logo

FCA Updates Cyber Incident and Third-Party Reporting Rules

ID: 0cfabc24-2ece-5d77-89fc-b975781823dc

STIX ID: report--0cfabc24-2ece-5d77-89fc-b975781823dc

Feed Name: Infosecurity Magazine (News)

Date Published: 2026-03-19

Date Updated: 2026-04-22

...
...

The UK Financial Conduct Authority has issued new rules to clarify what cyber-related incidents must be reported and when, creating a streamlined reporting regime with the PRA and Bank of England (single portal), removing duplicated reporting, refining required information, and adding clearer thresholds and responsibilities. The guidance highlights growing third‑party risk (40% of reported incidents in 2025 involved a third party), gives firms 12 months to prepare, and will come into force on March 18, 2027, with the FCA using reported data to share sector-wide insights and improve resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.