What the Bank of England’s new cyber resilience report means for London financial firms

The Bank of England’s July 2026 Financial Stability Report places cyber resilience firmly among the financial sector’s leading concerns. In the Bank’s 2026 H1 Systemic Risk Survey, 82% of respondents identified cyberattack as one of the five risks that could have the greatest impact on the UK financial system. This was two percentage points lower than in the previous survey, while 26% identified cyber risk as the single biggest risk.

For London financial firms, the practical message is to prepare for disruption rather than relying solely on prevention. Firms should understand their important business services, identify technology and supplier dependencies, manage vulnerabilities promptly and demonstrate that essential services can recover within acceptable timescales.

What the report says

Three themes stand out.

First, frontier artificial intelligence may change the speed, scale and economics of cyberattacks. The Bank says advanced AI could help malicious actors identify and exploit software weaknesses more quickly, although it may also support cyber defence. Firms should therefore keep vulnerability management, access controls, network security and recovery arrangements under review.

Second, shared suppliers can create concentrated risk. A compromise, outage or emergency shutdown affecting a common software provider, managed service provider or infrastructure supplier could disrupt several financial institutions simultaneously.

Third, response and recovery remain essential. The Bank says firms should base resilience work on severe but plausible scenarios and be able to respond to and recover from disruption quickly. Further detail is available in the Bank’s Financial Stability Report.

What it means for your firm

Regulatory focusPractical action for your firm
Important business servicesIdentify services whose disruption could cause intolerable harm to customers or markets
Impact tolerancesSet the maximum tolerable period or level of disruption for each important service
Third-party dependencyMap critical technology, cloud, software and outsourced-service providers
Vulnerability managementPrioritise, test and deploy security fixes at a pace appropriate to the risk
Response and recoveryMaintain and test procedures for containment, restoration and communication
Regulatory notificationEstablish which incidents must be reported and which regulator should be contacted

The FCA’s operational resilience rules apply to specified firms, including banks, building societies, insurers, payment and electronic money institutions, designated investment firms and enhanced-scope SMCR firms. The rules took effect in March 2022, with in-scope firms required by 31 March 2025 to complete sufficient mapping and testing to remain within their impact tolerances. Firms outside the formal scope can still use the FCA’s observations as useful guidance.

Third-party oversight has already started

The UK Critical Third Parties regime is no longer awaiting its first designations. Microsoft Ireland Operations Limited, Google Cloud EMEA Limited, Amazon Web Services EMEA SARL and Oracle Corporation UK Limited became the first designated critical third parties on 13 July 2026.

The Bank, PRA and FCA can now oversee the resilience of the systemic services these organisations provide to UK financial firms. However, designation does not transfer responsibility away from regulated businesses. Financial firms remain responsible for identifying, assessing and managing risks arising from their own suppliers.

The area that often catches firms out

A firm may have strong internal security while remaining heavily dependent on one portfolio platform, cloud environment, payment service or software provider. Supplier mapping should extend beyond the primary contract to include subcontractors, shared infrastructure, data locations, authentication services and recovery dependencies.

The Bank’s effective practices for cyber response and recovery emphasise preparation, testing and restoration. They do not create new requirements, but the regulators encourage firms to consider them when strengthening resilience.

Getting the basics right

A tested cyber incident response plan should define responsibilities, escalation routes, communications and recovery priorities. Business continuity and disaster recovery arrangements should explain how important services will continue or be restored when systems or suppliers fail.

Effective email security, appropriately configured Microsoft 365 security and getting the everyday basics right through multifactor authentication, patching, access reviews and tested backups can materially reduce exposure.

Book a resilience review

Cyber resilience requires more than a written policy. Firms need current dependency maps, realistic scenarios, tested recovery procedures and evidence that improvements are completed. Speak to Northern Star, a managed IT support in London team, about reviewing your technology risks and operational resilience arrangements.