This month, the data speaks for itself. Cybercrime in the UK has almost doubled in six years. The personal liability exposure facing senior managers in financial services has never been higher. And the incidents that dominated business headlines this year carry lessons that every firm in the sector should be applying now.
Three topics. All grounded in evidence. All directly relevant to the firms we work with.
Under the Senior Managers and Certification Regime (SMCR), that is not a rhetorical question. Section 66A of the Financial Services and Markets Act 2000 gives the FCA a direct route to you personally. If your firm breaches a requirement in your area of responsibility and you failed to take reasonable steps to prevent or address it, the fine can land on you, not just the firm.
A cyber incident does not automatically create that liability. Firms with sound controls still get breached. What decides the outcome is the evidence of oversight you can show for the months before it happened.
Check where Senior Management Function (SMF)24 sits in your firm. The FCA defines the Chief Operations function to cover technology, cyber security, business continuity and outsourcing, but it is only mandatory for Enhanced-tier firms. Fall below that threshold and the responsibility does not vanish. It has to sit on someone's Statement of Responsibilities.
Three things the FCA expects you to evidence:
On that last point, the FCA's own 2025 Cyber Coordination Group insights are blunt: active senior management involvement in incident testing measurably improves decision making when a real incident hits.
Delegating cyber security to a Managed Service Security Provider is sound management. Delegating accountability is not an option under SMCR. Accountability can never be delegated in any business.
If this sits under your remit, it is already your responsibility. The question is whether you can evidence control.
This is precisely what DEFEND™ is built to deliver: a business-led way to move from uncertainty to control, with the evidence to prove it.

The remaining 7% are not immune. They just have not been tested yet.
The figures come from Bridewell's 2026 review of UK critical infrastructure sectors. Financial services also recorded the slowest incident response time of any sector it studied.
Here is what the wider data shows. The UK government's Cyber Security Breaches Survey 2025/2026 found cybercrime among businesses has not surged. It has held steady at 19 to 22% over three years. What has shifted is exposure by size: 17% of micro businesses experienced cybercrime, against 24% of small firms, 41% of medium firms and 48% of large ones. Growth does not bring protection. It brings a bigger target.
Verizon's 2026 Data Breach Investigations Report adds a warning most firms have not adjusted for. For the first time in the report's 19-year history, exploiting a known software vulnerability overtook stolen credentials as the leading way attackers get in, present in 31% of breaches. Ransomware still featured in 48% of breaches, but 69% of victims refused to pay and the median payment fell. Paying is losing its grip. Recovery is starting to win.
Keynote Point
So the real question for a scaling firm is not whether an attack will happen. It is whether you can prove three things when it does:
Security spend does not answer any of those on its own. Structure does.
That is what DEFEND™ is for: understand your exposure, translate it into business impact, act on it, and hold the evidence to prove it.

In 2025, two of the most recognisable names in British retail suffered cyber incidents that became defining events in UK cybersecurity. The attacks on Marks and Spencer and the Co-op were assessed together as a single systemic event, with a combined estimated cost of between £270 million and £440 million. The M&S operating profit impact alone was approximately £300 million.
These were not small firms with inadequate resources. They were large, well-resourced organisations with established IT functions. The scale of the damage is the point.
For financial services firms, the lessons are specific and transferable. The incidents involved a combination of factors that are not unique to retail: social engineering of IT support staff, exploitation of third-party access pathways, and a period of undetected attacker presence inside systems before the breach was identified. None of those factors are sector-specific. All of them are present in the financial services threat landscape.
The most relevant lessons for IFAs, wealth managers, and mortgage brokers are:
The CrowdStrike outage of July 2024 added a further dimension to this picture. A single software update from a trusted security vendor caused global disruption across thousands of organisations. It demonstrated that cyber resilience is not only about defending against malicious actors. It is about the ability to keep operating when something goes wrong with any part of the technology ecosystem a firm depends on.
The FCA expects firms to map their critical third-party dependencies and to resilience-test against scenarios where those dependencies fail. The M&S, Co-op, and CrowdStrike incidents are precisely the kind of severe but plausible scenarios the FCA has in mind. Firms that have not stress-tested their dependencies against these kinds of events have a gap worth addressing.
Keynote Point
High-profile incidents carry lessons that go beyond the headlines. The M&S and Co-op attacks were not unique in their method. They were unique in their scale. The methods are already being used against smaller firms. The question is whether those firms have taken the same lessons seriously.

