FINANCIAL SERVICES SECURITY
Cyber security for financial services firms that the FCA, your board and the regulator will take seriously
You are a regulated UK firm, the DORA and FCA operational resilience deadlines are real, and the people advising you either speak compliance or speak technology but rarely both. This page sets out what good cyber security looks like in financial services, and how an independent senior leader closes that gap.
Book a conversationWhat cyber security for financial services means
Cyber security for financial services is the discipline of protecting a regulated firm’s data, money movement, customer trust and operational continuity against deliberate attack, while satisfying the specific obligations placed on the sector by the FCA, the PRA, the Bank of England and, for firms operating in or with the EU, the Digital Operational Resilience Act. It is not the same as general IT security. A retailer that suffers an outage loses sales. A bank, broker, insurer, payments firm or asset manager that suffers an outage can breach its regulatory permissions, fail its clients and trigger a supervisory response. The bar is higher, the scrutiny is constant, and the controls have to be evidenced, not just asserted.
Why financial services is a higher-risk target
Financial firms hold the two things attackers want most: money and rich personal data. That makes the sector a priority target for organised criminal groups, ransomware operators and state-aligned actors. The threat profile is distinctive in three ways. First, the attack surface is wide because regulated firms run dense networks of third parties, from custodians and payment rails to cloud platforms and outsourced administrators. A weakness in any one of them becomes your incident. Second, the consequences compound: a breach is simultaneously a security event, a regulatory event and a reputational event. Third, the data is sensitive enough that UK enforcement has teeth. The ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022 for security failings, and globally the IBM Cost of a Data Breach Report 2025 puts the average breach at USD 4.44 million. For a regulated firm, the regulatory cost sits on top of that.
If you are still mapping where your exposure actually sits, structured cyber security consulting is usually the right first move before you commit to controls or spend.
DORA and what it asks of you
The Digital Operational Resilience Act sets a single, demanding standard for how financial entities manage technology and cyber risk. It rests on five pillars: ICT risk management, incident reporting, digital operational resilience testing, the management of ICT third-party risk, and information sharing. DORA matters to UK firms in two ways. If you operate in the EU or serve EU clients, parts of it apply directly. Even where it does not apply in law, it has become the reference standard that boards, investors and counterparties expect you to be able to evidence. The hardest pillar for most firms is third-party risk: you have to know your critical ICT providers, understand your concentration risk, and be able to exit or substitute a provider without collapsing operations. That is a leadership question before it is a technical one, and it is one a fractional CIO and CISO is built to answer.
FCA operational resilience and what good looks like
The FCA’s operational resilience regime requires firms to identify their important business services, set impact tolerances that define the maximum tolerable disruption to each, and prove through testing that they can stay within those tolerances during severe but plausible scenarios, including a cyber attack. Good looks like this in practice. Your important business services are mapped to the people, processes, technology, data and third parties that deliver them, so you know exactly what breaks what. Your impact tolerances are set by the board and owned by named executives, not buried in a spreadsheet. You run severe-scenario testing, including ransomware and data-destruction scenarios, and you act on what it reveals. You have a rehearsed, costed incident response plan that names who decides, who communicates and how you recover within tolerance. And your board can describe your security posture without reading from a script, because they have been governed through it. If that last point feels uncomfortable, the board cyber governance view is where to start.
The controls that actually move the needle
Frameworks matter, but firms get breached through a small set of recurring weaknesses. Prioritise these.
- Identity and access: strong multi-factor authentication everywhere, least privilege, and tight control of privileged and service accounts, which are the routes attackers actually use.
- Third-party and supply-chain risk: a live inventory of critical providers, contractual security obligations, and tested exit and substitution plans.
- Detection and response: monitoring that surfaces an intrusion in hours, not weeks, paired with a response plan people have actually rehearsed.
- Backup and recovery: immutable, tested backups that survive a ransomware event and let you recover within your impact tolerances.
- Data governance: knowing what regulated and personal data you hold, where it lives, and who can reach it.
- Emerging-technology risk: clear policy on AI tools and the shadow AI staff adopt without telling you, governed through proper AI governance.
Note what is not on that list: a single product purchase. Tools help, but security maturity in financial services comes from operating model, ownership and discipline, not from licences.
How independent senior leadership fits
Most regulated firms face a structural problem. They need genuine CISO-grade judgement on DORA, operational resilience and board reporting, but they do not need, or cannot justify, a permanent executive at a full UK CISO salary, which recruiters such as DWH put at roughly £95,000 to £600,000 or more. The answer is fractional or interim leadership. A virtual CISO gives you ongoing senior security ownership at a fraction of a full-time hire, and the what is a vCISO explainer sets out exactly what that covers. When you need someone in the seat at pace, for example through a remediation programme or a regulatory deadline, an interim CIO and CISO brings that capacity immediately. If you are unsure whether your gap is technology delivery, security governance or both, the CIO vs CISO distinction is worth understanding before you hire. You can see how engagements are scoped and costed on the pricing page, or start with ongoing cover through CISO as a service.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Carrying both the CIO and CISO mandate at group level means Daniel has owned the exact tension a regulated financial services firm lives with: keeping technology delivering while standing behind the security posture to a board and an audit committee, in language both sides understand.
Frequently asked questions
Does DORA apply to UK financial services firms?
DORA applies directly to firms that operate in the EU or serve EU clients. Even where it does not apply in UK law, it has become the reference standard boards, investors and counterparties expect you to evidence, so most regulated UK firms align to it regardless.
What is the difference between cyber security and FCA operational resilience?
Cyber security protects you against attack. FCA operational resilience requires you to identify your important business services, set impact tolerances and prove you can keep operating within them during severe scenarios, including a cyber attack. Cyber security is one input to resilience, not the whole of it.
Do we need a full-time CISO?
Many regulated firms need CISO-grade judgement without a permanent executive hire, given a UK CISO salary can run from roughly £95,000 to £600,000 or more. A virtual or fractional CISO gives you that ownership at a fraction of the cost, scaled to your firm.
What is the biggest cyber risk for financial firms right now?
Third-party and supply-chain exposure, alongside ransomware. Regulated firms depend on dense networks of providers, and a weakness in any critical one becomes your incident, your regulatory event and your reputational problem at once.
Where should a regulated firm start?
Start by understanding what your board can and cannot currently evidence about your security posture, then map your important business services and critical providers. A board cyber governance check is a fast, focused way to see where you stand before committing to spend.
CHECK YOUR POSTURE
Find out what your board can actually evidence before the regulator asks
If you cannot say, today, whether your board could describe your security posture under DORA and FCA operational resilience, that is the gap to close first. The Board Cyber Governance check shows you exactly where you stand, and a conversation turns it into a plan.
Board Cyber Governance check Book a conversation