Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

essential services that the OES provides. Although serious incidents must be reported under the NIS Regulations, the ICO has also explained that software vulnerabilities – ie, weaknesses in a system that can be exploited by an attacker – may also need to be reported, as per the “additional information” required in the ICO’s NIS reporting form. 2.4 State Responsibilities and Obligations This is not applicable in the UK. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation In the UK, operational resilience in the financial sec - tor is primarily addressed by the FCA, the Prudential Regulatory Authority (PRA) and the Bank of England (BoE) in their rules and guidance on requirements to strengthen operational resilience in the financial services sector – for example, the FCA’s rules on operational resilience under Chapter 15A of its Sen - ior Management Arrangements, Systems and Con - trols Sourcebook and the PRA’s supervisory state - ment “Operational resilience: Impact tolerances for important business services” (SS1/21) (collectively, the “Operational Resilience Requirements”), which were published on 31 March 2022 and address how firms identify, map, test and enhance their important business services to withstand disruptions. From 31 March 2025, UK firms have been required to perform mapping and testing to ensure they remain within impact tolerances for each important business ser - vice. The rules are intended to align closely (albeit not entirely) with international standards and other regimes, such as the EU’s Digital and Operational Resilience Act (DORA). In November 2024, the FCA, the PRA and the BoE published a joint policy statement, “Operational resil - ience: Critical third parties to the UK financial sector” (PS16/24) (the “CTP Policy Statement”). This con - firmed that operational resilience remains a priority for the regulators and that they are focusing, among other things, on further defining obligations regard - ing critical third parties (CTPs). The CTP requirements

apply regardless of the service provider’s location (see 3.2 ICT Service Provider Contractual Requirements for further details). In December 2024, the PRA, the FCA and the BoE published further consultation papers – respectively, “Operational resilience: Operational incident and out - sourcing and third-party reporting” (PRA CP17/24) and “Operational Incident and Third-Party Reporting” (FCA CP24/28). The papers propose a framework for reporting operational incidents and material third- party arrangements. Notably, the proposals would require firms to report some incidents which fall short of breaching the impact tolerance of the relevant busi - ness service under the operational resilience rules. In October 2025, the PRA, the FCA and the BoE published a review of “effective practices” which the authorities had observed in the self-assessments of relevant firms. Such practices include the implemen - tation of “pre-defined crisis communication” plans, testing against impact tolerance metrics beyond dura - tion alone (eg, volume, payment type, and value), and the use of immutable back-ups to accelerate cyberat - tack recovery. In the event of an incident causing major disruption to UK financial services, the PRA, the FCA, the BoE and HM Treasury may coordinate a joint response under the Authorities Response Framework. 3.2 ICT Service Provider Contractual Requirements As noted in 3.1 Scope of Financial Sector Opera- tional Resilience Regulation above, CTPs are a key focus of UK financial services operational resilience. The CTP Policy Statement introduced new rules that apply to a CTP designated under the regime. Under the applicable rules, CTPs are expected to: • meet the minimum resilience standards in respect of any “systemic third party services” that they are providing to financial services firms; • comply with six “Fundamental Rules”, five of which are applicable specifically in relation to the provision of systemic third-party services to firms. These six rules include having effective risk strate -

447 CHAMBERS.COM

Powered by