The volume of cyber-attacks reported to the Financial Conduct Authority (FCA) has fallen significantly in 2024, according to data obtained and analysed by Hack The Box via a Freedom of Information (FOI) request.
Between 1 January and 21 October 2024, the FCA received 101 incident notifications from regulated firms.
This represents a 53% decrease compared to the entirety of 2023. Notably, incidents related to a cyber-attack against third-party providers have dropped by 37%, while data breaches tied to cyber incidents have decreased by 29%.
The downtrend aligns with the FCA’s ongoing effort to tighten regulations around operational resilience to secure financial firms’ critical data.
Under the current rules, regulated firms are required to set impact tolerances, use testing to identify vulnerabilities, conduct crisis simulation exercises, and develop robust internal and external communication plans.
By 31 March 2025, organisations must make further financial investments to sustain compliance.
The data emphasises the positive impact of adequate regulations and enhanced incident preparedness in boosting overall resilience.
Significant investments have already been made in artificial intelligence (AI) and machine learning-powered cybersecurity tools for real-time threat detection.
However, further investment is needed to ensure a comprehensive approach to incident response – including the use of tabletop exercises for realistic crisis preparedness.
“The downtrend in reported attacks against regulated financial firms is a welcome development, given the continuing global threat landscape across several key industries,” Haris Pylarinos, CEO and founder at Hack The Box, said. “There has been a conscious effort to factor preparedness and response into new FCA regulation, and on the surface, it appears that these efforts have, at least partially, helped.”
Recommended reading
- Report: Cyber-attacks on Financial Services Doubled in 2023, So Far
- Cybersecurity and Cloud Still Top Priorities for Financial Firms
- Report: Cybersecurity Top Concern For Rising Financial Crimes
“Preparedness and consistency in response is critical to maintain business operations. This requires firms to empower CISOs and security executives to take control of an incident.
“If security leaders maintain the trust of the board to respond according to regulations and have clear directions in place for how employees should respond, significant business disruptions could be avoided. To achieve this, investment is needed in cybersecurity upskilling, but also in table-top exercises that provide realistic, scenario-based crisis preparation.”
Lucas Kello, associate professor of International Relations, University of Oxford, comments: “While the reduction in reported incidents is a positive trend, it might also reflect increasing sophistication in cyber-attack methods that enable attackers to evade detection. Avoiding complacency is key. Financial firms must continuously develop proactive security measures.
“The finance industry has long been on the front line of cyber threats, a reality heightened by today’s geopolitical tensions.
“Nation-state actors and other adversaries post a constant – and constantly evolving – risk to financial firms. Combining advanced security tools with robust preparedness and incident response strategies is essential to limiting the damage of successful attacks.”





