For IFAs and small advice firms

Will you know when you've had an operational incident?

FCA PS26/2 · In force from 18 March 2027About 5 months away

From 18 March 2027, FCA-authorised firms have to report operational incidents. The hard part isn’t the form — it’s knowing you’ve had one.

Reporting starts with detection. A firm that cannot see a compromised mailbox, or cannot show what happened afterwards, has a technical problem long before it has a regulatory one.

Regulated-sector background Cyber Essentials support Chorley, Lancashire
PS26/2

What it means operationally

A short, plain summary of what the policy statement does. It is not a substitute for reading it, and it is not advice about your firm.

This is not regulatory advice. We are an IT and cyber security provider, not a compliance consultancy. Whether any rule applies to your firm, and whether any given incident is reportable, are questions for your compliance function, compliance consultant or network.

What it is

The FCA published PS26/2, Operational incident and third party reporting, on 18 March 2026. The rules apply from 18 March 2027, alongside finalised guidance FG26/3 on incident reporting and FG26/4 on material third party arrangements.

Who the incident rules cover

Operational incident reporting applies to all firms with a Part 4A permission, as well as payment service providers, UK recognised investment exchanges, registered trade repositories and registered credit rating agencies.

What counts as an operational incident

At a high level, an event that disrupts service to clients, or affects the availability, authenticity, integrity or confidentiality of client data. The rules set out how an incident is defined, when it has to be reported and a standard process for doing so.

What it means in practice, technically

You cannot report what you did not notice, and you cannot describe what you did not record. Detection, logging and a route for getting something in front of the right person quickly are the technical foundations underneath the requirement.

We deliberately do not restate the reporting thresholds, timeframes or form contents here. They are set out in the policy statement and the guidance, and paraphrasing them would be exactly the kind of second-hand regulatory summary your compliance function should not have to correct.

Read PS26/2 on the FCA website

FCA PS26/2 — Operational incident and third party reporting · published 18 March 2026

The third party reporting requirements are narrower

PS26/2 also introduces material third party reporting, but that part applies to a defined list of firm types — enhanced scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK recognised investment exchanges, authorised electronic money and payment institutions, and consolidated tape providers. That will not typically include a small advice firm, but your own categorisation is a question for your compliance adviser rather than for us.

Keeping a list of who your firm depends on — platforms, providers, back office, IT — is good practice whatever your scope, and it is useful the day something goes wrong. We supply a template for it. We do not present it as a regulatory register, because for most advice firms it is not one.

What actually goes wrong

Five risks, and the one that decides the rest

Four of these are familiar. The fifth — whether you would notice — is the one that changes character in March 2027.

Email compromise and impersonation

The pattern is consistent: an attacker reads a mailbox for weeks, then impersonates the adviser to the client or the client to the adviser at the moment a pension transfer, investment or withdrawal is being arranged. The sums involved make advice firms a deliberate target rather than an incidental one.

Unusually sensitive client data

Identity documents, bank details, pension and investment holdings — and, where protection advice is given, health information. It is hard to think of a small-business data set that would do more damage if it were exposed.

Advisers on the road

Laptops and phones used in clients’ homes, in cars and in coffee shops, often personally owned and frequently outside any device management. The device that holds the fact-find is the one most likely to be left somewhere.

Platform and provider logins

A dozen or more, often shared with paraplanners and administrators because that is how the work actually gets done. Shared credentials are not just a security problem — they make it impossible to say afterwards who did what.

The detection gap

This is the one that matters most from March 2027. A firm cannot report an incident it never noticed, and cannot describe one it did not record. Logging, alerting and a clear route for escalating something quickly are the difference between an incident you handled and an incident you found out about later.

An example — not a real case

What an operational incident tends to look like before anyone calls it one.

