FCA Introduces New Cyber Incident Reporting Rules

FCA Introduces New Cyber Incident Reporting Rules

First seen 19 Mar 2026, 10:43 UTC ProfessionaladviserInfosecurity-MagazineComputing 27.9

Article Content

Browse articles
ThreatCluster

The UK Financial Conduct Authority (FCA) has updated its reporting rules for cyber-related incidents to enhance resilience in the financial services sector. This update follows industry feedback indicating confusion about reporting requirements. The FCA emphasized the increasing reliance on third-party providers, noting that over 40% of reported incidents in 2025 involved third parties. The new rules aim to provide firms with clearer guidelines on what to report and when, particularly during disruptions like cyber-attacks or outages. Firms have a 12-month preparation period before the rules take effect on March 18, 2027. The FCA plans to use the reported data to improve operational resilience and keep the industry informed during major outages. This initiative aligns with broader regulatory efforts like the EU’s Digital Operational Resilience Act (DORA).

Key Points: • FCA's new rules clarify cyber incident reporting for financial firms. • Over 40% of incidents reported in 2025 involved third-party providers. • Firms have until March 18, 2027, to comply with the new reporting regime.

Timeline

2025-01-01
FCA receives feedback on incident reporting clarity
2025-01-05
40% of reported incidents involve third parties
2026-03-18
FCA announces new reporting rules
2026-03-19
FCA publishes articles on updated rules