Cyber Security Insights August 2026

Cyber Security Insights August 2026

Written by Bryan Altimas

The Risks Are Changing.

The Cost of Ignoring Them Is Not.

Last month we looked at regulatory deadlines, the joint AI warning from the UK's most senior financial authorities, and the uncomfortable truth about where most incidents begin. This month, we will go further.

New legislation is moving through Parliament that will reshape how cyber risk is managed across entire supply chains. Ransomware has found a new target. Cyber insurance is failing firms that believed they were covered. And good cyber governance does not require a large budget, it requires clarity about what good actually looks like.

Four topics. All of them are directly relevant to financial services firms that want to stay ahead rather than react.

The Cyber Security and Resilience Bill Is Not About You. Until It Is.

The UK Cyber Security and Resilience Bill is often described as legislation for critical national infrastructure, water, energy, gas, transport. And for the most part, that is accurate. What many people are missing is that critical national infrastructure is being expanded to include managed service providers (MSP), and designated critical technology suppliers. Financial advisers, wealth managers, and mortgage brokers will not appear on that list.

So why does it matter to you?

The firms that will be directly regulated by this Bill include the cloud platforms, software providers, and managed service providers that your business relies on every day. When those firms become subject to new mandatory security standards, incident reporting obligations, and regulatory scrutiny, the pressure will not stay with them. It will travel down the supply chain, to you.

This is already happening in other regulated sectors. When the legislation raises the bar for a supplier, the supplier raises the bar for its clients. Contracts are updated. Questionnaires arrive. Due diligence requests follow. The firms that are prepared for those conversations will move through them quickly. The firms that are not will find themselves scrambling to demonstrate controls they assumed were someone else's responsibility.

There is a second reason this matters. The Bill signals the direction of travel. The UK government has made clear that the regulatory floor for cyber resilience is rising. The Cyber Security and Resilience Bill is not the end of that process. It is the beginning. Financial services regulators, the FCA, the PRA, the Bank of England, are watching the same threat landscape and drawing the same conclusions. The expectations placed on regulated firms will continue to increase. The Bill tells you where the destination is, even if your journey there runs through a different regulatory route.

What firms should be aware of now:

  • Identify which of your suppliers and technology providers are likely to be in scope under the Bill
  • Expect your IT support company or managed service provider to ask more questions about your security posture
  • Review your supplier contracts for cyber resilience obligations and incident notification requirements
  • Use this moment to assess your own controls, not because the Bill requires it, but because the FCA will
  • Document your supply chain dependencies — who you rely on, what access they have, and what happens if they are disrupted

The Cyber Security and Resilience Bill passed all House of Commons stages and entered the House of Lords on 17 June 2026. Royal Assent is expected before the end of 2026, with phased implementation running through to 2028. The window to prepare is open. It will not stay open indefinitely.

Keynote Point
Legislation that does not name your firm directly can still reshape the environment your firm operates in. The Cyber Security and Resilience Bill will raise expectations across the supply chain, accelerate scrutiny from your technology providers, and signal where regulators are heading. Understanding it now is not a compliance exercise. It is a strategic one.

This is not a compliance exercise. It is a strategic one. If your supply chain exposure is not mapped, it is not under control. Talk to Riverside Court Consulting about a DEFEND™ Supply Chain Review.

Image
An AI-generated image of a professional reviewing legislation documents in a modern boardroom.

Ransomware Has a New Favourite Target. It Looks a Lot Like Your Firm.

For several years, the dominant ransomware story was about large organisations. Major retailers, hospital systems, car manufacturers, global logistics companies and critical infrastructure. The attacks were visible, the ransoms were large, and the headlines were dramatic.

That story has not gone away. But alongside it, a quieter shift has taken place. Ransomware groups have discovered that smaller, less defended organisations are easier to breach, faster to extort, and far less likely to have the legal and technical resources to fight back. The average ransom demand surged 47% year on year in 2025. And increasingly, those demands are landing on the desks of IFA principals, wealth management partners, and mortgage broking directors.

