The March 2027 deadline looms for Britain’s Financial Services firms
All organisations are at risk of falling victim to a cyber attack; it’s not if, it’s when.
By Ben Gibbins, Managing Principle, BFS&I, Orange Cyberdefense
All organisations are at risk of falling victim to a cyber attack; it’s not if, it’s when.
Historically, firms have disproportionately invested in attempting to prevent incidents from occurring, and underinvested in detection, response and recovery capabilities. Mature cyber security practices affect the likelihood of an incident occurring, but even a company with an excellent security culture, the best in breed tools, and a bottomless budget can be compromised. All organisations are susceptible to the exploitation of previously unknown vulnerabilities or the impact of an incident within their extended supply chain.
Consequently, financial services regulators in both the UK and EU have rightly adopted an operational resilience mindset. The effectiveness of a firm’s cyber security is measured by its ability to maintain critical operations and deliver core services during a disruption, whether caused by an attack, system failures, or situations outside of their control. Rather than assuming cyber incidents can be blocked, regulators expect organisations to operate under the assumption that severe incidents will occur.
On 18 March 2026, the UK’s Financial Services operational resilience regime was supplemented as PS26/2 and PS7/26 were published by the FCA and PRA respectively, along with finalised guidance to help firms with the requirements. These policies cover reporting serious incidents and the material third party relationships that underpin the firms’ operations. They include new, prescriptive reporting requirements that firms have until 18 March 2027 to comply with.
A Parallel path to DORA
The UK’s framework and the EU’s Digital Operational Resilience Act (DORA) both aim to strengthen operational resilience across financial services, but they differ in scope and philosophy. DORA focuses, almost exclusively, on technology risks and digital service providers. In contrast, the UK’s framework takes a holistic view centred around important business services.
The two regimes also diverge on incident metrics and thresholds. DORA enforces quantitative criteria for incident classification and defined notification timelines. The UK’s framework avoids prescriptive criteria for incident reporting, taking an outcome-focused approach centred around a firm’s reasonable belief and each regulator’s statutory objectives. When it comes to supply chain risk DORA outlines standardised contractual clauses, whereas the new rules require in scope UK firms to maintain a structured Material Third Party (MTP) register and notify regulators prior to entering or significantly amending third party arrangements.
The key takeaway for UK firms is to recognise that although both the UK and EU’s regimes have the same goal of enhancing the operational resilience of the sector, compliance with one regime does not automatically mean compliance to both.
How Firms Should Prepare
Firms have less than six months before the new rules come into force on 18 March 2027. The FCA and PRA have emphasised that compliance is not a tick-box exercise, and the amount of effort required to satisfy the requirements will depend on each firm’s current incident response and supply chain security policies and processes. For some, their processes will need to be tweaked, for others compliance will be a more significant undertaking.
Impacted organisations must proactively update their internal triage processes, incident playbooks and escalation procedures to reflect the outcomes-based thresholds defined in the new policies. For firms that are required to submit a Material Third Party (MTP) register, they must review their supply chain security policies and processes to ensure they can achieve the outcomes expected of them.
Why are the new rules important?
Compliance requirements can seem tedious, but as a cyber security professional I consider these rules as an opportunity to raise awareness as to the systemic challenges the UK’s financial services system faces. Our financial systems are critical to the health of our society and economy, and the UK is famously the world’s largest net exporter of financial services. This makes our firms an excellent target for opportunistic threat actors and political adversaries alike, and firms must be prepared to weather cyber incidents.
In 2025, 40% of cyber incidents reported to the FCA involved at least one third party. This figure was a primary driver for policy change and represents a significant shift in the modern financial services threat landscape. Interconnected supply chains also have the potential to impact large swathes of the UK’s financial services sector due to firms increasingly relying on a concentrated pool of external cloud providers and software vendors. A single downstream incident can ripple across hundreds, if not thousands of regulated entities. An incident of that magnitude isn’t a thought experiment. The LockBit ransomware attack in 2023 that impacted 350,000 organisations across the world) is a stark reminder of the criticality of supply chains. By providing the supervisory authorities with the incident and material third party reports, the regulators will better understand active campaigns and concentration risks across the sector and can begin to mitigate their effects.