Cybersecurity for Financial Services: UK Compliance Guide
UK financial services firms face overlapping cybersecurity obligations from the FCA, DORA, PRA and UK GDPR. This guide covers the key regulatory requirements, common threat vectors and the technical controls firms of all sizes must have in place.
Nathan Hill-Haimes
Technical Director
By Nathan Hill-Haimes, Founder, AMVIA — 9 min read. Updated 26 June 2026.
Financial services is one of the most heavily regulated sectors for cyber risk in the UK, and the bar keeps rising. The rules below apply whether you are a 10-person IFA or a 500-person asset manager — only the scale of the controls changes. This guide sets out what the regulators actually expect, where attacks come from, and the technical controls that hold up under audit. For the wider picture, start with our managed cybersecurity for UK businesses pillar and the dedicated cybersecurity for financial services firms page.
What is the regulatory landscape for financial services cybersecurity?
UK financial firms operate under one of the most demanding cyber regulatory environments of any sector, overseen primarily by the FCA and PRA, with UK GDPR enforced by the ICO. Cyber resilience is no longer an IT concern — it is a board-level compliance obligation tied to your permission to trade.
The FCA's Operational Resilience Policy Statement (PS21/3) requires firms to identify their important business services, map the dependencies that support them, and demonstrate they can remain within impact tolerances — the maximum disruption acceptable before customer harm occurs — by March 2025. Cybersecurity is central to meeting that requirement.
The Digital Operational Resilience Act (DORA), which applies to UK firms operating within or serving EU markets, took effect in January 2025. DORA imposes specific requirements around ICT risk management, incident classification and reporting, third-party ICT risk, and digital operational resilience testing — including threat-led penetration testing (TLPT) for significant institutions.
The UK's National Cyber Security Centre also publishes sector-relevant guidance that supervisors expect firms to follow as good practice. See the NCSC's 10 Steps to Cyber Security for the baseline framework regulators benchmark against.
What are the FCA's cybersecurity expectations?
The FCA expects a proportionate but genuine approach to cyber risk, evidenced by governance, controls and testing. It does not mandate specific products — it judges whether your controls match your risk, and whether senior management can demonstrate active oversight. "We didn't know" is not a defence the regulator accepts.
Key areas of FCA focus include:
- Governance: Boards and senior management must articulate the firm's cyber risk appetite, understand the controls in place, and demonstrate active oversight rather than delegating responsibility entirely to IT.
- Third-party risk: Firms must manage cyber risk across their supply chain. An attack on a critical outsourced provider can breach your operational resilience obligations even if your own systems are untouched.
- Incident response: The FCA expects tested incident response plans and notification of material operational incidents within the specified timescales.
- Access controls: Privileged access management, multi-factor authentication and regular access reviews are treated as baseline. Our guide to multi-factor authentication setup for Microsoft 365 covers the email and cloud controls insurers and auditors check first.
What are the most common threat vectors in financial services?
The three most common attack routes against regulated firms are phishing, third-party compromise and ransomware. Each exploits the same thing: financial firms hold sensitive client data, face regulatory pressure, and need near-continuous availability — a combination criminals find profitable.
Phishing and spear phishing
Targeted phishing aimed at finance teams and client-facing staff remains the most common initial access vector. Criminals research firms on LinkedIn and Companies House to craft convincing impersonation emails. Business email compromise — where an attacker impersonates the CEO or a supplier to authorise a fraudulent payment — costs UK financial firms heavily every year.
Third-party and supply chain attacks
Most UK financial firms rely on managed service providers, cloud platforms and specialist fintech integrations. A compromise of any one can expose client data or halt operations. PS21/3 and DORA both require due diligence on critical ICT third-party providers and contractually enforced security standards.
Ransomware
Ransomware against financial services has increased, with smaller regulated firms — those outside the perimeter of the very largest banks — increasingly targeted. Continuous availability requirements make these firms more likely to pay, which is exactly why criminals choose them. A fast, tested incident response capability is the difference between hours and weeks of downtime.
What technical controls does the FCA expect?
