Cyber Incident Reporting in Financial Services
Written by Mark Farrell
Mark Farrell explains how UK GDPR, forthcoming FCA reporting rules and the proposed Cyber Security and Resilience Bill fit together, with practical steps for financial services firms.
When a financial services firm suffers a cyber incident, the first question is usually technical: what has happened, and how do we contain it? Close behind comes a regulatory question that is getting harder to answer: who do we have to tell, and by when?
For years the data protection answer has been familiar. Report a personal data breach to the ICO within 72 hours. From 18 March 2027, most FCA-regulated firms will also have a 24-hour operational incident reporting duty. And the Cyber Security and Resilience Bill, now in the House of Lords, will put many of the sector’s key technology suppliers under their own 24-hour regime.
Each regime has its own test, its own regulator and its own clock. In this post we look at how they fit together, where they diverge, and what firms can do now so that one incident does not become three separate scrambles to provide information.
The Three Clocks
The table below sets out the three regimes side by side. The FCA regime applies directly to regulated firms. The Cyber Security and Resilience Bill mainly reaches financial services firms through their suppliers.
| Reporting Requirement | UK GDPR | FCA/PRA Operational Incident Reporting | Cyber Security and Resilience Bill |
|---|---|---|---|
| Who reports | Controllers (processors tell their controller) | All firms with a Part 4A permission, payment service providers and some others | Operators of essential services, plus newly in-scope data centres and medium and large managed service providers |
| What triggers it | A personal data breach likely to result in a risk to people’s rights and freedoms | An operational incident the firm reasonably believes poses a risk of intolerable consumer harm, to safety and soundness, or to market stability and integrity | A significant incident, including some incidents that could have had a significant impact |
| First report due | Without undue delay and, where feasible, within 72 hours of becoming aware | As soon as practicable, expected within 24 hours of deciding a threshold is met (4 hours from detection for payment service providers) | Initial notification within 24 hours, full report within 72 hours |
| Report to | ICO (and affected individuals where the risk is high) | FCA via Connect, one submission shared with the PRA where relevant | The sector regulator, copied to the NCSC (and affected customers for data centres and managed service providers) |
| Status | In force | Applies from 18 March 2027 | In the House of Lords; detail to follow in secondary legislation |
Two details stand out. The FCA clock runs from when the firm decides a threshold is met, while the ICO clock runs from when it becomes aware of a breach. And the FCA rules expressly treat loss of confidentiality of customer data as a type of operational incident, so a data breach can engage both regimes at once.
Different Tests, Different Answers
The regimes ask different questions. UK GDPR asks about risk to individuals. The FCA asks about serious harm to consumers, firms and markets. The Bill asks about the security and continuity of essential services. So the same incident can be reportable to one regulator and not another.
A few scenarios show how this plays out:
- A misdirected email. Fifty customers’ account statements are sent to the wrong recipient. That is very likely a reportable personal data breach. It is unlikely to meet the FCA’s thresholds, which the FCA says are intended only for serious incidents.
- Ransomware without exfiltration. Systems are encrypted and customers cannot access services for a day, but no data leaves the firm. This may well meet the FCA’s consumer harm threshold. It is also a personal data breach, because loss of availability counts, and whether it is reportable to the ICO depends on the risk to individuals.
- A blocked intrusion. An attacker gets into a supplier’s network but is stopped before reaching customer data. There is no personal data breach and nothing for the FCA, which has said firms do not have to report near misses under these rules. But the supplier may have a duty under the Bill, which captures some incidents by their potential impact.
The FCA has also said firms must not skip a report just because an incident falls below their internal severity rating. It points to signals such as involving a Senior Manager or activating crisis procedures as signs a threshold may be met. In our view, those same signals should prompt a fresh look at the data protection position too.
There is a structural point as well. FCA reports are made per regulated entity, so a group with several authorised firms may need several reports. Under UK GDPR, the question is which entities are controllers of the affected data. The two answers will not always match.
