Firms can’t report to the FCA what they can’t see

By Aishwarya Ramani, Senior Solutions Manager at Illumio 

The FCA’s new reporting rules aim to bring clarity about how cyber incidents are recognised and reported.

The incident and third-party reporting regime, in force from 18 March 2027, is a useful step for the industry. Firms report through Connect, and the FCA, PRA and Bank of England have aligned behind one set of requirements.

The FCA has set three thresholds for reporting an incident: intolerable harm to consumers, risk to safety and soundness, and risk to market stability or confidence.

The harder part is determining when one of those thresholds has actually been met. It’s up to organisations to make that judgement, and the FCA is clear this is not a tick-box exercise.

Once a threshold has been met, firms should report within 24 hours of making that determination. That responsibility remains with the firm, even when the incident originates with a third-party provider.

Aishwarya Ramani

Understanding risk requires context

Judging a threshold is a risk judgement, and risk comes down to two things: how likely is something to happen, and how significant would the impact be?

In banks, impact is usually well understood. Likelihood is harder because it’s shaped by how the environment has been architected. Take the application processing transactions behind ATM withdrawals. If it breaks down and people cannot access their money, it disrupts the bank and potentially the economy.

However, if that application sits purely downstream and has few paths into it, the likelihood of compromise may be relatively low. Change what connects to it, and the calculation changes too.

That is why understanding connections and dependencies matters so much to the new reporting regime. The FCA expects firms to assess whether an important business service has been affected, yet an incident can begin in a resource that nobody realised supported that service.

The difficulty is that many firms still lack that context. Our research found financial services globally to be the most confident sector at detecting unauthorised lateral movement, yet more than four in ten still admit they struggle to stop it. Teams may spot unusual behaviour without being able to quickly establish how the affected systems are connected.

And those relationships increasingly extend beyond the organisation itself. More than 40% of incidents reported to the FCA in 2025 involved third-party providers.

What to have in place before March 2027

Preparation starts with observability, not because regulation requires it, but because organisations cannot manage cyber risk effectively without understanding how systems, services, and third parties connect.

That context is what turns detection into a defensible judgement on what is affected, how significant it is, and whether it crosses a reporting threshold. It cannot be assembled after an incident has already begun.

Look at what an enhanced report asks for. Firms must name the services affected, the proportion of users and transactions involved, the parties involved, related entities, and any third party an incident originated with, down to its legal entity identifier.

For many organisations, getting to that level of understanding is still difficult. Across financial services globally, our research found around 30% take at least a month to discover previously unknown communication paths. Observability gives firms the context to understand those relationships before an incident and make faster, better-informed risk judgements when one occurs.

That understanding also has to extend to the organisations on the other side of those connections. Firms need to know which services their providers support, what information will be available during an incident, and who is responsible for supplying it.

Existing Service Level Agreements (SLAs) and contracts may not oblige providers to supply everything needed within the reporting timeframe, making it important to clarify accountability and, where necessary, renegotiate terms before an incident happens.

Finally, the process itself needs to work under pressure. Nobody will perfect this immediately, but assessing impact, gathering the required information, and escalating a report needs to be tried, tested, and repeatable.

Beyond the deadline

The FCA’s objective is better incident reporting. However, meeting those new set of requirements depends on understanding how systems, services, and third parties are connected.

That capability shouldn’t be viewed as a one-off compliance exercise. The same observability needed to assess incidents, determine materiality, and meet reporting obligations can help organisations make better-informed decisions about cyber risk more broadly.

The reporting requirements may be the immediate priority, but the understanding they encourage of systems, dependencies, and third-party relationships will continue to deliver value long after the reporting regime comes into force.

spot_img
spot_img

Subscribe to our Newsletter