FCA sees huge rise in cyber incident reports

The number of cyber security incidents reported by the UK’s financial services firms rose to 819 last year, up from just 69 in 2017, according to new data obtained from the Financial Conduct Authority (FCA).

A freedom of information request submitted by accountancy firm RSM found a huge rise incidents reported to the regulator, with retail banking firms accounting for 486 incidents – nearly 60 per cent of all reported.

This was followed by wholesale financial market firms on 115 reports (14 per cent of overall reports) and retail investment firms on 53 (six per cent of the total).

When it comes to the root causes of the cyber incident, third party failure was found to be to blame for 21 per cent of reported incidents, followed by hardware and software issues (19 per cent) and change management within the organisation (18 per cent).

Cyber attack from outside actors accounted for 93 cyber incidents (11 per cent of total reports).

Of these 93 cyber attacks, the FCA data was broken down into the following categories of breach: 48 incidents of phishing or credential compromise (52 per cent of the total); 19 incidents of ransomware (20 per cent); 16 incidents of malicious code (17 per cent); and ten incidents of denial of service attack (DDOS) attack (accounting for 11 per cent of the total).

Steve Snaith, a technology risk assurance partner at RSM, said: “While the jump in cyber incidents among financial services firms looks alarming, it's likely that this is due in part to firms being more proactive in reporting incidents to the regulator – it also reflects the increased onus on security and data breach reporting following the GDPR and recent FCA requirements.

“However, we suspect that there is still a high level of under-reporting, failure to immediately report to the FCA a significant attempted fraud against a firm via cyber-attack could expose the firm to sanctions and penalties.”

He said the figures also underlined the importance of organisations obtaining third party assurance of their partners' cyber controls. “Overall, there remain serious vulnerabilities across some financial services businesses when it comes to the effectiveness of their cyber controls.”

    Share Story:

Recent Stories


FREE E-NEWS SIGN UP

Subscribe to our newsletter to receive breaking news and other industry announcements by email.

  Please tick here to confirm you are happy to receive third party promotions from carefully selected partners.


The new episode of The Mortgage Insider podcast, out now
Regional housing markets now matter more than ever. While London and the Southeast still tend to dominate the headlines from a house price and affordability perspective, much of the growth in rental yields and buyer demand is coming from other parts of the UK.

In this episode of the Barclays Mortgage Insider Podcast, host Phil Spencer is joined by Lucian Cook, Head of Research at Savills, and Ross Jones, founder of Home Financial and Evolve Commercial Finance.

Air and the role of later-life lending
Content editor at MoneyAge, Dan McGrath, spoke to the chief executive officer at Air, Will Hale, about the later-life lending industry, the importance of tailored advice and how technology and obligations have shaped the sector.


Helping the credit challenged get mortgage ready
A rising number of borrowers are finding it harder to access mortgages due to being credit challenged - whether that’s from historic debts, a county court judgment, or having little to no credit history.

In the latest episode of the Mortgage Insider podcast, Phil Spencer is joined by Eloise Hall, Head of National Accounts at Kensington Mortgages, and Alastair Douglas, CEO of TotallyMoney.

The future of the bridging industry and the Autumn Budget
MoneyAge content editor, Dan McGrath, is joined by head of marketing at Black & White Bridging, Matt Horton, to discuss the bridging industry, the impact of the Autumn Budget and what the future holds for the sector.