Cyber Security Insights September 2026

Cyber Security Insights September 2026

Written by Bryan Altimas

The Numbers Are In. And They Are Not Comfortable Reading.

This month, the data speaks for itself. Cybercrime in the UK has almost doubled in six years. The personal liability exposure facing senior managers in financial services has never been higher. And the incidents that dominated business headlines this year carry lessons that every firm in the sector should be applying now.

Three topics. All grounded in evidence. All directly relevant to the firms we work with.

If the FCA asked what you personally did about cyber risk, could you prove it?

Under the Senior Managers and Certification Regime (SMCR), that is not a rhetorical question. Section 66A of the Financial Services and Markets Act 2000 gives the FCA a direct route to you personally. If your firm breaches a requirement in your area of responsibility and you failed to take reasonable steps to prevent or address it, the fine can land on you, not just the firm. 

A cyber incident does not automatically create that liability. Firms with sound controls still get breached. What decides the outcome is the evidence of oversight you can show for the months before it happened.

Check where Senior Management Function (SMF)24 sits in your firm. The FCA defines the Chief Operations function to cover technology, cyber security, business continuity and outsourcing, but it is only mandatory for Enhanced-tier firms. Fall below that threshold and the responsibility does not vanish. It has to sit on someone's Statement of Responsibilities.

Three things the FCA expects you to evidence:

  • Who holds responsibility for cyber and operational resilience, and what they report to you.
  • What weaknesses have been found, and who is closing them.
  • When you last tested your incident response, and whether you were in the room.

On that last point, the FCA's own 2025 Cyber Coordination Group insights are blunt: active senior management involvement in incident testing measurably improves decision making when a real incident hits.

Delegating cyber security to a Managed Service Security Provider is sound management. Delegating accountability is not an option under SMCR. Accountability can never be delegated in any business.

If this sits under your remit, it is already your responsibility. The question is whether you can evidence control.

This is precisely what DEFEND™ is built to deliver: a business-led way to move from uncertainty to control, with the evidence to prove it.

Image
An AI-generated image of a senior manager reviewing a risk document with colleagues in a modern boardroom.

93% of financial services firms were hit by a cyber attack in the last year. 

The remaining 7% are not immune. They just have not been tested yet.

The figures come from Bridewell's 2026 review of UK critical infrastructure sectors. Financial services also recorded the slowest incident response time of any sector it studied.

Here is what the wider data shows. The UK government's Cyber Security Breaches Survey 2025/2026 found cybercrime among businesses has not surged. It has held steady at 19 to 22% over three years. What has shifted is exposure by size: 17% of micro businesses experienced cybercrime, against 24% of small firms, 41% of medium firms and 48% of large ones. Growth does not bring protection. It brings a bigger target.

Verizon's 2026 Data Breach Investigations Report adds a warning most firms have not adjusted for. For the first time in the report's 19-year history, exploiting a known software vulnerability overtook stolen credentials as the leading way attackers get in, present in 31% of breaches. Ransomware still featured in 48% of breaches, but 69% of victims refused to pay and the median payment fell. Paying is losing its grip. Recovery is starting to win.

Keynote Point

So the real question for a scaling firm is not whether an attack will happen. It is whether you can prove three things when it does:

  • Your critical vulnerabilities are found and patched, not just logged.
  • Your backups actually restore, not just exist.
  • Your response plan has been rehearsed, not just written.

Security spend does not answer any of those on its own. Structure does.

That is what DEFEND™ is for: understand your exposure, translate it into business impact, act on it, and hold the evidence to prove it.

Image
An AI-generated image of a professional presenting cybersecurity data to a small team in a bright modern office.

The M&S and Co-op Attacks Cost Over £400 Million. Here Is What Every Financial Services Firm Should Learn From Them.

In 2025, two of the most recognisable names in British retail suffered cyber incidents that became defining events in UK cybersecurity. The attacks on Marks and Spencer and the Co-op were assessed together as a single systemic event, with a combined estimated cost of between £270 million and £440 million. The M&S operating profit impact alone was approximately £300 million.

These were not small firms with inadequate resources. They were large, well-resourced organisations with established IT functions. The scale of the damage is the point.

For financial services firms, the lessons are specific and transferable. The incidents involved a combination of factors that are not unique to retail: social engineering of IT support staff, exploitation of third-party access pathways, and a period of undetected attacker presence inside systems before the breach was identified. None of those factors are sector-specific. All of them are present in the financial services threat landscape.

The most relevant lessons for IFAs, wealth managers, and mortgage brokers are:

  • Social engineering works. Attackers did not breach these firms through sophisticated technical exploits. They convinced people with access to provide it. Training and verification processes are not optional extras.
  • Third-party access is a genuine attack surface. Suppliers, IT support providers, and managed service providers with access to your systems represent a risk that needs to be actively managed, not assumed.
  • Undetected presence is the real danger. In many significant incidents, attackers are inside systems for weeks or months before the breach is identified. Monitoring and detection capability determines how much damage is done.
  • Recovery capability matters as much as prevention. The firms that recovered most effectively had tested plans, clear communication protocols, and the ability to restore systems from clean backups. Those that did not faced prolonged disruption.
  • Reputational damage outlasts the incident. The financial cost of a breach is significant. The client trust impact in a relationship-based business can be longer lasting and harder to quantify.

The CrowdStrike outage of July 2024 added a further dimension to this picture. A single software update from a trusted security vendor caused global disruption across thousands of organisations. It demonstrated that cyber resilience is not only about defending against malicious actors. It is about the ability to keep operating when something goes wrong with any part of the technology ecosystem a firm depends on.

The FCA expects firms to map their critical third-party dependencies and to resilience-test against scenarios where those dependencies fail. The M&S, Co-op, and CrowdStrike incidents are precisely the kind of severe but plausible scenarios the FCA has in mind. Firms that have not stress-tested their dependencies against these kinds of events have a gap worth addressing.

Keynote Point
High-profile incidents carry lessons that go beyond the headlines. The M&S and Co-op attacks were not unique in their method. They were unique in their scale. The methods are already being used against smaller firms. The question is whether those firms have taken the same lessons seriously.

Image
An AI-generated image of a team reviewing an incident response plan together in a modern meeting room.


Join the Newsletter
Insights from Riverside Court Consulting Ltd into cyber security, data protection and regulatory compliance
Subscribe Now
Categories
Recent Posts

Cyber Security is serious. But it shouldn't be confusing and stressful

crossmenuarrow-right