Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

gies and dealing with the FCA or PRA (as applica - ble) in a co-operative manner; and • comply with eight “Operational Risk and Resilience Requirements” that will apply to a CTP’s material services, such as the requirement to appropriately manage incidents that may adversely affect, or may reasonably be expected to adversely affect, the delivery of a systemic third-party service. The new regime for CTPs was created under the Finan - cial Services and Markets Act 2023, which amended the Financial Services and Markets Act 2000 (FSMA). The relevant provisions allow the UK Treasury to des - ignate a person who provides services to regulated firms and financial market infrastructures as “critical”. CTPs will typically be service providers that provide outsourced, third-party services to large numbers of financial institutions and whose services are very difficult to substitute. CTPs are required to conduct a self-assessment, which must be submitted to the regulator within three months of the CTP’s designa - tion, and annually thereafter. Although the concepts in FSMA are broadly analogous to DORA, the criteria for designation and the scope of regulatory powers differ in several important respects. 3.3 Key Operational Resilience Obligations The FCA has demonstrated a strong focus on cyber - security in the financial services industry. This is par - ticularly relevant in the context of: • Principle 3 (Management and Control) of the FCA Handbook’s Principles for Businesses, which states that “a firm must take reasonable care to organise and control its affairs responsibly and effectively, with adequate risk management sys - tems”; and • Principle 11 (Relations with Regulators), which requires that “a firm must deal with its regulators in an open and co-operative way and must dis - close to the FCA appropriately anything relating to the firm of which that regulator would reasonably expect notice”. In relation to Principle 11, the FCA has confirmed that regulated firms must report material cyber-incidents. The FCA considers that an incident may be material if it:

• results in significant loss of data or the availability or control of a firm’s IT systems; • affects a large number of customers; and • results in unauthorised access to, or malicious software present on, a firm’s information and com - munication systems. The FCA goes on to require that, where such an inci - dent is deemed to be material: • the FCA (and the PRA for dual-regulated firms) should be notified; • if the incident is criminal, Action Fraud (the UK’s national fraud and cybercrime reporting centre) should be contacted; and • where the incident is also a personal data breach, organisations may need to report the incident to the ICO. The FCA also recommends that firms refer to the NCSC guidance on reporting incidents, and that reports be shared on the Cyber Security Information Sharing Partnership (CiSP) platform. The CiSP is a key information-sharing organisation in the UK. It is a joint industry and UK government initiative managed by the NCSC. The CiSP allows members to voluntarily exchange cyber-risk information in a secure environ - ment, thereby reducing the impact of cyber-risks on UK businesses in general. More generally, as part of the FCA’s goal to assist firms in becoming more resilient to cyber-attacks, it recommends that firms of all sizes develop a “security culture,” identify and prioritise information assets and constantly evolve to meet new threats. In addition, certain categories of FCA-regulated firms have additional reporting requirements. By way of example, payment services providers are required to report major operational and security incidents pursu - ant to the PSRs. For CTPs, the rules established in the CTP Policy Statement introduce a phased approach to notifica - tions for incidents affecting CTP services, including those that impact the availability, authenticity, integrity or confidentiality of assets. This reporting will consist of:

448 CHAMBERS.COM

Powered by