Menu
a close up of lines and dots

Recent developments in UK and EU cybersecurity laws: Incident Reporting and DORA a year on

Posted on 6 August 2026

Reading time 9 minutes

This article provides an update on recent developments in cybersecurity and operational resilience regulation in both the UK and the EU, covering new incident reporting rules, the first annual report on UK FCA/PRA operational resilience rules, the first annual report on major ICT-related incidents under DORA, and useful insights gleaned from these reports.

Request a consultation

UK: new rules on operational Incident and third-party reporting

On 18 March 2026, the Financial Conduct Authority (FCA), the Prudential Regulation Authority (PRA), and the Bank of England published final policy statements introducing a co-ordinated framework for operational incident and third-party reporting (FCA PS26/2 and PRA PS7/26). The new rules will be enforceable from 18 March 2027, giving firms a 12-month implementation period.

The framework represents a significant evolution from the existing regime, under which reporting obligations were linked to the concept of impact tolerances and firms were required to notify regulators if they were unable to remain within tolerable levels of harm. Under the new rules, firms will notify incidents linked to service disruption or data loss (similar to DORA incident reporting rules – see below). This is because the concept of impact tolerances will not be relevant to all firms in scope and some of the incidents will need to be reported even if there is no impact on the tolerance levels.

Reporting triggers in the UK are regulator-specific: consumer harm for the FCA, safety and soundness of the firm for the PRA and FCA, and market stability and integrity for the FCA. One of the central aims of the new framework is to harmonise incident reporting across the financial sector.

The reporting process will be standardised for payment service providers (PSPs) in the same way as for other financial firms, and compliance with the new framework will satisfy the equivalent obligation under the Payment Services Regulations, avoiding duplication. PSPs retain a tighter initial notification deadline of four hours from first detection, consistent with their existing obligations, whilst other firms must provide an initial notification within 24 hours.

For firms dual-regulated by both the PRA and the FCA, a single report will be submitted through the FCA Connect portal. This applies where an incident simultaneously meets the FCA's consumer harm threshold and poses a risk to the firm's safety and soundness, thereby meeting the PRA threshold. Reporting obligations should be clear to InfoSec teams: in some circumstances, at a dual-regulated firm with EU operations, a single incident could simultaneously engage the FCA/PRA 24-hour trigger, DORA's initial notification, UK GDPR's 72 hours, and the PSR four-hour clock.

Incident definition and reporting tiers

An operational incident is defined as "either a single event or a series of linked events which disrupts the firm’s operations such that it: disrupts the delivery of a service to an end user external to the firm; or impacts the availability, authenticity, integrity or confidentiality of information or data relating or belonging to such an end user."

This now aligns to the definition of an ICT-related incident under DORA, a single event or a series of linked events that compromises the security of network and information systems and has an adverse impact on the availability, authenticity, integrity, or confidentiality of data or services.

thresholds for reporting are not strictly set as for major incidents under DORA. However, an example given is broadly similar to the thresholds under DORA: for PSPs, an incident must be reported where it affects more than 10 per cent of payment transactions totalling more than £100,000, and affects more than 10 per cent of payment service users or more than 5,000 users in total. Unlike DORA, the UK thresholds are illustrative rather than prescriptive, affording firms a degree of judgement in their application.

framework introduces two tiers of reporting: a standard tier, applicable to all in-scope firms, and an enhanced tier, which applies to a subset of firms and is also open to other firms on a voluntary basis.

reporting:

firms must submit an initial notification within 24 hours of first detecting a reportable incident (or within four hours for PSPs, in line with their existing obligations), followed by an intermediate report and a final report within 30 days of the incident concluding.

reporting (applies to the following firm types):

  • Enhanced scope SMCR firms
  • Banks
  • Designated investment firms
  • Building societies
  • Solvency II firms
  • CASS large firms
  • Payment service providers
  • UK RIEs
  • Registered trade repositories
  • Registered credit rating agencies

What do firms' notifications tell us? FCA observations one year on

On 27 March 2026, the FCA published its Operational Resilience: Insights and Observations One Year On report (the FCA Observations Report), reviewing good and poor practice from firms' annual operational resilience self-assessments following the end of the transition period on 31 March 2025.

