Cybersecurity 2026

UK Law and Practice Contributed by: William Long, Francesca Blythe, Eleanor Dodding and Matthias Bruynseraede, Sidley Austin LLP

3.5 International Data Transfers This is not applicable in the UK. 3.6 Threat-Led Penetration Testing

• an initial notification, without undue delay, to the relevant parties after the CTP is aware that the relevant incident has occurred; • one or more intermediate incident reports as needed; and • a final incident report. The CTP Policy Statement notes that regulators “nor - mally expect” a CTP to submit a final incident report within 30 working days of the incident’s resolution. Looking forward, the Operational Resilience Require - ments will require financial services firms to comply with a number of obligations around operational resil - ience, including: • performing mapping and scenario testing (includ - ing for cyber-related disruptions); • investing to enable a firm to operate within its impact tolerances and respond effectively and recover quickly when disruption does occur; • documenting and maintaining operational resil - ience policies and procedures; • assigning clear roles and responsibilities within the firm; and • engaging with key stakeholders (eg, regulators, clients, suppliers, and CTPs). As described in 3.1 Scope of Financial Sector Opera- tional Resilience Regulation , in December 2024, the PRA and FCA published further consultation papers – respectively, “Operational resilience: Operational inci - dent and outsourcing and third-party reporting” (PRA CP17/24) and “Operational Incident and Third-Party Reporting” (FCA CP24/28), which propose a frame - work for reporting operational incidents and notifi - cation and reporting of material third-party arrange - ments. As of January 2026, the comments from the consultation papers have not been published. 3.4 Operational Resilience Enforcement The FCA and PRA have a broad legislative mandate and powers to enforce rules made under the CTP regime against designated CTPs. As this is a relatively new regime, it remains to be seen how such powers will be exercised. As of January 2026, no entities have yet been designated as CTPs.

See 3.3 Key Operational Resilience Obligations for operational resilience requirements, including the requirement to perform mapping and testing to ensure firms remain within impact tolerances for each impor - tant business service. In addition, the Critical National Infrastructure Bank - ing Supervision and Evaluation Testing (CBEST) pro - gramme is a cyber-assessment tool that assists UK firms in assessing the cyber-resilience of key finan - cial institutions through security testing conducted in “live” corporate environments. On 13 December 2024, the FCA (together with the PRA) published their annual CBEST thematic report (the “CBEST Report”). The CBEST Report contains cyber-resilience good- practice recommendations and insights, including those from the NCSC, to help firms maintain their operational resilience. The good practice recommen - dations are the result of a programme that assesses the cyber-resilience of systemic financial institutions through live testing. The report highlights the impor - tance of building a strong foundation of cyber hygiene to prevent common cyber incidents, including training and awareness and robust authentication. The key areas of focus based on the 2024 CBEST Report are: • cybersecurity risks to assets and individuals; • cyber-risk management and impact-based approaches to the protection of key resources (people, process, technology and data); • detection and response capabilities leveraging the latest threat intelligence; and • cyber-incident response to eradicate threats and mitigate impacts.

4. Cyber-Resilience 4.1 Cyber-Resilience Legislation

As outlined in 1.2 Cybersecurity Laws , several laws supplement the UK’s cyber-resilience strategy along -

449 CHAMBERS.COM

Powered by