Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • Cyber incidents reported to the FCA up over 50%

Security

Cyber incidents reported to the FCA up over 50%

The pioneer of Breach and Attack Simulation (BAS), Picus Security, today released a report revealing a large rise in cyber incidents reported to the UK's Financial Conduct Authority (FCA).

Image copyright Shutterstock

The report, based on FCA data obtained via a Freedom of Information (FOI) request, reveals that:

  • The FCA received 116 reports of material cyber security incidents in 2021, up from 76 in 2020 (an increase of 52%).
  • 65% of cyber incidents reported in 2021 (75) were due to cyber-attacks.
  • Approximately one third of incident reports (37) contained notifications where the confidentiality of company or personal data may have been compromised or breached.
  • One in five incidents reported to the FCA in 2021 involved ransomware.
  • 21 cyber incidents were reported to the FCA in March 2021 – the most submitted in any month that year and coinciding with the disclosure of critical vulnerabilities in Microsoft Exchange Server.

"Financial services firms are amongst the best prepared and most highly capable organisations at detecting and responding to cyber incidents," said Dr Suleyman Ozarslan, Picus Security co-founder and VP of Picus Labs. "Yet, despite investing heavily in security and data protection, it's clear that many continue to experience challenges in these areas.

Advertisement
Leonardo animated rectangle

"The large rise in cyber incidents reported to the FCA in 2021 is a concerning trend and should serve as an important reminder to all firms about the need to make ongoing improvements in all areas of security. This is necessary to not only mitigate the risks posed by external threats but also those which arise due to IT failures and human error."

Digital transformation in the financial services sector, including widespread adoption of remote working, means that many firms over the last few years have had to adjust their security and data protection practices. On top of this, they have had to contend with being a target of Advanced Persistent Threats groups and ransomware operators, as well as manage the risks of critical vulnerabilities in widely used systems such as Microsoft Exchange Server.

"Defending financial institutions against all the threats they face remains a tough challenge, made even harder by the growing attack surface," Ozarslan added. "Only by validating security capabilities on a continuous basis can firms hope to measure their threat readiness more accurately and swiftly close the gaps needed to take their operational resilience to the next level."

 

Advertisement
ODU RT

 

 

Advertisement
General Atomics LB
NCSC warns mistaking AI vulnerability could lead to large-scale breaches

Security

NCSC warns mistaking AI vulnerability could lead to large-scale breaches

16 December 2025

The National Cyber Security Centre (NCSC) – a part of GCHQ – has shared critical insights cautioning cyber security professionals against comparing prompt injection and more classical application vulnerabilities classed as SQL injection.

Tyron Runflat set to establish UK centre of excellence

Defence Security

Tyron Runflat set to establish UK centre of excellence

16 December 2025

Tyron Runflat has invested in doubling its facility with the ambition of creating its first UK centre of excellence within the next five years.

Spaceport Cornwall and National Drone Hub launch UAS project

Aerospace Defence Security Space

Spaceport Cornwall and National Drone Hub launch UAS project

15 December 2025

The UK's first licensed spaceport, Spaceport Cornwall, has commenced work on a groundbreaking project with the National Drone Hub to establish a unique testing environment for uncrewed aerial systems (UAS).

Smiths Detection’s SDX 100100 DV HC on TSA ACSTL

Aerospace Security

Smiths Detection’s SDX 100100 DV HC on TSA ACSTL

15 December 2025

Smiths Detection's SDX 100100 DV HC X-ray scanner has been added to the Transportation Security Administration’s Air Cargo Screening Technology List (ACSTL), enabling its use by regulated operators across the US air cargo sector.

Advertisement
Leonardo animated rectangle
JFD Global to enhance Polish Navy

Defence Security

JFD Global to enhance Polish Navy's submarine rescue capability

11 December 2025

James Fisher (JFD Global) has secured a contract with PGZ Stocznia Wojenna, which will see JFD Global integrate a combined, hyperbaric and saturation diving system into the Polish Navy’s new salvage and rescue vessel, Ratownik.

RISC appoints Paul Lincoln as Chair

Security

RISC appoints Paul Lincoln as Chair

11 December 2025

The Security and Resilience Industry Suppliers Community (RISC), today announces the appointment of Paul Lincoln CB OBE VR as its new Chair.

Advertisement
ODU RT