Operational Cyber Risk and FCA Resilience Requirements for UK Boards 2026
Dr. Saranaya · Professor of IT, Cyber Security, Data Science & AI
Abstract
This study examines how UK boards govern operational cyber risk after the Financial Conduct Authority (FCA) operational resilience transition ended on 31 March 2025. Using qualitative document analysis of FCA policy materials, peer-reviewed risk and information-systems research, and UK government cyber-governance guidance, the paper identifies three findings: boards have shifted from programme compliance to continuous assurance of impact tolerances; third-party and cloud concentration now dominate scenario-test failure modes; and directors require cyber literacy sufficient for credible challenge under Senior Managers and Certification Regime accountability. The implications for management practice and postgraduate cyber-risk education are discussed for executives and regulated firms.
Published: September 2026 | Last reviewed: September 2026
Introduction
According to the Cyber Security Breaches Survey 2024 (Department for Science, Innovation and Technology, 2024), 74% of large UK businesses reported a cyber security breach or attack in the previous twelve months, establishing cyber disruption as a material board concern rather than a specialised technology issue. For UK organisations authorised by the Financial Conduct Authority, that exposure intersects with PS21/3 operational resilience rules, whose transition period ended on 31 March 2025 and which now require firms to remain within board-approved impact tolerances for important business services (Financial Conduct Authority, 2021; Financial Conduct Authority, 2024). The post-deadline supervisory stance treats resilience as continuous business-as-usual governance, not a one-off implementation project (Financial Conduct Authority, 2025).
This paper addresses three research questions: (1) How have UK boards redefined accountability for operational cyber risk after the FCA resilience deadline? (2) Which failure modes most frequently threaten impact tolerances in board-level scenario evidence? (3) What capabilities do directors and senior managers require to provide credible challenge under the UK regulatory regime?
Literature Review
Incident-centred information security research frames cyber disruption as a strategic balance between prevention and response rather than a purely technical control problem (Baskerville, Spagnoletti and Kim, 2014). Complementary work on business-model resilience shows that cyber events can invalidate revenue and service assumptions when continuity planning is detached from customer-facing value creation (Niemimaa, Järveläinen, Heikkilä and Heikkilä, 2019). Dynamic capabilities theory further explains why boards that only “sense” threats without reallocating capital and routines fail to convert awareness into resilience (Teece, 2007).
UK regulation extends this international literature by hard-wiring outcomes. FCA PS21/3 requires identification of important business services, impact tolerances, mapping, scenario testing and governing-body self-assessment (Financial Conduct Authority, 2021). Parallel government guidance in the Cyber Governance Code of Practice specifies director-level actions on risk appetite, strategy, assurance and incident accountability across sectors (Department for Science, Innovation and Technology and National Cyber Security Centre, 2024). The UK combination of outcomes-based financial regulation and explicit board cyber duties therefore goes beyond generic enterprise risk frameworks by making delivery continuity for consumers and markets a testable board responsibility.
Methodology
The study uses qualitative document analysis of three source categories. First, FCA publications on operational resilience were reviewed, including PS21/3 and subsequent supervisory insights issued through 2024–2025. Second, peer-reviewed articles in Information & Management, the International Journal of Information Management and the Strategic Management Journal were analysed for theoretical constructs linking cyber events to organisational resilience. Third, UK government and National Cyber Security Centre materials—including the Cyber Governance Code of Practice, the Cyber Security Breaches Survey 2024 and the NCSC Annual Review 2024—were examined for threat prevalence and board expectations. A genuine limitation is the absence of primary interviews with UK non-executive directors; published supervisory observations may under-represent informal board dynamics.
Findings and Analysis
Board accountability has moved from transition programmes to continuous tolerance assurance. FCA guidance ahead of 31 March 2025 stressed that operational resilience must be embedded in enterprise risk, change management and strategic planning, and that boards must approve self-assessments demonstrating the ability to remain within impact tolerances in severe but plausible scenarios (Financial Conduct Authority, 2024). Post-deadline commentary from the FCA’s Head of Technology, Resilience and Cyber frames the milestone as the start of supervisory focus on learning from incidents and ongoing scenario testing rather than completion of a compliance project (Financial Conduct Authority, 2025). For boards, operational cyber risk therefore appears as an enduring agenda item with documented challenge, remediation ownership and audit trails—not a temporary programme update.
