Theguardian UK Regulates Major Tech Firms to Enhance Cyber Resilience in Financial Sector
Article Content
- •The Bank of England will regulate Amazon, Google, Microsoft, and Oracle starting July 13, 2026.
- •These firms are classified as 'critical third parties' to the UK financial sector.
- •The regulation aims to reduce risks from cyber-attacks and technology outages affecting financial stability.
The Bank of England has been granted regulatory powers over key tech firms, including Amazon, Google, Microsoft, and Oracle, effective July 13, 2026. This decision aims to ensure the resilience of cloud services critical to the UK financial sector and mitigate risks from cyber-attacks and technology outages. The firms designated as 'critical third parties' must undergo resilience testing and report major incidents to regulators. This move follows significant disruptions in the financial sector due to reliance on these cloud services, including a notable incident in October 2025 that affected over 2,000 companies. The regulation is part of a broader effort to enhance the UK's financial stability amid increasing cyber threats. The companies have expressed support for the initiative, emphasizing the importance of collaboration for a resilient financial ecosystem.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…