Risk & Compliance

Cyber Security for FCA-Regulated Firms: Resilience, Reporting and Controls

How FCA firms should manage cyber risk: operational resilience, SYSC governance, reporting material incidents, the ICO 72-hour rule and NCSC controls.

Cyber Security for FCA-Regulated Firms: Resilience, Reporting and Controls

Cyber security is no longer just an IT concern for FCA-regulated firms. It sits at the heart of how the regulator judges whether a firm can keep serving its customers when something goes wrong. A ransomware outbreak, a compromised supplier or a data breach can stop a firm delivering the services people rely on, and the FCA expects boards to treat that possibility as a foreseeable business risk rather than a rare accident.

The regulatory picture pulls together several strands. The FCA's operational resilience rules require firms to keep important business services running through severe but plausible disruption, including cyber attacks. The Senior Management Arrangements, Systems and Controls sourcebook (SYSC) puts responsibility for adequate systems and controls squarely on senior management. Principle 11 obliges firms to tell the FCA about material cyber incidents. And separately, the Information Commissioner's Office (ICO) requires reporting of personal data breaches, in most cases within 72 hours.

This guide explains what those expectations mean in practice, how they fit together, and how the National Cyber Security Centre (NCSC) frameworks give firms a tested way to build the controls the FCA wants to see. The aim is to help compliance and operations teams turn a fragmented set of obligations into a single, coherent approach to managing cyber risk.

Protect customersReduce risk and prevent harm
Meet obligationsStay aligned with laws and standards
Build trustStrengthen confidence with stakeholders
Improve decisionsUse insight to prioritise and act
Drive efficiencyStreamline audits and reporting

The FCA's expectations on cyber resilience

The FCA frames cyber security as part of operational resilience, which it defines as the ability of firms and the financial sector to prevent, adapt and respond to, and recover and learn from operational disruption. Cyber attacks are called out explicitly as one of the disruptions firms must be ready for, alongside IT outages and third-party failures.

Under the operational resilience rules, in-scope firms must identify their important business services, set impact tolerances that define the maximum tolerable disruption without causing intolerable harm, map the people, processes, technology and third parties that support those services, and test their ability to stay within tolerance through severe but plausible scenarios. The FCA's rules and guidance came into force on 31 March 2022, with firms expected to have completed mapping and testing to demonstrate they can remain within impact tolerances by 31 March 2025.

Cyber risk does not sit outside this framework. It is one of the most likely causes of a firm breaching its impact tolerances, which is why the FCA encourages scenario testing that includes a broad range of cyber threats. Firms are also expected to invest in the response and recovery capabilities they will need when prevention fails, and to learn lessons from incidents and near misses.

The regulator's supervisory work reinforces the point. Its Cyber Coordination Groups bring firms together to share good and poor practice, and its assessment tools, such as the self-assessment questionnaires used across the sector, give firms a structured way to benchmark their maturity. The consistent message is that resilience is an ongoing discipline rather than a one-off project: threats evolve, firms change their systems and suppliers, and controls that were adequate last year may not be adequate today.

Governance: SYSC and senior management responsibility

The FCA's expectations start with governance. SYSC 3.1.1 requires a firm to take reasonable care to establish and maintain such systems and controls as are appropriate to its business, and SYSC 3.2.6 requires effective systems and controls for compliance with the regulatory system. Cyber security controls fall squarely within that duty, so a weak security posture is a systems and controls failing, not merely a technical shortcoming.

Accountability is personal as well as corporate. Under the Senior Managers and Certification Regime, the individual performing the Chief Operations function (SMF24) is responsible for managing the firm's internal operations or technology, which includes cyber security. Where a cyber incident reveals that a senior manager did not take reasonable steps to prevent a breach, that individual can face regulatory scrutiny.

In practice this means the board and senior management need a clear view of the firm's cyber risks, the controls in place, and the residual exposure. Cyber security should be a standing item at board or risk committee level, supported by management information that lets non-technical directors understand where the firm stands and what decisions they are being asked to make.

1
Identify
Map critical assets, data, systems and suppliers, and assess the cyber risks to your important business services.
2
Protect
Apply controls such as access management, patching, secure configuration and staff training to reduce likelihood.
3
Detect
Use logging and monitoring to spot suspicious activity early, before it escalates into a major incident.
4
Respond
Follow a tested incident plan covering containment, decision-making, regulatory notification and internal escalation.
5
Recover
Restore services within impact tolerance, then review the incident and feed lessons back into controls.

