Cybersecurity

Cybersecurity for Financial Services: UK Compliance Guide

UK financial services firms face overlapping cybersecurity obligations from the FCA, DORA, PRA and UK GDPR. This guide covers the key regulatory requirements, common threat vectors and the technical controls firms of all sizes must have in place.

NH

Nathan Hill-Haimes

Technical Director

9 min read·Mar 2026

By Nathan Hill-Haimes, Founder, AMVIA — 9 min read. Updated 26 June 2026.

Financial services is one of the most heavily regulated sectors for cyber risk in the UK, and the bar keeps rising. The rules below apply whether you are a 10-person IFA or a 500-person asset manager — only the scale of the controls changes. This guide sets out what the regulators actually expect, where attacks come from, and the technical controls that hold up under audit. For the wider picture, start with our managed cybersecurity for UK businesses pillar and the dedicated cybersecurity for financial services firms page.

What is the regulatory landscape for financial services cybersecurity?

UK financial firms operate under one of the most demanding cyber regulatory environments of any sector, overseen primarily by the FCA and PRA, with UK GDPR enforced by the ICO. Cyber resilience is no longer an IT concern — it is a board-level compliance obligation tied to your permission to trade.

The FCA's Operational Resilience Policy Statement (PS21/3) requires firms to identify their important business services, map the dependencies that support them, and demonstrate they can remain within impact tolerances — the maximum disruption acceptable before customer harm occurs — by March 2025. Cybersecurity is central to meeting that requirement.

The Digital Operational Resilience Act (DORA), which applies to UK firms operating within or serving EU markets, took effect in January 2025. DORA imposes specific requirements around ICT risk management, incident classification and reporting, third-party ICT risk, and digital operational resilience testing — including threat-led penetration testing (TLPT) for significant institutions.

The UK's National Cyber Security Centre also publishes sector-relevant guidance that supervisors expect firms to follow as good practice. See the NCSC's 10 Steps to Cyber Security for the baseline framework regulators benchmark against.

What are the FCA's cybersecurity expectations?

The FCA expects a proportionate but genuine approach to cyber risk, evidenced by governance, controls and testing. It does not mandate specific products — it judges whether your controls match your risk, and whether senior management can demonstrate active oversight. "We didn't know" is not a defence the regulator accepts.

Key areas of FCA focus include:

  • Governance: Boards and senior management must articulate the firm's cyber risk appetite, understand the controls in place, and demonstrate active oversight rather than delegating responsibility entirely to IT.
  • Third-party risk: Firms must manage cyber risk across their supply chain. An attack on a critical outsourced provider can breach your operational resilience obligations even if your own systems are untouched.
  • Incident response: The FCA expects tested incident response plans and notification of material operational incidents within the specified timescales.
  • Access controls: Privileged access management, multi-factor authentication and regular access reviews are treated as baseline. Our guide to multi-factor authentication setup for Microsoft 365 covers the email and cloud controls insurers and auditors check first.

What are the most common threat vectors in financial services?

The three most common attack routes against regulated firms are phishing, third-party compromise and ransomware. Each exploits the same thing: financial firms hold sensitive client data, face regulatory pressure, and need near-continuous availability — a combination criminals find profitable.

Phishing and spear phishing

Targeted phishing aimed at finance teams and client-facing staff remains the most common initial access vector. Criminals research firms on LinkedIn and Companies House to craft convincing impersonation emails. Business email compromise — where an attacker impersonates the CEO or a supplier to authorise a fraudulent payment — costs UK financial firms heavily every year.

Third-party and supply chain attacks

Most UK financial firms rely on managed service providers, cloud platforms and specialist fintech integrations. A compromise of any one can expose client data or halt operations. PS21/3 and DORA both require due diligence on critical ICT third-party providers and contractually enforced security standards.

Ransomware

Ransomware against financial services has increased, with smaller regulated firms — those outside the perimeter of the very largest banks — increasingly targeted. Continuous availability requirements make these firms more likely to pay, which is exactly why criminals choose them. A fast, tested incident response capability is the difference between hours and weeks of downtime.

What technical controls does the FCA expect?

The FCA is not prescriptive about specific technologies, but supervisory guidance and industry frameworks point to a clear baseline set of controls for regulated firms. If you cannot evidence these, you will struggle in both a regulatory review and a cyber insurance application.

ControlWhy it mattersWhat "good" looks like
Multi-factor authenticationStops the majority of account takeoverMFA on email, VPN and all cloud platforms
Endpoint detection & response (EDR)Detects threats legacy antivirus missesManaged EDR monitored 24/7
Patch managementCloses known exploited vulnerabilitiesDocumented timescales for critical fixes
Network segmentationLimits lateral movement after a breachClient data isolated from general systems
EncryptionProtects UK GDPR-regulated client dataEncrypted at rest and in transit
Privileged access managementLimits blast radius of stolen credentialsLeast-privilege, with regular access reviews
Security monitoring & loggingSupports incident investigationCentralised logs, 12-month retention via a managed SOC

These map directly onto the UK government's Cyber Essentials technical controls, which the FCA treats as a sensible minimum for smaller firms.

How does cyber insurance affect regulated firms?

Cyber insurance is now effectively standard for FCA-regulated businesses, and insurers increasingly require a minimum security posture before offering cover — typically MFA on email and a tested incident response plan. Firms that cannot evidence these controls face declined applications or substantially higher premiums.

The practical effect is that the controls your insurer demands and the controls your regulator expects have converged. Investing in MFA, EDR and monitoring once satisfies both the FCA's operational resilience expectations and your insurer's underwriting questions — and protects client data under UK GDPR at the same time.

How do you build a proportionate security programme?

Proportionality runs through all FCA guidance — what is expected of a 10-person IFA differs from a 500-person asset manager — but the principle is identical. Understand your specific risks, implement controls appropriate to them, and be able to evidence this to a regulator or auditor at any time.

In practice, a proportionate programme means:

  • Mapping your important business services and their ICT dependencies.
  • Closing the baseline controls above, prioritised by risk.
  • Putting 24/7 monitoring over the systems that matter most.
  • Testing your incident response plan at least annually, not just writing it.
  • Documenting everything, so oversight is demonstrable rather than asserted.

A managed security partner with financial services experience can accelerate this significantly. AMVIA runs security, Microsoft 365 and monitoring as a single accountable provider — security-first, with Microsoft-certified engineers — for over 1,200 UK businesses, rated 4.8/5 by clients. AMVIA holds Cyber Essentials Plus and is a Microsoft Solutions Partner.

Does Your Security Meet FCA Expectations?

AMVIA can assess your current cybersecurity posture against FCA operational resilience requirements and identify the gaps before your regulator does.

Frequently Asked Questions