Skip to Primary Navigation

FCA confirms new incident and third-party rules after cyberattacks

Regulator says new rules will make existing incident and third-party reporting clearer, more consistent, and easier for firms to follow.

The UK’s FCA has confirmed its final rules and guidance setting out requirements for reporting operational incidents and material third-party arrangements. The move follows a wave of serious and damaging cyberattacks against commercial and government entities over the past year.

The new single regimes, which will apply from March 18,detailed

Register for free to keep reading

To continue reading this article and unlock full access to GRIP, register now. You’ll enjoy free access to all content until our subscription service launches in early 2026.

  • Unlimited access to industry insights
  • Stay on top of key rules and regulatory changes with our Rules Navigator
  • Ad-free experience with no distractions
  • Regular podcasts from trusted external experts
  • Fresh compliance and regulatory content every day