The FCA identified several areas where further improvement in compliance is needed:

  • Third-party vulnerabilities: firms must improve their identification, assessment, and remediation of third-party vulnerabilities. The FCA found that many firms focus disproportionately on technology, whilst insufficiently addressing risks arising from third-party dependencies.
  • Scenario testing: scenario exercises should include sufficiently severe scenarios to provide evidence that the firm can remain within its impact tolerances. The FCA noted concern that some firms assert that no scenario exists from which they could not recover, without providing evidence of having tested adequately severe scenarios.
  • Scenarios should also account for consumer harm and market impact.
  • Vulnerability reporting: a number of self-assessments lack sufficient detail on the framework and end-to-end process for vulnerability identification and remediation.
  • Communications strategies: firms are expected to maintain tested internal and external communications strategies capable of operating during a disruption, including contingencies for the loss of usual communication channels. Communications strategies must be documented and exercised as part of scenario testing.

EU: DORA and NIS2 updates

DORA's First Incident Report

The European Supervisory Authorities (the EBA, EIOPA, and ESMA, together the ESAs) published their first annual report on major ICT-related incidents in June 2026, based on data reported to competent authorities during 2025. The report provides the first bloc-wide incident benchmark since DORA became fully applicable in January 2025.

The ESAs' report analysed the 3,383 major ICT-related incidents reported to competent authorities across the EU in 2025, averaging approximately 282 incidents per month. The report offers both encouraging findings and areas of concern.

Encouraging findings:

  • Only 10 per cent of major incidents were cybersecurity-related, predominantly Denial of Service (DoS) attacks, data exfiltration and manipulation, and identity theft. The report attributes the low proportion of successful attacks to the effective use of safeguards and detection mechanisms by financial entities. Ransomware attacks were concentrated in the insurance sector, which the ESAs link to the high volumes of sensitive health and financial data that insurers hold. Firms should continue applying the highest cybersecurity standards to preserve this.
  • The majority of incidents were reported by the credit sector (over 60 per cent) and the payment sector (16 per cent). The ESAs note that this is partly because entities in these sectors were already subject to major incident reporting under PSD2, and partly because of the nature of the services they provide. Credit institutions and payment institutions operate some of the most "digitally intensive and consumer-facing services in the financial system, such as payments, online and mobile banking, and card processing, which are used at massive scale every day." Firms operating in less digitally intensive sectors are likely to have a significantly lower exposure to major ICT incidents.
  • The direct impact of major incidents on clients, transactions, and financial counterparties was generally limited resulting in minor disruption. Where a heavier impact on clients was observed, it was concentrated in the credit and payment sectors, which the ESAs attribute to those sectors' large and frequently active customer bases.

Areas of concern:

  • Around one third of major incidents were caused by failures at third parties, including ICT third-party service providers, infrastructure providers, and other financial entities. In many cases, this required financial entities to agree and implement additional safeguards with their third-party providers after the incident. The report also notes that around one third of all reported incidents had a cross-border impact, underscoring the growing interconnectedness of the EU financial sector through shared infrastructure and services.
  • System failures (accounting for 51 per cent of all major incidents) and external events such as energy blackouts (27 per cent) were the principal drivers of major large-scale incidents. The April 2025 Iberian Peninsula energy blackout is a notable example, causing disruptions across all sectors.

    This illustrates that even where an organisation has implemented the highest cybersecurity standards, it remains vulnerable to business disruptions originating from external events. Proper technical testing, robust business continuity plans and tackling resilience issues are therefore essential for compliance with DORA.

Looking ahead, both the ESAs' DORA report and the UK FCA Mills' Review warn that cybersecurity threats are likely to intensify. The 'uplift' to attackers from more capable AI tools means that risks may spread more quickly across the increasingly interconnected financial system and this is an area regulators are interested in.

Financial entities should treat this as a prompt to review and strengthen their cybersecurity programmes now, rather than waiting for the next incident. The report underlines contemporary cyber security strategy – focusing on rapid detection, and efficient and effective response over pure protection. Incidents will happen, but reducing the impact ultimately is the place to be.

NIS2 implementation

The transposition deadline for the NIS2 Directive passed on 17 October 2024, yet a significant number of EU Member States missed it. By early 2026, the majority had completed transposition, many following infringement proceedings initiated by the European Commission.

Of the remaining Member States, the Commission has now referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to complete transposition and proposed targeted amendments to NIS2 in January 2026 to increase legal clarity, with the Dutch Senate acting to implement just ahead of referral.

The UK critical third parties regime

As of 13 July 2026, the Bank of England, the Prudential Regulation Authority (PRA), and the FCA started overseeing the first critical third parties (CTPs), with the intent to manage the resilience of the critical services these provide to the UK financial services sector.

The Treasury has announced the first designations of global cloud services and technology providers: Amazon Web Services, Google Cloud, Microsoft, and Oracle.

These providers are deeply embedded across organisations, creating new forms of systemic risk for the economy.

Register your interest for a free consultation

Request a complimentary 30-minute consultation with a Mishcon expert on your organisation's cybersecurity compliance.

Request a consultation

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else