NCSC frameworks: 10 Steps and Cyber Essentials

The NCSC provides the practical building blocks that support the FCA's outcome-focused expectations. Its 10 Steps to Cyber Security is aimed at medium to large organisations with someone dedicated to managing cyber security, and it breaks the task of protecting an organisation into ten components. The ten steps are risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management, and supply chain security.

For a baseline of technical hygiene, the NCSC's Cyber Essentials scheme is described as the minimum standard of cyber security recommended by the government for organisations of all sizes. It is built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Certification is available as Cyber Essentials, which combines self-assessment with an independent audit, and Cyber Essentials Plus, which adds more rigorous independent technical testing.

Neither framework is mandated by the FCA, but both map cleanly onto the identify, protect, detect, respond and recover lifecycle the regulator expects. Adopting them gives a firm a defensible, recognised basis for its controls and a common language for discussing cyber risk with the board, auditors and the regulator.

FrameworkOwnerFocusBest suited to
10 Steps to Cyber SecurityNCSCTen components covering the full cyber risk lifecycleFirms with dedicated security resource
Cyber EssentialsNCSCFive technical controls, self-assessment plus auditBaseline hygiene for firms of any size
Cyber Essentials PlusNCSCSame five controls with independent technical testingFirms wanting assured verification
Operational resilienceFCAKeeping important business services within impact toleranceAll in-scope FCA firms
How the main frameworks relate to FCA cyber resilience expectations.

Reporting material cyber incidents to the FCA

When a cyber incident occurs, FCA firms have a reporting duty that is distinct from any data protection obligation. Under Principle 11 of the Principles for Businesses, a firm must deal with the FCA in an open and cooperative way and disclose anything of which the FCA would reasonably expect notice. That includes material cyber events. SUP 15.3 sets out the general notification framework that supports this.

The FCA points to several factors that make an incident reportable. An incident may be material where it results in a significant loss of data, affects the availability or control of the firm's IT systems, or involves unauthorised access to information systems or the presence of malicious software. Disruption to the provision of financial services, or an impact on a large number of customers, also weighs towards notification.

In the current regime, firms should contact their named FCA supervisor or use the firm notification form, and dual-regulated firms should also notify the Prudential Regulation Authority. Firms should not wait until they have completed their investigation before making contact. The FCA has confirmed new incident and third-party reporting rules that come into force on 18 March 2027, introducing a more standardised framework with clearer thresholds and definitions, so firms should track that change and update their procedures ahead of the deadline.

Reporting material cyber incidents to the FCA

Reporting personal data breaches to the ICO

Where a cyber incident involves personal data, a separate obligation to the ICO can be triggered under the UK GDPR. A firm must assess whether the breach is likely to result in a risk to the rights and freedoms of individuals. If it is, the breach must be reported to the ICO without undue delay and, where feasible, no later than 72 hours after the firm becomes aware of it.

The 72-hour clock starts when the firm discovers the breach, not when it actually happened, and it runs continuously, including weekends and bank holidays. If the risk to individuals is high, the firm must also inform the affected individuals without undue delay. The ICO makes clear that firms should not wait until they have all the facts: reporting can be done in phases under Article 33(4), so the priority is to notify within the deadline even if the picture is still incomplete.

The two regimes run in parallel. A single ransomware incident can require both an FCA notification under Principle 11 and an ICO notification under the UK GDPR, on different tests and different timelines. Firms should design their incident playbooks to assess both obligations at the same time, so neither deadline is missed while attention is focused on containment.

ObligationRegulatorTriggerTimeframe
Material cyber incidentFCASignificant data loss, IT unavailability or unauthorised accessReport to your FCA supervisor as soon as you become aware
Personal data breachICOBreach likely to result in a risk to individuals' rights and freedomsWithout undue delay, where feasible within 72 hours
High-risk data breachICOBreach likely to result in a high risk to individualsInform affected individuals without undue delay
Core cyber and data breach reporting obligations for FCA-regulated firms.

Building a joined-up cyber programme

The obligations above overlap, so the most efficient response is a single programme rather than separate silos for security, resilience and data protection. Start by identifying the firm's important business services and the data and systems that underpin them, then use a recognised framework such as the NCSC 10 Steps to structure the controls that protect them. Cyber Essentials provides a sensible baseline to certify against.

