FCA OPERATIONAL RESILIENCE · United Kingdom

FCA Operational Resilience Consulting — UK

Hands-on consulting that takes FCA-regulated firms from PS21/3 theory to audit-ready evidence. We map important business services, set impact tolerances, design severe-but-plausible cyber disruption scenarios, and run them — so you can prove to the FCA you'd stay within tolerance in a real cyber event.

PS21/3 aligned SMCR aware Scenario-tested ICO-coordinated Audit-ready evidence pack Fixed-price engagements

31 Mar 2025

FCA deadline for firms to remain within tolerance during severe disruption

£££

FCA fines for operational resilience failures — multi-million-pound range

Fixed

Gridisys PS21/3 cyber resilience engagement — fixed price

6-10 weeks

typical engagement length — gap to audit-ready

Cybersecurity Consulting + 24/7 SOC Monitoring

Every Gridisys engagement is built on two pillars — strategic consulting to design the right controls, and managed SOC monitoring to keep them effective.

Cybersecurity Consulting

UK consulting engagements: risk assessment, security architecture, conditional access design, compliance (Cyber Essentials, UK GDPR, FCA PS21/3, NIS2), incident-response planning. Board-ready documentation, no jargon, no surprise invoices.

  • Risk assessment + security architecture review
  • Conditional access + Entra ID hardening design
  • Cyber Essentials / UK GDPR / FCA / NIS2 compliance support
  • Incident response planning + tabletop exercises
  • Vendor + supply-chain security assessment
  • Board / DPO reporting + evidence pack

Managed SOC Monitoring · 24/7

AI-augmented Security Operations Centre — continuous monitoring across Microsoft 365 / Entra ID, Defender, on-prem, and cloud. UK-based analysts, sub-hour triage on critical alerts. No long contract required.

  • 24/7 SIEM monitoring — Microsoft 365, Entra ID, Defender, Azure, on-prem logs
  • BEC + mailbox-compromise + OAuth grant abuse detection
  • Suspicious sign-in + conditional access drift alerting
  • Ransomware + lateral-movement detection from EDR + Defender
  • Sub-hour triage on critical alerts, monthly ops report
  • Optional + integrated with consulting engagements

Most engagements start with consulting (1-2 weeks), then SOC monitoring (ongoing ) keeps the controls effective.

GET A QUOTE

Pricing tailored to your needs

Every engagement is scoped to your environment and requirements. Book a free consultation for a tailored quote — no obligation.

What we cover

Practical, board-ready consulting — no jargon, no surprise invoices.

Important Business Service mapping

We help you identify and document the services your firm could not survive interrupting — payments, client money, trading, claims handling — and the people, processes, third parties, and IT that support them.

Impact tolerance setting

We work with your leadership to set objectively-measurable impact tolerances for each IBS — clients, markets, and firm-integrity impact, with time horizons (e.g. 'tolerate 4 hours of disruption').

Severe-but-plausible cyber scenarios

We design cyber-specific disruption scenarios aligned to the NCSC threat categories — ransomware, BEC, third-party outage, insider — that meet FCA's 'severe but plausible' bar.

Scenario testing & evidence

We run table-top and live scenario tests, document results against tolerances, and produce the evidence pack your FCA supervisor expects: identified vulnerabilities, remediation actions, and timelines.

Self-assessment & lessons learned

Prepared self-assessment template aligned to SUP 17.7, with internal lessons-learned register, governance mapping, and sign-off chain for your SMCR accountable individuals.

Third-party concentration risk

Mapping of critical third parties (cloud, payment, MSP, custody) and the contractual exit strategies the FCA expects to see included in your operational resilience register.

How we work

1

IBS discovery (week 1-2)

Workshops with operations, IT, risk, and compliance. We identify important business services and document supporting resources and dependencies.

2

Tolerances & scenarios (week 3-4)

Impact tolerance setting with leadership. We design 3-5 severe-but-plausible cyber scenarios and the testing plan.

3

Execution (week 5-8)

Run scenario tests, capture evidence, identify vulnerabilities, agree remediation roadmap with owners and due dates.

4

Evidence & sign-off (week 9-10)

Deliver the audit-ready evidence pack, governance chain, and self-assessment template — ready for FCA supervisor review or internal audit.

Sectors we protect

Wealth managers & IFAs Payment institutions & EMI Insurance intermediaries Consumer credit firms Mortgage brokers Banks & building societies
FREE CONSULTATION

FCA operational resilience — audit-ready in 10 weeks

Free 30-minute scoping call for FCA-regulated firms. We assess your current PS21/3 readiness and produce an evidence roadmap.

Frequently asked questions

Gridisys

AI-powered cybersecurity and app development. Protecting and building for businesses worldwide.

© 2026 Gridisys. All rights reserved.Gridisys Ltd — Company No. 15780405 — Registered in England & WalesRegistered Office: 128 City Road, London, United Kingdom, EC1V 2NX

We use cookies to improve your experience and analyse site traffic. By clicking "Accept", you consent to our use of cookies. Learn more.