The logic is straightforward. A small financial services firm holds highly sensitive client data: financial records, identity documents, investment portfolios, property transactions. That data has real value, both to the firm and to the clients it belongs to. The reputational and regulatory consequences of a breach are severe. And the firm is unlikely to have a dedicated security team, a tested incident response plan, or an offline backup strategy.

For an attacker, that is an attractive combination.

The most common entry points for ransomware in firms of this size are not sophisticated. They are the same entry points that have always existed:

  • Phishing emails that deliver malicious links or attachments
  • Remote access tools — VPNs, remote desktops — with weak or stolen credentials
  • Unpatched software on workstations or servers
  • Third-party providers with access to internal systems who have been compromised upstream

 Once inside, attackers move quickly. Data is exfiltrated before encryption begins, giving the attacker two forms of leverage: the ransom demand for the decryption key, and the threat to publish or sell the stolen data if the demand is not met. For a firm whose clients trust it with their most sensitive financial information, the second threat is often more damaging than the first.

What reduces the risk:

  • Tested, offline or immutable backups that cannot be encrypted alongside live systems
  • Multi-factor authentication on all remote access and cloud platforms
  • A patching process that closes known vulnerabilities within defined timeframes
  • Staff awareness training that includes current ransomware delivery methods
  • An incident response plan that has been rehearsed, not just written

86% of businesses targeted in ransomware incidents in 2025 refused to pay. The firms that were able to refuse were the ones with backups they could trust. The firms that paid were the ones that discovered, at the worst possible moment, that their recovery options were not what they believed.

Keynote Point
Ransomware is no longer a large-enterprise problem. It is a financial services problem, and the firms being targeted are increasingly the ones that assumed they were too small to matter. Size is not a defence. Preparation is.

You will not know if your backups work until you need them. By then, it is too late to find out. Book a Ransomware Readiness Review with Riverside Court Consulting. Under DEFEND™, we test your recovery options before an attacker does.

Unnamed (7)
An AI-generated image of an office worker responding to a security alert on their screen.

Your Cyber Insurance Policy May Not Do What You Think It Does.

Cyber insurance has become a standard part of the risk management conversation for financial services firms. Premiums are paid. Policies are filed. The assumption, reasonable on its face, is that if a cyber incident occurs, the financial consequences are covered.

That assumption is increasingly wrong.

Cyber insurance claim denial rates are rising to more than 40% in the UK market, primarily because the controls that insurers expect to be in place were not there at the time of the incident. The policy was valid. The premium was paid. The incident was real. But the claim was declined because the firm could not demonstrate it had maintained the security standards the policy required.

The underwriting bar has risen sharply. Policies now routinely include conditions around multi-factor authentication, endpoint protection, patch management, privileged access controls, and incident response capability. These are not optional enhancements listed in the small print. They are conditions of cover. If those controls are not in place and demonstrable at the time of a claim, the insurer has grounds to challenge or decline.

There is a specific risk that catches firms out. Cyber insurance is assessed on a specific day, often through an online form completed without full visibility of the technical environment. The controls declared at that point have to remain accurate and maintained on every day between the form and the date of any claim. A control that existed at renewal but was not consistently maintained is a gap an insurer's forensic team will find.

For FCA-regulated firms, the consequences extend beyond the insurance claim. An incident that the policy does not cover is an incident the firm absorbs in full — financially, operationally, and reputationally. In a sector where client trust is the foundation of the business, that is a risk with consequences that go well beyond the policy limit.

What firms should do before their next renewal:

–    Read the policy conditions carefully, specifically the warranties and security control requirements

–    Validate that every control declared at underwriting is actually in place and consistently maintained

–    Treat renewal as a point of genuine review, not an administrative payment

–    Engage a broker who can explain obligations, not just price the risk

–    Document your controls in a form that could be produced quickly under a claims investigation

UK cyber insurance underwriters now ask for Cyber Essentials certification, multi-factor authentication on all administrative accounts, and tested backups before they will quote competitive premiums. Firms that have those controls in place can expect 25 to 40% lower premiums than firms that do not. The controls that protect you and the controls that make your insurance valid are the same controls.

