IT Support for Financial Services · Cyber Security
Cyber Insurance for Financial Services Firms: What Insurers and the FCA Both Expect
31 July 2026

For FCA-regulated firms, cyber insurance sits within a wider compliance picture. The controls your insurer expects at claim time and the controls the FCA expects as a matter of ongoing regulatory compliance are not separate lists — they overlap significantly. A firm that genuinely meets its regulatory obligations is, in most respects, a firm whose insurer should have very little to argue about.
The practical problem is that many firms believe they meet both sets of requirements without having audited whether their controls actually work in practice. That gap — between what a firm believes its posture to be and what it actually is — is where claims and regulatory enforcement actions both originate.
What the FCA expects on operational resilience
The FCA's operational resilience framework, which came into full effect in March 2025, requires firms to identify their important business services, set impact tolerances for disruption, and demonstrate they can remain within those tolerances through testing. The underlying assumption is that disruption will happen — the question is whether the firm can continue to serve clients and contain the damage.
Cyber attacks are the most common cause of operational disruption for financial services firms. The resilience framework effectively requires firms to have thought through what happens when systems are unavailable, data is compromised, or a third-party provider is taken offline — and to have tested their response.
Insurers ask the same question, less formally: if something goes wrong, do you have the controls and the response capability to limit the damage? Evidence that you have tested your recovery, that your staff know what to do, and that you have documented your critical processes is exactly what both the regulator and your insurer want to see.
Where SM&CR adds personal accountability
The Senior Managers and Certification Regime means that operational resilience — including cyber resilience — is a named individual's personal responsibility. If a breach occurs and it emerges that reasonable controls were not in place, that question will eventually reach a named senior manager.
This changes the risk calculation. Cyber insurance covers financial loss from a breach. It does not cover regulatory enforcement action against an individual under SM&CR. The reason to have strong controls is not only to make a claim pay out — it is to demonstrate that the firm and its senior managers discharged their responsibilities.
What insurers check at claim time for financial services firms
Multi-factor authentication
MFA on all systems handling client data, financial transactions, and remote access is a near-universal requirement. Insurers are increasingly specific: MFA on email is not sufficient if trading platforms, client portals, or administrative systems are unprotected. Every account that touches client money or data needs to be covered.
Access controls and privileged access
Who can access client accounts, transaction systems, and sensitive data — and whether those permissions are reviewed regularly — is a standard claim-time question. Former employees whose accounts remain active, or staff with broader access than their role requires, are documented routes for both external attackers and insider incidents.
Third-party and supply chain controls
Financial services firms rely heavily on third-party technology providers. Insurers will ask whether you have assessed the cyber posture of your critical suppliers and whether your contracts with them include appropriate security requirements. The FCA's own guidance on third-party risk expects the same.
Data classification and protection
Personal data held under FCA and GDPR obligations needs to be identifiable, protected, and recoverable. Insurers want to know that you know what data you hold, where it is, and how it is protected — including whether it is encrypted at rest and in transit.
Incident response and regulatory notification
The FCA requires Material Operational Incidents to be reported within specific timeframes. Insurers require notification within their own policy windows. A documented incident response plan that covers both requirements — and that has been tested — is evidence of a firm that takes its obligations seriously. The absence of one, or evidence that it was not followed, weakens both your claim and your regulatory position.
Consumer Duty implications
Consumer Duty requires firms to deliver good outcomes for retail clients. A cyber incident that exposes client data or disrupts access to financial services is, by definition, a bad outcome. The controls that prevent or limit such incidents — and the speed with which a firm can recover and communicate with clients — are becoming part of how the FCA assesses whether firms are genuinely meeting their Duty obligations, not just their technical requirements.
Knowing where your controls actually stand
The Technology Resilience Score™ gives FCA-regulated firms a clear, evidence-based view of their current posture across the controls that matter to insurers and regulators alike: access management, backup and recovery, device and system security, staff awareness, and incident preparedness.
Your score is not self-assessment based on what you believe to be true. It is a structured view of what your environment actually looks like today — the kind of picture that insurers build after a claim and that regulators build during a review. Getting it in advance, and acting on what it shows, is the straightforward way to close the gap before it matters.
Get your free Technology Resilience Score for financial services →
We are not insurance advisers or FCA compliance consultants. For advice on your specific policy or regulatory obligations, speak to your broker and your compliance function. What we can tell you is what the controls look like in practice and how to strengthen them.
Is your firm's technology environment resilient?
Find out how prepared your firm really is to keep operating and evidence its resilience, with a free Technology Resilience Score™ for financial services.