Financial services firms already take security seriously. The government's Cyber Security Breaches Survey 2025/2026 found that 89% of finance and insurance businesses treat cyber security as a high priority, against 72% of businesses overall.
The weaker spot sits one step outside the firm. Across all UK businesses, only 15% formally review the cyber risk posed by their immediate suppliers.
For most companies that is a governance gap. For a regulated firm, it is a gap with a regulator attached to it.
First, check what actually applies to you
Plenty of providers will tell you that every financial services firm is now covered by the operational resilience rules. That is not what the rules say.
The FCA's requirements under PS21/3 reached the end of their transition period on 31 March 2025. Firms in scope had to identify their important business services, set impact tolerances, map the resources behind them, complete scenario testing and prepare a communications plan.
Scope covers dual-regulated firms such as banks, building societies and Solvency II firms, plus enhanced SMCR firms, payment institutions, electronic money institutions, registered account information service providers and recognised investment exchanges.
Core and limited scope SMCR firms sit outside it. That takes in a lot of smaller brokers, advisers and wealth managers. But in March 2026 the FCA said those firms should still consider how far its good and poor practice examples apply to them, and the general duty to run your affairs with adequate risk management has not gone anywhere.
So for many smaller firms the honest answer is this: the rules may not bite, but the expectation does. Your insurer and your larger clients will ask the same questions regardless.
Here is what that means when you choose an IT partner.
1. They are part of your map
On 27 March 2026 the FCA published what it found after a year of reviewing firms' self-assessments. One criticism came up repeatedly: mapping was still too focused on internal technology, and incomplete mapping of third party dependencies made vulnerabilities harder to find.
If a provider runs your servers, your Microsoft 365 tenant or your backups, they are on the map. They should be able to tell you which services they touch and what happens when they are unavailable. A service catalogue and a response time is not mapping.
2. Impact tolerance is not a recovery time
An impact tolerance is the most disruption your clients can absorb before real harm occurs. A recovery time objective is what your provider commits to. The FCA has found firms setting one equal to the other without ever asking whether that duration would actually harm anyone.
Work backwards instead. Decide what clients can withstand, then find out whether your provider can meet it.
Ask directly: what is your recovery time objective, what is the recovery point objective, and when did you last prove both?
3. Put them in the scenario testing
The firms the FCA rated well had widened their testing, documented how scenarios were built, and used the results to drive fixes. It was noticeably unimpressed by firms claiming there was no scenario they could not recover from, with nothing to show that this had been tested.
Your provider should be in the room, not sent the findings afterwards. One who treats a resilience test as an interruption to the support desk is telling you something useful.
4. Ask about the material third party register
Put 18 March 2027 in the diary. The FCA's PS26/2, published in March 2026 alongside equivalent PRA and Bank of England policy, comes into force that day.
Firms will have to notify the FCA of new or significantly changed material third party arrangements, and keep a register to submit annually. There is one definition, one template and one portal across all three regulators.
5. Ask what happens in the first hour
PS26/2 also standardises incident reporting. For most FCA solo-regulated firms it comes down to a short form with ten required questions, updated as the incident runs.
Ten questions is not many, but you cannot answer them from a support ticket. The FCA also found communications plans that existed on paper and had never been tested.
So ask: who calls me, how quickly, and what do they tell me? Then test it.
At 1-Fix, a security operations centre watching your environment around the clock is included as standard rather than sold as an upgrade.
6. Microsoft 365 and Azure: know who holds the keys
Most firms this size run on Microsoft 365, often with workloads in Azure. That is sensible, and it concentrates a lot of regulatory risk in one tenant. The questions are about control rather than product:
• Where is our data stored, and can you show that in writing?
• Who holds global administrator rights, and how is that access logged?
• How long are audit logs kept, and can you retrieve them for an investigation?
• Who approves changes to conditional access policies?
• If we adopt Copilot, what happens about oversharing first?
That last one matters more than most firms expect. Copilot surfaces whatever a user can already see, so loose permissions become a discovery problem the day you switch it on.
