The Financial Conduct Authority has released a warning to banks that they must ensure they can deal with potential but plausible severe scenarios, like the CrowdStrike outage, by March 2025, in order to build better operational resilience with their third-party service providers.
In a statement, the FCA noted the increased reliance on “unregulated third parties” for important business services, noting third-party related issues like the CrowdStrike outage which the regulator said they’ve seen an upward trend of since 2023.
The CrowdStrike outage devastated IT systems globally, interrupting major airports, critical infrastructure, and operational systems across the world.
The FCA released a full review of the outage as well as lessons learned that they hope to pass onto other firms, noting where companies succeeded in getting back online and safeguarding their assets, and where others failed to do so.
Firms that mapped their important business services and the resources necessary to deliver these services, were able to prioritise getting key services back online to reduce the overall impact the incident had on their operations.
The FCA also found that firms benefited from having tested scenarios that were severe but plausible, including those impacting multiple important business services at the same time.
The regulator noted that firms with clearly defined and tested communications strategies were better able to quickly and efficiently respond to and communicate with, customers and stakeholders.
The FCA therefore recommends that firms should consider if their current testing scenarios are adequate and assure themselves that impact would be minimised during operational disruptions.
Obvious to many after the CrowdStrike outage, which was largely the result of an update that was phased out globally, the FCA has now stressed that firms should ensure the adequate testing of updates, and consider phasing releases of updates across smaller groups to contain any failures.
Further, firms may benefit from reviewing third-party management frameworks regularly, and after significant events or incidents, to improve the effectiveness of third-party risk controls.
Recommended reading
- CrowdStrike Reveals Global Outage Details
- CrowdStrike Incident | Lessons Learned and Key Questions Answered
- Mass IT Outages Reported Worldwide
“The CrowdStrike outage was one of the most disruptive incidents to occur this year, so it is not surprising the FCA is using its analysis of the incident to stress the importance of resilience in the financial sector,” David Ferbrache, managing director at Beyond Blue, commented.
“The digital world has grown increasingly interconnected. Heavily regulated industries, such as the UK’s financial sector, have become critically dependent on many less-known and often unregulated suppliers to provide their services. However, this can create serious security and resilience concerns, especially when partners are not practicing good cyber hygiene, have privileged access into your network, or become so critical to operations that financial institutions cannot operate with them.
“This is a challenge that the FCA, together with the PRA and the Bank of England, are looking to address through the forthcoming Critical Third Parties (CTP) regulatory regime, which is expected to land this quarter.
“Operational resilience is the ability for financial firms to meet the vital needs of their customers even in the face of severe disruptions. When third parties—such as cloud service providers, IT management services, or communication platforms—fail, the ripple effect can be catastrophic for financial firms and, by extension, the broader financial ecosystem. The upcoming policy is working to tackle this challenge.
“The policy stipulates that financial firms must have an understanding of the resilience of their third parties in the face of severe but plausible scenarios, while also ensuring they can remain resilient if those third parties are rendered unavailable.
“While we expect the CTP regime will regulate the most important of those third parties, there will many hundreds more of suppliers on which the financial sector depends and which could also cause major disruption. This requires the financial sector to work together to tackle the resilience of those “significant” third parties.
“The Cross Market Operational Resilience Group (CMORG) of the Bank of England brought financial institutions together to agree the next steps on how the community tackles that next tier of suppliers, making recommendations on how scenario testing of third parties is carried out, the types of evidence third parties should provide regarding their resilience to give confidence to financial firms, and how resilience obligations may be embedded in future contracts.
“Operationalising these findings over the coming year will be key to improving sector resilience and complements the roll-out of the CTP regime. Together these initiatives will both be key to a resilient financial sector ecosystem – one that is increasingly complex and interdependent.”





