Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026

Twenty Million US IP Connections Used by Proxy Services

June 25, 2026

Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

June 25, 2026
Facebook X (Twitter) Instagram
Thursday, June 25
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»FCA Updates Cyber Incident and Third-Party Reporting Rules
News

FCA Updates Cyber Incident and Third-Party Reporting Rules

Team-CWDBy Team-CWDMarch 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK Financial Conduct Authority (FCA) has issued new rules designed to give firms more certainty about what cyber‑related incidents to report and when, in order to bolster their cyber and business resilience.

The financial services regulator said the update came after industry feedback that organizations often aren’t clear on what to report and what information to provide when they do.

“Resilience is being tested like never before, with firms facing growing cyber threats and increasing reliance on third parties to deliver the essential financial services consumers rely on,” said FCA director of specialists and wholesale sell-side, Mark Francis.

“These changes give firms clearer rules and practical guidance to better manage disruption, while supporting our ambition to be a smarter regulator, giving us better data to spot risks, share insights and strengthen sector-wide resilience.”

Read more on FCA: Major Drop in Cyber-Attack Reports from Large UK Financial Businesses.

The new rules cover both internal cyber-related incidents and incidents and outages caused by suppliers/service providers.

The FCA said it had:

  • Created a streamlined reporting regime with the Prudential Regulation Authority (PRA) and Bank of England, featuring a single reporting portal
  • Removed duplicated incident reporting for payment service providers and credit rating agencies
  • Refined the overall information required, allowing most regulated firms to simply complete a short form
  • Added clearer guidance on thresholds, definitions and responsibilities

Third-Party Risk to the Fore

The FCA said the new reporting regime is important at a time when financial services firms are increasingly reliant on third parties.

Citing recent outages at AWS and Cloudflare which affected the industry, it said 40% of the incidents reported to the FCA in 2025 involved a third party.

This trend has been reflected in a growing focus on third-party risk management in the EU’s Digital Operational Resilience Act (DORA) and the UK’s Cyber Security and Resilience Bill currently making its way through parliament.

Firms now have 12 months to prepare for the new reporting regime, which will come into force on March 18, 2027.

The FCA said it will use the data reported to it to share insights that will help firms to improve operational resilience, as well as to keep the industry updated during major outages.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
Next Article Ransomware Affiliate Exposes Details of ‘The Gentlemen’ Operation
Team-CWD
  • Website

Related Posts

News

Twenty Million US IP Connections Used by Proxy Services

June 25, 2026
News

Adversarial Exposure Validation Turns Security Visibility into Confident Prioritization

June 25, 2026
News

KDDI Breach Affects Six Japanese ISPs, Exposes 14.2 Email Credentials

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

A quick guide to recovering a hacked account

March 21, 2026

What to consider before asking an AI chatbot for health advice

May 27, 2026

Beware of threats lurking in booby-trapped PDF files

October 7, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.