Skip to Primary Navigation

FCA confirms new incident and third-party rules after cyberattacks

Illustration of a hacker behind a computer screen.
Updated rules will help bolster resilience and protect customers. Photo: Chesnot/Getty Images.

Regulator says new rules will make existing incident and third-party reporting clearer, more consistent, and easier for firms to follow.

The UK’s FCA has confirmed its final rules and guidance setting out requirements for reporting operational incidents and material third-party arrangements. The move follows a wave of serious and damaging cyberattacks against commercial and government entities over the past year.

The new single regimes, which will apply from March 18,detailed

Get full access, free for a month

Start your 28-day free trial to continue reading and access
all content on GRIP – no payment details required.

What’s included:

  • Every new article, plus our 5,000+ archive
  • Daily regulatory insight and guidance
  • Exclusive interviews and in-depth analysis
  • Coverage of industry-leading events and conferences
  • All podcasts and videos, featuring industry experts
  • The full set of Rules Navigator tools
  • An ad-free experience