7. Telephony and records
If your firm records calls, your phone system is a compliance system rather than a utility. Moving to VoIP is usually the right decision, particularly with the analogue network being retired, but treat it as a records exercise as well as a connectivity one.
Ask how recordings are stored, how long they are kept, who can reach them, how quickly a specific call can be found, and what happens to the archive if you change provider. Before the migration, not during it.
8. Fixed price is fine, as long as you know what is inside it
A per user monthly price makes budgeting straightforward. 1-Fix packages are priced per user, typically between £50 and £150 per user per month depending on scope.
The question is what falls outside it. Ask whether these are included or chargeable: out of hours attendance, incident response, evidence packs for audits and due diligence questionnaires, attendance at scenario tests, and help with your resilience self-assessment.
What good evidence looks like
The pattern running through the FCA's findings is consistent. Assertions are not enough. Ask your provider for things you can put in front of a board:
• Independently verified certifications. 1-Fix holds Cyber Essentials Plus, which only 2% of UK businesses reported holding in the latest Breaches Survey
• A named contact who attends your governance meetings
• Recovery time and recovery point objectives per service, with test dates
• Evidence of their own supplier and subcontractor arrangements
• A written incident communications process, and the date it was last tested
If they can produce that within a fortnight, they have done it before. If it takes two months, you have your answer.
Who we do this for
Quantum Six is a consultancy that banks, financial institutions and fintechs bring in for core banking and payments work: vendor selection, target operating model design, due diligence and programme assurance. Assessing other people's technology decisions is what they do for a living. They chose us to look after their own.
"Reliable, friendly, efficient service."
G.B. at Quantum Six
Tax Automation works with corporate tax teams, where deadlines are external and immovable. On the point above about the first hour, their feedback speaks to it directly:
"1-Fix are always quick to respond to any IT issues that occur and provide regular updates as the issue is being worked on and resolved."
A.P. at Tax Automation Limited
Where to start
Write down your important business services. Work out which ones depend on your IT provider. Ask the questions above. Then decide whether the answers would stand up to someone reading them who does not work for you.
We work with firms in and around financial services across the Thames Valley and the wider UK, and we are happy to walk through this with you whether or not you end up working with us.
Book a discovery call and we will go through your current arrangements and where the gaps are.
FAQ block
Does my firm need to comply with the FCA's operational resilience rules?
It depends on your permissions. The rules apply to banks, building societies, PRA-designated investment firms, Solvency II firms, the Society of Lloyd's and its managing agents, recognised investment exchanges, enhanced SMCR firms, payment institutions, electronic money institutions and registered account information service providers. Core and limited scope SMCR firms are outside the formal requirements, but the FCA has said they should consider applying the same good practice, and other obligations around adequate risk management still apply.
Is my IT provider a material third party?
Possibly. From 18 March 2027, firms will need to notify the FCA of material third party arrangements and maintain an annual register of them. Whether your IT provider qualifies depends on how far your important business services rely on them. If they run your core systems, backups or Microsoft 365 tenant, it is worth assuming yes and confirming with your compliance adviser.
What is the difference between an impact tolerance and a recovery time objective?
An impact tolerance is the maximum disruption your clients and the market can withstand before real harm occurs. A recovery time objective is your provider's commitment for restoring a system. The tolerance should be set first, based on harm, then tested against what your provider can actually deliver.
What happens on 18 March 2027?
The FCA's rules in PS26/2, along with the equivalent PRA and Bank of England policy, come into force. They introduce a single incident definition, standardised reporting thresholds and forms, a single submission portal across the three regulators, and the material third party notification and register requirements.
Do we need a specialist financial services IT provider?
Not necessarily, but you do need one that understands regulated environments and can produce evidence rather than assurances. The practical test is whether they can answer questions about mapping, recovery objectives, audit log retention and incident communications without needing to go away and think about it.
How much should IT support cost a financial services firm?
Most UK providers work on a per user monthly price. 1-Fix packages typically range from £50 to £150 per user per month depending on scope. For regulated firms, check what sits outside the monthly fee, particularly incident response, audit evidence and attendance at resilience testing.