The FCA is not prescriptive about specific technologies, but supervisory guidance and industry frameworks point to a clear baseline set of controls for regulated firms. If you cannot evidence these, you will struggle in both a regulatory review and a cyber insurance application.
| Control | Why it matters | What "good" looks like |
|---|---|---|
| Multi-factor authentication | Stops the majority of account takeover | MFA on email, VPN and all cloud platforms |
| Endpoint detection & response (EDR) | Detects threats legacy antivirus misses | Managed EDR monitored 24/7 |
| Patch management | Closes known exploited vulnerabilities | Documented timescales for critical fixes |
| Network segmentation | Limits lateral movement after a breach | Client data isolated from general systems |
| Encryption | Protects UK GDPR-regulated client data | Encrypted at rest and in transit |
| Privileged access management | Limits blast radius of stolen credentials | Least-privilege, with regular access reviews |
| Security monitoring & logging | Supports incident investigation | Centralised logs, 12-month retention via a managed SOC |
These map directly onto the UK government's Cyber Essentials technical controls, which the FCA treats as a sensible minimum for smaller firms.
How does cyber insurance affect regulated firms?
Cyber insurance is now effectively standard for FCA-regulated businesses, and insurers increasingly require a minimum security posture before offering cover — typically MFA on email and a tested incident response plan. Firms that cannot evidence these controls face declined applications or substantially higher premiums.
The practical effect is that the controls your insurer demands and the controls your regulator expects have converged. Investing in MFA, EDR and monitoring once satisfies both the FCA's operational resilience expectations and your insurer's underwriting questions — and protects client data under UK GDPR at the same time.
How do you build a proportionate security programme?
Proportionality runs through all FCA guidance — what is expected of a 10-person IFA differs from a 500-person asset manager — but the principle is identical. Understand your specific risks, implement controls appropriate to them, and be able to evidence this to a regulator or auditor at any time.
In practice, a proportionate programme means:
- Mapping your important business services and their ICT dependencies.
- Closing the baseline controls above, prioritised by risk.
- Putting 24/7 monitoring over the systems that matter most.
- Testing your incident response plan at least annually, not just writing it.
- Documenting everything, so oversight is demonstrable rather than asserted.
A managed security partner with financial services experience can accelerate this significantly. AMVIA runs security, Microsoft 365 and monitoring as a single accountable provider — security-first, with Microsoft-certified engineers — for over 1,200 UK businesses, rated 4.8/5 by clients. AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner.
Does Your Security Meet FCA Expectations?
AMVIA can assess your current cybersecurity posture against FCA operational resilience requirements and identify the gaps before your regulator does.
Frequently Asked Questions
DORA is EU legislation that directly applies to firms regulated within the EU. UK firms that operate in EU markets, serve EU-based clients, or have EU subsidiaries may be in scope. UK regulators have also closely aligned their own operational resilience requirements with DORA principles. Take legal advice on your specific obligations.
The FCA expects firms to notify it of material operational incidents, including cyber attacks, under its incident reporting requirements. The notification timescale depends on the nature and severity of the incident. Firms should have a pre-defined escalation process that identifies exactly when the FCA notification threshold has been crossed.
FCA enforcement on cyber and operational resilience has focused on failures in governance and oversight, inadequate third-party risk management, delayed or inadequate incident reporting, and the absence of tested business continuity arrangements. The regulator consistently rewards proactive approaches and penalises reactive ones.
Maintain an inventory of all critical ICT third-party providers, conduct due diligence on their security posture before onboarding, include contractual security requirements in supplier agreements, and monitor suppliers on an ongoing basis. DORA adds specific requirements for concentration risk where many firms rely on the same provider. UK government research indicates more than half of large financial services firms reported a third-party supply chain attack in 2024.
At minimum, regulated firms should centrally log authentication events, privileged access activity and network connections, with enough retention to support investigation — typically 12 months. Firms with higher risk profiles or significant client data obligations should run a managed SOC providing 24/7 monitoring and alerting rather than relying on business-hours cover.
Related Reading
ISO 27001 Cybersecurity: UK Implementation Guide
A practical guide to implementing ISO 27001 information security management for UK businesses.
Cybersecurity Insurance: How Strong Security Reduces Premiums
How improving your cybersecurity posture can lower cyber insurance premiums and what insurers require.
GDPR Cybersecurity Compliance
The technical cybersecurity measures required for UK GDPR compliance, from encryption to access controls.
Protect your business → Get Cybersecurity Assessment