Your Suppliers May Report First
Third parties are now central to incident risk in financial services. The FCA says incidents originating at third parties have recently been the top root cause for firms. It also says over 40% of the cyber incidents reported to it in 2025 involved a third party.
Most financial services firms are not themselves in scope of the NIS regime. Many of their suppliers soon will be. The Bill brings in data centres above set capacity thresholds and medium and large managed service providers, such as outsourced IT, helpdesk and managed security providers. Those suppliers will have their own 24-hour duty to notify their regulator and the NCSC, and a duty to tell affected customers.
That creates an awkward possibility. A supplier could be reporting an incident to a regulator before its financial services customer has been told about it, let alone worked out what it means.
For the data protection team, this is where Article 28 contracts matter. A processor must tell the controller about a personal data breach without undue delay. Contracts often give processors longer than a firm can now afford, and some say nothing about incidents that do not involve personal data. A firm facing a 24-hour FCA expectation needs supplier clauses that match. The FCA reporting form even asks firms to name the third party where an incident originated with one.
One Incident, One Story
The biggest practical risk is not missing a deadline. It is telling different regulators different things.
In the first hours of an incident, facts are thin and change quickly. A firm might tell the FCA at hour 20 that no customer data appears to be affected, then tell the ICO at hour 70 that data was exfiltrated. Both reports may be accurate when made. But read side by side, they can look like a firm that was slow, confused or less than candid.
Regulators may compare notes. The FCA’s enhanced reporting form asks which other regulatory bodies have been notified. The FCA’s rules on inaccurate, false or misleading information apply to these reports. And Principle 11 requires firms to deal with the FCA openly.
Customers are a fourth audience. Under UK GDPR, people must be told without undue delay where a breach is likely to result in a high risk to them. Under the Bill, data centres and managed service providers will have to tell affected customers too. What customers hear should line up with what regulators hear.
The answer is a single incident record that every report draws from. It should log what was known and when, and be updated as facts change. Each regulator then gets a report tailored to its own test, but built on the same facts and timeline.
What to Do Before 18 March 2027
The FCA has given firms 12 months to prepare, and around half of that has already gone. These are the steps we would prioritise.
- Build one triage process. At the first sign of an incident, run the UK GDPR, FCA and (for suppliers) Bill tests together, rather than in separate teams at separate times.
- Put the DPO in the room early. The data protection assessment should start in the first hours, not once the operational picture has settled.
- Record decisions and timings. Log when the firm became aware of a breach and when it decided an FCA threshold was met. Those are different moments, and each regulator will ask about its own.
- Map reporting entities. Work out which group entities are FCA-regulated reporting firms and which are controllers, before an incident forces the question.
- Review supplier contracts. Check that breach and incident notification clauses are fast enough for a 24-hour clock and cover incidents that do not involve personal data.
- Prepare holding wording. Draft template reports for the ICO, the FCA and customers that share a common factual core.
- Test it. Run a test exercise against all three clocks, including a scenario that starts at a supplier.
Final Thoughts
Cyber security, operational resilience and data protection have often been run by different teams with different playbooks. The new reporting landscape makes that harder to sustain. One incident can now engage three regimes within the same three days.
Firms that treat this as one problem, with one triage process, one incident record and one set of facts, will find the clocks much easier to manage.
If you would like help aligning your breach response and incident reporting ahead of March 2027, get in touch with our financial services team at Data Protection People.
Sources
- FCA: PS26/2 Operational incident and third party reporting
- FCA: PS26/2 full policy statement and made rules (PDF)
- FCA: Reporting operational incidents
- ICO: 72 hours – how to respond to a personal data breach
- Hansard: Cyber Security and Resilience (Network and Information Systems) Bill, House of Lords, 14 July 2026
- Burges Salmon: UK Cyber Security and Resilience Bill – what you need to know
- Browne Jacobson: The UK Cyber Security and Resilience Bill – what you need to know