Detection and response are where many firms are weakest. Logging and monitoring, tested incident response plans, and pre-agreed decision routes for regulatory notification turn a chaotic scramble into a managed process. Scenario testing, including realistic cyber attack simulations, is the practical way to confirm the firm can stay within its impact tolerances and to expose gaps before an attacker does.

Third parties deserve particular attention. The FCA has noted that a large share of reported cyber incidents involve a third party, so supplier due diligence, contractual security requirements and clarity over who reports what are all essential. A cyber programme that ends at the firm's own perimeter is an incomplete one. Managing all of this within a single compliance framework helps evidence to the board and the regulator that cyber risk is owned, understood and controlled.

Conclusion

For FCA-regulated firms, cyber security is a governance and resilience issue as much as a technical one. The regulator expects firms to identify their important business services, protect and monitor the systems behind them, respond effectively when incidents occur, and recover within impact tolerance. Senior management is accountable for having the systems and controls to make that happen, and material cyber incidents must be reported to the FCA under Principle 11.

Layered on top is the ICO's separate duty to report qualifying personal data breaches without undue delay and, where feasible, within 72 hours. Firms that treat these obligations as one connected programme, underpinned by NCSC frameworks such as the 10 Steps and Cyber Essentials, will be far better placed to meet regulatory expectations and, more importantly, to keep serving their customers when an attack lands. To build controls and reporting into a single system, explore Nasara Connect Control or request a demo.

Frequently asked questions

Is cyber security a specific FCA rule or part of operational resilience?

The FCA does not have a single standalone cyber rulebook. Cyber risk is treated as part of operational resilience and of the general SYSC requirement to maintain adequate systems and controls, with cyber attacks named explicitly as a disruption firms must prepare for and stay resilient against.

When must a firm report a cyber incident to the FCA?

Under Principle 11 and SUP 15.3, a firm must notify the FCA of material cyber incidents. An incident may be material where it involves significant data loss, affects the availability or control of IT systems, or involves unauthorised access. Firms should contact their FCA supervisor as soon as they become aware and not wait for the investigation to conclude.

What is the ICO 72-hour rule?

Under the UK GDPR, if a personal data breach is likely to result in a risk to individuals' rights and freedoms, it must be reported to the ICO without undue delay and, where feasible, within 72 hours of the firm becoming aware of it. The clock starts from discovery and includes weekends and bank holidays.

Do FCA and ICO reporting obligations overlap?

They can both apply to the same incident but they are separate. A cyber attack that exposes personal data may require an FCA notification under Principle 11 and an ICO notification under the UK GDPR, each on its own test and timeline. Firms should assess both obligations at once when an incident occurs.

What are the NCSC 10 Steps to Cyber Security?

They are risk management, engagement and training, asset management, architecture and configuration, vulnerability management, identity and access management, data security, logging and monitoring, incident management, and supply chain security. Together they cover the full cyber risk lifecycle and support the FCA's resilience expectations.

Is Cyber Essentials mandatory for FCA firms?

Cyber Essentials is not mandated by the FCA. It is the government-recommended minimum standard built around five technical controls, and certification gives firms a recognised, defensible baseline for their cyber controls that maps onto the FCA's identify, protect, detect, respond and recover expectations.

Ready to move money with confidence?

Nasara Control helps UK firms send and control payments with lower fees, better rates and full visibility.

Talk to an expert
Secure by designBank-grade security and encryption
Built for UK firmsMade for FCA-regulated businesses
Data protectedYour data stays private and controlled
Global reachCross-border payments worldwide
Accepting enquiries

Tell us what you’re working on.

New firm, FCA authorisation, ongoing compliance or controlled payments, send a note and we’ll come back within one business day.

The business control layer for firms that start, get authorised, stay compliant and make controlled payments.

Nasara Connect is a trading name of Mema Financial Services Ltd, registered with the Financial Conduct Authority as a Small Payment Institution under the Payment Services Regulations 2017 (Firm Reference Number 1040933) and with HM Revenue & Customs for anti-money laundering supervision (registration number XFML00000205542). Registered in England & Wales, company number 15382445. View on the FCA Register.

© 2026 Nasara Connect. All rights reserved.

Cyber Essentials Certified