Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Ransomware Affiliate Exposes Details of ‘The Gentlemen’ Operation

March 19, 2026

FCA Updates Cyber Incident and Third-Party Reporting Rules

March 19, 2026

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

March 19, 2026
Facebook X (Twitter) Instagram
Thursday, March 19
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»FCA Updates Cyber Incident and Third-Party Reporting Rules
News

FCA Updates Cyber Incident and Third-Party Reporting Rules

Team-CWDBy Team-CWDMarch 19, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


The UK Financial Conduct Authority (FCA) has issued new rules designed to give firms more certainty about what cyber‑related incidents to report and when, in order to bolster their cyber and business resilience.

The financial services regulator said the update came after industry feedback that organizations often aren’t clear on what to report and what information to provide when they do.

“Resilience is being tested like never before, with firms facing growing cyber threats and increasing reliance on third parties to deliver the essential financial services consumers rely on,” said FCA director of specialists and wholesale sell-side, Mark Francis.

“These changes give firms clearer rules and practical guidance to better manage disruption, while supporting our ambition to be a smarter regulator, giving us better data to spot risks, share insights and strengthen sector-wide resilience.”

Read more on FCA: Major Drop in Cyber-Attack Reports from Large UK Financial Businesses.

The new rules cover both internal cyber-related incidents and incidents and outages caused by suppliers/service providers.

The FCA said it had:

  • Created a streamlined reporting regime with the Prudential Regulation Authority (PRA) and Bank of England, featuring a single reporting portal
  • Removed duplicated incident reporting for payment service providers and credit rating agencies
  • Refined the overall information required, allowing most regulated firms to simply complete a short form
  • Added clearer guidance on thresholds, definitions and responsibilities

Third-Party Risk to the Fore

The FCA said the new reporting regime is important at a time when financial services firms are increasingly reliant on third parties.

Citing recent outages at AWS and Cloudflare which affected the industry, it said 40% of the incidents reported to the FCA in 2025 involved a third party.

This trend has been reflected in a growing focus on third-party risk management in the EU’s Digital Operational Resilience Act (DORA) and the UK’s Cyber Security and Resilience Bill currently making its way through parliament.

Firms now have 12 months to prepare for the new reporting regime, which will come into force on March 18, 2027.

The FCA said it will use the data reported to it to share insights that will help firms to improve operational resilience, as well as to keep the industry updated during major outages.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days
Next Article Ransomware Affiliate Exposes Details of ‘The Gentlemen’ Operation
Team-CWD
  • Website

Related Posts

News

Microsoft Patches 84 Flaws in March Patch Tuesday, Including Two Public Zero-Days

March 19, 2026
News

AWS Warns Hackers Have Abused Cisco Firewall Zero-Day Since January

March 19, 2026
News

UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

March 19, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views

Near-ultrasonic attacks on voice assistants

September 11, 20256 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

Why you should never pay to get paid

September 15, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.