Back to Blog
Cybersecurity 8 min read2026-07-03

FCA Operational Resilience & Cybersecurity: What UK Firms Need in 2025

FCA operational resilience cybersecurity FCA PS21/3 cybersecurity operational resilience FCA regulated firms FCA cybersecurity requirements UK

FCA Operational Resilience & Cybersecurity: What UK Firms Need in 2025

The FCA's operational resilience rules (PS21/3) came into full effect in March 2025. UK financial services firms must now demonstrate they can remain within impact tolerances for important business services, even during severe disruption including cyber attacks.

The FCA Operational Resilience Framework

Firms must:

  1. Identify important business services
  2. Set impact tolerances (maximum disruption before harm becomes intolerable)
  3. Map people, processes, technology, facilities, and information
  4. Scenario test — including cyber attack scenarios
  5. Remediate gaps identified
  6. Self-assess annually

Cyber Attack Scenarios the FCA Expects You to Test

  • Ransomware encrypting your systems
  • Denial-of-service against your client portal
  • Credential compromise leading to unauthorised client account access
  • Third-party technology provider compromised
  • Data breach exposing client financial information

SMCR Accountability

Under SMCR, specific Senior Managers are accountable for cybersecurity. Typically the COO or CRO. They need real-time information about security posture — not just quarterly board reports.

FCA-Expected Cybersecurity Controls

  • MFA for all users with access to client data or critical systems
  • Regular privileged access reviews
  • 24/7 security monitoring (or documented equivalent)
  • Incident detection capabilities proportionate to firm size
  • Logging sufficient to support post-incident investigation
  • Documented and tested incident response plan
  • Third-party risk due diligence

FCA SYSC 15A Notifications

From 31 March 2025, firms must notify the FCA when a cyber incident meets the materiality threshold:

  • Initial notification: by end of business the next day
  • Further updates: as material information emerges
  • Final notification: within 30 days of closure

This sits alongside UK GDPR obligation to notify ICO within 72 hours.

How Gridisys Supports FCA Firms

  • Real-time monitoring of Microsoft Entra ID and Google Workspace
  • Structured incident records for FCA SYSC 15A and ICO notifications
  • Evidence of monitoring capability for SMCR accountability
  • UK GDPR alignment

Book a session for FCA-regulated firms →

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.