controls to make that happen, and material cyber incidents must be reported to the FCA under Principle 11.
Layered on top is the ICO's separate duty to report qualifying personal data breaches without undue delay and, where feasible, within 72 hours. Firms that treat these obligations as one connected programme, underpinned by NCSC frameworks such as the 10 Steps and Cyber Essentials, will be far better placed to meet regulatory expectations and, more importantly, to keep serving their customers when an attack lands. To build controls and reporting into a single system, explore Nasara Connect Control or request a demo.
The FCA does not have a single standalone cyber rulebook. Cyber risk is treated as part of operational resilience and of the general SYSC requirement to maintain adequate systems and controls, with cyber attacks named explicitly as a disruption firms must prepare for and stay resilient against.
Under Principle 11 and SUP 15.3, a firm must notify the FCA of material cyber incidents. An incident may be material where it involves significant data loss, affects the availability or control of IT systems, or involves unauthorised access. Firms should contact their FCA supervisor as soon as they become aware and not wait for the investigation to conclude.
Under the UK GDPR, if a personal data breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of the firm becoming aware of it. The clock starts from discovery and includes weekends and bank holidays.
They can both apply to the same incident but they are separate. A cyber attack that exposes personal data may require an FCA notification under Principle 11 and an ICO notification under the UK GDPR, each on its own test and timeline. Firms should assess both obligations at once when an incident occurs.
They are risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management, and supply chain security. Together they cover the full cyber risk lifecycle and support the FCA's resilience expectations.
Cyber Essentials is not mandated by the FCA. It is the government-recommended minimum standard built around five technical controls, and certification gives firms a recognised, defensible baseline for their cyber controls that maps onto the FCA's identify, protect, detect, respond and recover expectations.
Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.
Practical guides and updates for UK firms, straight to your inbox.