Keynote Point
A policy that does not respond at the point of claim provides no protection. The question is not whether your firm has cyber insurance. It is whether your firm has done the work to ensure the policy will actually pay out when it is needed. Those are very different things.


The controls that protect you and the controls that make your insurance valid are the same controls. Talk to Riverside Court Consulting before your next renewal, while there is still time to close the gaps.

Unnamed (8)
An AI-generated image of two professionals reviewing an insurance document together.

What Good Cyber Governance Actually Looks Like for a Small Financial Services Firm.

The conversation around cyber governance in financial services often defaults to the language of large organisations. Dedicated security teams. CISO-level leadership. Enterprise platforms. Seven-figure budgets.

Most IFA practices, wealth management boutiques, and mortgage broking firms do not have any of those things. And the assumption that good cyber governance is therefore out of reach is one of the most costly mistakes a small financial services firm can make.

Good cyber governance at firm level is not about matching what a large bank does. It is about having a clear, honest picture of what you hold, what you depend on, what could go wrong, and what you would do if it did. Proportionate. Documented. Consistently maintained. Those four things describe good governance regardless of firm size.

In practice, it looks like this.

Leadership owns it. The principal, partner, or director of a small financial services firm does not need to understand every technical detail of cybersecurity. They do need to understand the risks the firm carries, the obligations it operates under, and the decisions that have been made about how to manage both. Cyber governance is a leadership function, not an IT function.

The firm knows what it holds. A small firm that can answer the question what data do we hold, where does it sit, and who has access to it is ahead of the majority of organisations of any size. That clarity is the foundation of every other governance decision.

The basics are maintained consistently. Multi-factor authentication on all systems. Access reviewed regularly. Patches applied on schedule. Staff who have received training that reflects current threats, not a module completed two years ago. These are not sophisticated controls. They are the controls that stop the majority of attacks before they begin.

There is a plan for when something goes wrong. Not a lengthy document that no one has read. A clear, short, rehearsed set of steps: who to call, what to preserve, who to notify, and how to communicate with clients. The firms that recover well from incidents are the ones that knew what to do before the incident happened.

It is documented. The FCA does not expect a five-person IFA practice to operate like a tier-one bank. It does expect that firm to have considered its cyber risks, made proportionate decisions in response, and be able to demonstrate that it has done so. Documentation is not bureaucracy. It is evidence.

The markers of good cyber governance for a small financial services firm:

  • A named individual with responsibility for cyber risk at leadership level
  • An up-to-date record of what data the firm holds, where it sits, and who can access it
  • Multi-factor authentication enabled across all systems and cloud platforms
  • A staff training programme that is current, tested, and recorded
  • A written incident response plan that has been reviewed in the last twelve months
  • Cyber insurance that has been reviewed against actual controls, not just renewed
  • A supplier review that confirms third parties with system access meet minimum security standards

None of this is beyond a small firm. All of it is within reach without a dedicated security team or a large budget. What it requires is ownership, consistency, and the decision to treat cyber governance as a core business function rather than an IT problem.

Keynote Point
The firms that manage cyber risk most effectively in financial services are not always the largest or the best-resourced. They are the ones where the leadership understands the risk, the basics are consistently maintained, and the firm knows what to do when something goes wrong. That combination is available to every firm, regardless of size.


Four risks. One root cause. The firms most exposed this year are not the ones without security tools. They are the ones without control, over their supply chain, their ransomware readiness, their insurance cover, or their governance record.

DEFEND™ is how we bring all four under control, not as four separate projects, but as one structured view of where your firm actually stands.

If any of this sits under your remit, it is already your responsibility. The question is whether it is under control.

Book a DEFEND™ Control Review with Riverside Court Consulting and find out.

Image
An AI-generated image of a small team chatting in an office.



Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right