Third-party and technology concentration dominate severe scenario failure modes. Supervisory observations after the transition period highlight cloud-service outages and high-profile cyber attacks as catalysts for more rigorous testing of third-party resilience and, in some cases, joint exercising with critical suppliers (Financial Conduct Authority, 2025). The NCSC Annual Review 2024 records 317 ransomware activity reports and 20 NCSC-managed ransomware incidents, of which 13 were nationally significant, reinforcing that severe cyber disruption remains plausible for UK organisations (National Cyber Security Centre, 2024). Mapping that stops at internal systems therefore fails board scrutiny when important business services depend on concentrated technology providers whose outage exceeds the firm’s impact tolerance.
Directors require cyber literacy for credible challenge under UK accountability regimes. The Cyber Governance Code of Practice requires boards to set cyber risk appetite, receive at least quarterly reporting against agreed metrics, and take responsibility for regulatory obligations and communications during incidents (Department for Science, Innovation and Technology and National Cyber Security Centre, 2024). Combined with Senior Managers and Certification Regime expectations in financial services, this places personal accountability on executives who cannot outsource judgement to technical teams. Baskerville, Spagnoletti and Kim (2014) argue that organisations must manage the strategic balance between prevention and response; boards that lack sufficient literacy cannot set that balance or interrogate recovery assumptions when scenario tests fail.
Discussion
Taken together, the findings describe a governance shift: resilience is judged by sustained consumer and market outcomes under disruption, not by the completeness of a cyber control catalogue. UK boards must therefore integrate operational cyber risk into capital allocation, third-party strategy and executive capability planning, consistent with dynamic capabilities that reconfigure routines as threat and dependency landscapes change (Teece, 2007). For management education, this elevates demand for programmes that join cyber technical literacy with board-level risk and strategy. Postgraduate pathways such as the MBA in Cybersecurity and Risk Management at UK School of Management address that intersection for professionals who must translate regulatory expectations into governed operating models without treating resilience as an IT workstream alone.
Conclusion
UK boards now operate in a post-transition FCA environment where remaining within impact tolerances for important business services is a continuous obligation. Evidence from FCA policy and supervisory publications, UK cyber-governance guidance and peer-reviewed resilience research supports three takeaways: governing-body assurance must be ongoing; third-party and cloud concentration are central residual risks; and director cyber literacy is a prerequisite for accountable challenge. Primary research with UK board chairs and senior managers across firm sizes remains necessary to test how these expectations are enacted in practice and how capability gaps shape remediation quality under live cyber pressure.
You May Also Find Useful
Digital Disruption and Strategic Leadership: How UK Executives Are Navigating Uncertainty in 2026
ESG Integration in UK Business Strategy: What Every Manager Must Know in 2026
References
- Baskerville, R., Spagnoletti, P. and Kim, J. (2014) 'Incident-centered information security: Managing a strategic balance between prevention and response', Information & Management, 51(1), pp. 138–151.
- Department for Science, Innovation and Technology and National Cyber Security Centre (2024) Cyber Governance Code of Practice. GOV.UK, London.
- Financial Conduct Authority (2021) PS21/3: Building operational resilience. Financial Conduct Authority, London.
- Financial Conduct Authority (2024) Operational resilience: insights and observations for firms. Financial Conduct Authority, London.
- Financial Conduct Authority (2025) Operational resilience: beyond regulatory raincoats. Financial Conduct Authority, London.
- National Cyber Security Centre (2024) NCSC Annual Review 2024. NCSC, London.
- Niemimaa, M., Järveläinen, J., Heikkilä, M. and Heikkilä, J. (2019) 'Business continuity of business models: Evaluating the resilience of business models to cyber risks', International Journal of Information Management, 49, pp. 430–445.
- Teece, D. J. (2007) 'Explicating dynamic capabilities: The nature and microfoundations of (sustainable) enterprise performance', Strategic Management Journal, 28(13), pp. 1319–1350.
- Department for Science, Innovation and Technology (2024) Cyber Security Breaches Survey 2024. GOV.UK, London.
