On 14 August 2025, the Financial Conduct Authority (FCA) published discussions held throughout 2024 with industry members of the FCA’s Cyber Coordination Group (CCG) programme.

Background

The FCA CCG programme has been running since 2017, with 139 members bringing together industry cyber resilience and information security leaders to exchange insights and learn from each other.

Key topics

The discussion focused on three topics with key challenges and insights outlined below:

  • Reconnection and third-party incident management: Members discussed their views and experiences of the Cross Market Operational Resilience Group Reconnection Framework, which they use to help manage incidents with third-parties. Insights mentioned included cross-industry sharing forums such as Cross Market Operational Resilience Group (CMORG) or the Financial Services Information Sharing and Analysis Centre (FS-ISAC), which can be highly effective in enabling collective communication with third party suppliers during significant outages. A further insight discussed was how third-party outage scenarios in incident response testing can help firms understand how to operate temporarily without access to key third-party services. Key challenges mentioned by members included firms’ reliance on third-party suppliers for resilience practices and suppliers’ limited cyber security capabilities which can weaken a firm’s ability to respond or recover from disruption.
  • Threat and vulnerability management and threat-led penetration testing: Using established threat-led penetration testing frameworks such as CBEST and Simulated Targeted Attack and Response for Financial Services (STAR-FS) were likely to identify vulnerabilities as well as gaps in cyber resilience. Challenges discussed by members included the impact of combined or cumulative non-critical vulnerabilities, securing legacy systems and maintaining effective threat and vulnerability management technical capabilities.
  • AI and emerging technologies: Members discussed their experiences implementing AI into their cyber resilience strategies and their systems and controls framework. Insights discussed were that AI can be useful in automating quality assurance processes such as password policy compliance and for cyber defence processes such as threat intelligence analysis or risk analysis. Challenges mainly discussed involved the unidentified risks and increased exposure AI transpires into a firm’s internal systems and defending against cyber-attacks that target AI which could damage the integrity of information, poisoning large language models.