FCA Operational Resilience & Cybersecurity: What UK Firms Need in 2025
FCA Operational Resilience & Cybersecurity: What UK Firms Need in 2025
The FCA's operational resilience rules (PS21/3) came into full effect in March 2025. UK financial services firms must now demonstrate they can remain within impact tolerances for important business services, even during severe disruption including cyber attacks.
The FCA Operational Resilience Framework
Firms must:
- Identify important business services
- Set impact tolerances (maximum disruption before harm becomes intolerable)
- Map people, processes, technology, facilities, and information
- Scenario test — including cyber attack scenarios
- Remediate gaps identified
- Self-assess annually
Cyber Attack Scenarios the FCA Expects You to Test
- Ransomware encrypting your systems
- Denial-of-service against your client portal
- Credential compromise leading to unauthorised client account access
- Third-party technology provider compromised
- Data breach exposing client financial information
SMCR Accountability
Under SMCR, specific Senior Managers are accountable for cybersecurity. Typically the COO or CRO. They need real-time information about security posture — not just quarterly board reports.
FCA-Expected Cybersecurity Controls
- MFA for all users with access to client data or critical systems
- Regular privileged access reviews
- 24/7 security monitoring (or documented equivalent)
- Incident detection capabilities proportionate to firm size
- Logging sufficient to support post-incident investigation
- Documented and tested incident response plan
- Third-party risk due diligence
FCA SYSC 15A Notifications
From 31 March 2025, firms must notify the FCA when a cyber incident meets the materiality threshold:
- Initial notification: by end of business the next day
- Further updates: as material information emerges
- Final notification: within 30 days of closure
This sits alongside UK GDPR obligation to notify ICO within 72 hours.
How Gridisys Supports FCA Firms
- Real-time monitoring of Microsoft Entra ID and Google Workspace
- Structured incident records for FCA SYSC 15A and ICO notifications
- Evidence of monitoring capability for SMCR accountability
- UK GDPR alignment