The Financial Conduct Authority is issuing new rules to make existing cyber incident and third-party reporting clearer, more consistent, and easier for firms to follow.
The new rules are meant to help the FCA respond more quickly to disruptions such as cyber-attacks or power outages, give firms greater certainty on what to report and when, and strengthen firm resilience to better protect consumers and markets.
The new rules come as cyber-attack become more frequent and sophisticated, with firms evermore reliant on third-party providers.
In 2025, over 40% of cyber incidents reported to the FCA involved a third-party, with several high-profile incidents impacting the financial services sector, including the Cloudflare and AWS outage.
The FCA says that firms have not always reported incidents consistently due to a lack of clarity on what to report and what to provide.
Based on a consultation, the FCA has released new rules following feedback to create requirements to reduce unnecessary burden, while ensuring the FCA gets the information it needs to assess impact and respond swiftly to incidents.
The FCA has now created a simple, streamlined reporting regime with the Prudential Regulation Authority (PRA) and Bank of England including a single reporting portal.
The regulator has also removed duplicative incident reporting for payment service providers and credit rating agencies, as well as refined the overall information required. This would allow most firms under FCA regulation to complete a short form to tell the regulator about their incident.
The FCA also added clearer guidance on thresholds, definitions, and responsibilities for incident reporting.
“Resilience is being tested like never before, with firms facing growing cyber threats and increasing reliance on third parties to deliver the essential financial services consumers rely on,” Mark Francis, director of specialists and wholesale sell-side at the FCA, said.
“These changes give firms clearer rules and practical guidance to better manage disruption, while supporting our ambition to be a smarter regulator, giving us better data to spot risks, share insights and strengthen sector-wide resilience.”
Recommended reading
- Darcula Phishing Scam Claims 800K+ Victims
- New Cyber and Fraud Advisory Board Launches in Scotland
- Fraud-as-a-Service Driving ‘Mega’ Cyber-attacks
- Cyber Scam Gangs Spreading Like “Cancer,” UN Says
Over time, the FCA says the data will share insights and trends to help firms bolster their operational resilience and share relevant information with industry, where appropriate during widespread disruption, particularly in stressed market conditions.
Where disruption occurs at a third party, the data will help the regulator see through the firm’s supply chains to identify which services are the most exposed, and help the FCA identify potential critical third parties to the UK financial system.
The FCA is also charing Finalised Guidance for both incident reporting and third party report, including clear examples of what a firm should report, help apply thresholds, and guidance on completing the incident form and third party register.
Now, firms will have 12 months to prepare for the new rules which come into force 18 March 2027.





