Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Cyber incidents reported to the FCA up over 50%

Security

Cyber incidents reported to the FCA up over 50%

The pioneer of Breach and Attack Simulation (BAS), Picus Security, today released a report revealing a large rise in cyber incidents reported to the UK's Financial Conduct Authority (FCA).

Image copyright Shutterstock

The report, based on FCA data obtained via a Freedom of Information (FOI) request, reveals that:

  • The FCA received 116 reports of material cyber security incidents in 2021, up from 76 in 2020 (an increase of 52%).
  • 65% of cyber incidents reported in 2021 (75) were due to cyber-attacks.
  • Approximately one third of incident reports (37) contained notifications where the confidentiality of company or personal data may have been compromised or breached.
  • One in five incidents reported to the FCA in 2021 involved ransomware.
  • 21 cyber incidents were reported to the FCA in March 2021 – the most submitted in any month that year and coinciding with the disclosure of critical vulnerabilities in Microsoft Exchange Server.

"Financial services firms are amongst the best prepared and most highly capable organisations at detecting and responding to cyber incidents," said Dr Suleyman Ozarslan, Picus Security co-founder and VP of Picus Labs. "Yet, despite investing heavily in security and data protection, it's clear that many continue to experience challenges in these areas.

Advertisement
ODU RT

"The large rise in cyber incidents reported to the FCA in 2021 is a concerning trend and should serve as an important reminder to all firms about the need to make ongoing improvements in all areas of security. This is necessary to not only mitigate the risks posed by external threats but also those which arise due to IT failures and human error."

Digital transformation in the financial services sector, including widespread adoption of remote working, means that many firms over the last few years have had to adjust their security and data protection practices. On top of this, they have had to contend with being a target of Advanced Persistent Threats groups and ransomware operators, as well as manage the risks of critical vulnerabilities in widely used systems such as Microsoft Exchange Server.

"Defending financial institutions against all the threats they face remains a tough challenge, made even harder by the growing attack surface," Ozarslan added. "Only by validating security capabilities on a continuous basis can firms hope to measure their threat readiness more accurately and swiftly close the gaps needed to take their operational resilience to the next level."

 

Advertisement
ODU RT

 

 

Advertisement
FIA2026 animated banner
ADS appoints Matthew Reynolds as CIO

Aerospace Defence Security Space Events

ADS appoints Matthew Reynolds as CIO

19 June 2026

ADS Group - parent organisation of trade association ADS and Farnborough International - has appointed Matthew Reynolds as its Chief Information Officer (CIO).

Cyber security tech licensed by UK Government for global markets

Security

Cyber security tech licensed by UK Government for global markets

19 June 2026

The Government Office for Technology Transfer (GOTT), supported by the National Cyber Security Centre (NCSC), has licensed SilentGlass - a plug-and-play cyber security device that actively blocks any unexpected or malicious HDMI and Display Port connections - to UK firm Goldilock Labs for global use.

QinetiQ joins UK Quantum Growth Alliance

Defence Security

QinetiQ joins UK Quantum Growth Alliance

17 June 2026

QinetiQ has been invited to join the UK Quantum Growth Alliance, a new government–industry partnership bringing together senior representatives from leading British companies to accelerate the adoption of quantum technologies across the UK.

Avon Protection introduces short-duration CBRN CS-PAPR

Defence Security Events

Avon Protection introduces short-duration CBRN CS-PAPR

16 June 2026

Avon Protection has introduced its Combination System Powered Air Purifying Respirator (CS-PAPR), a new short duration (SD) breathing apparatus option of their Powered Air Purifying Respirator (PAPR) for integration with a Combination Respirator Unit (CRU).

Advertisement
ODU RT
Optera funding fuels UK hub for space domain awareness

Defence Security Space

Optera funding fuels UK hub for space domain awareness

15 June 2026

Optera, a neuromorphic sensing company delivering next-generation space domain awareness (SDA), has raised £3 million to establish and scale its UK headquarters and engineering team.

BAE Systems and NEC sign MoU to strengthen Japan

Security

BAE Systems and NEC sign MoU to strengthen Japan's cyber defence

15 June 2026

BAE Systems and NEC Corporation have signed a Memorandum of Understanding (MoU) to combine expertise for the implementation of active cyber defence (ACD) solutions for the Japanese Government.

Advertisement
ODU RT
Advertisement
FIA2026 animated banner