logo

Bank of England: Financial sector failing to implement basic cybersecurity controls

ID: 4826d073-d9f8-53a7-b68a-a533f7d49c0e

STIX ID: report--4826d073-d9f8-53a7-b68a-a533f7d49c0e

Feed Name: The Register (Security)

Date Published: 2026-01-22

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The UK’s 2025 CBEST review of financial institutions highlights recurring weaknesses—misconfigured and inconsistently patched systems, weak access controls, inadequate detection/monitoring, and staff prone to social engineering (phishing, helpdesk impersonation); NCSC notes these tactics align with groups like Scattered Spider. While CTI foundations exist and MFA adoption has improved, integration across the business and security culture remain gaps, and regulators urge firms and FMIs to strengthen resilience against sophisticated/state-backed, third-party/supply-chain, and insider threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.