Redline Application Services Ltd icon

Regulator presents cyber and technology resilience survey findings

28th Nov 2018

This week, Megan Butler, Executive Director of Supervision – Investment, Wholesale and Specialists at the Financial Conduct Authority (FCA) gave a speech on cyber and technology resilience in UK financial services. The full speech can be found here. The speech is based on an FCA survey of 296 firms during 2017 and 2018 to assess their technology and cyber capabilities. The survey looked at key areas such as governance, delivery of change management, managing third-party risks and effective cyber defences. The FCA survey can be found here.

Highlights from the speech include:

  • Firms have reported significantly more outages and cyber-attacks over the last year (138% and 18% increases respectively)
  • FCA see the above as an increasing threat to UK customers and financial markets
  • Cyber security is not just a technology risk, it is a human risk
  • According to FCA’s survey, nearly half of firms do not upgrade or retire old IT systems in time
  • Only 56% of firms say they can measure the effectiveness of their information asset controls
  • Management of third parties is seen as key
  • Key weaknesses highlighted include serious vulnerabilities across areas like: identification of key assets, information and detection
  • A third of firms still do not perform regular cyber assessments and only the largest firms have automated their detection systems to spot potential cyber-attacks
  • Retail lending within larger firms is seen as one of the least mature in relation to managing cyber capabilities according to FCA’s latest findings
  • Businesses are struggling to identify and manage high risk staff, including those who deal with critical and sensitive data
  • Finally, Megan Butler talks about the importance of a ‘positive security culture’ with all staff needing to be on board.

At Redline, we’re very proud of our cyber resilience track record and all that we do to protect our client’s data. Many of our clients are firmly entrenched in the financial services sector. Obsessing over information and data security is one of the six pillars that form ‘The Redline Way’, an internal philosophy that underpins how we work. Our Information Security Management System (ISMS) is maintained by a dedicated team of highly skilled professionals. Redline’s database and information infrastructure are rigorously tested to ensure full compliance with our ISO27001 accreditation. We are committed to continually improving our knowledge, controls and measures to manage any potential threats. On top of that, Redline owns and manages its own dedicated infrastructure in IL3/4 rated data centres across the UK. There is no replication of data worldwide. Redline’s clients have the certainty that their data is rigorously protected from threats and vulnerabilities 24 hours a day, 365 days a year.

Redline
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.