  1. 1A paraplanner’s mailbox is accessed. Nothing is deleted and nothing looks wrong; a rule quietly copies anything mentioning a transfer to an outside address.
  2. 2Three weeks later a client is mid-transfer. They receive an email in the right thread, from the right address, with revised payment instructions.
  3. 3The firm finds out when the client rings to ask why the money has not arrived.
  4. 4Now come the questions that are hard to answer without logs: when did the access start, what else was reachable, whose data was in that mailbox, and what exactly happened when.

The reporting obligation is the easy part of that story. The difficult part is being able to answer the four questions in the last line — which is a matter of what you switched on months earlier.

Which are you?

Directly authorised, or an appointed representative?

It changes where you should start, and it changes what you should buy.

Directly authorised

You own the controls, and the evidence

Nobody else is going to build this for you. We put the technical controls in place, get the logging and alerting configured so incidents are detected and evidenced, and give you an escalation route that ends at your compliance function rather than at us.

  • Detection and logging configured and monitored
  • Incident response plan with a clear internal escalation point
  • Evidence retained so the firm can describe what happened
  • Controls you can show, not just describe
Appointed representative

Start with your network’s requirements

Your network will have its own IT and security expectations, and those come first — check them before you buy anything from anyone, including us. Where they set a requirement, we help you meet it and evidence it. We do not replace your network’s framework and we would be wary of anyone offering to.

  • We work to your network’s stated requirements
  • Evidence packaged the way they ask for it
  • Gaps flagged where your setup falls short of their standard
  • No duplication of what the network already provides
How I help

Three stages, and you can stop after any of them

Most firms start with the review. Until somebody has looked at what your systems actually log, neither of us can honestly say what the rest involves.

One-off

Incident Readiness Review

Find out what you would be able to say.

A technical review of whether your firm would detect an operational incident, and whether it could describe one afterwards.

  • Microsoft 365 and Entra review — MFA, Conditional Access, mailbox rules, forwarding, admin accounts, audit logging status
  • Email authentication check: SPF, DKIM and DMARC
  • Device review — managed against unmanaged, encryption, patching
  • Inventory of platform and provider logins, and shared credential review
  • Your existing incident arrangements assessed against the operational needs: detection, escalation, evidence capture, and a clear internal decision point
  • Cyber Essentials gap analysis
  • Written report with RAG findings and a prioritised plan to be ready by 18 March 2027

The review covers what your systems can detect and evidence. Whether any given incident is reportable is a decision for your compliance function, and the report says so.

Fixed fee · quoted after a short call
Get a quote
Most firms
Project

FCA Incident Ready

Close the gaps before the date.

Everything in the review, then the work: the controls, the logging, and the plan that turns a bad morning into a documented sequence of events.

  • Everything in Incident Readiness Review
  • MFA and Conditional Access, Defender for Business, Intune compliance for laptops and phones
  • Risky mailbox rules and external forwarding found and removed
  • Audit logging and alerting configured, so incidents are detected and the evidence is kept
  • Incident response plan and escalation flow, handing off to your compliance function for the reportability decision
  • Managed Bitwarden for platform and provider logins, with role-based sharing for paraplanners and administrators
  • A procedure for verifying changes to client bank details and payment instructions
  • Supplier list template — good practice, not presented as a regulatory register
  • Cyber Essentials submission support
  • A staff session on impersonation and payment diversion
Project fee · scales with your size
Get a quote
Monthly, per person

Adviser Managed

Stay ready, and stay able to prove it.

Detection only works if someone is watching, and a plan only works if it has been tested. This is both, plus the evidence gathering on the day it matters.

  • Ongoing management of Defender, Intune, patching and Microsoft 365 backup
  • Alert monitoring and incident support, including gathering evidence to support your reporting
  • An annual incident response tabletop exercise and plan refresh
  • Annual Cyber Essentials renewal support
  • A quarterly security summary written for the accountable senior manager
  • Optional: external security monitoring, managed password manager, same-day device replacement
Monthly, per person · minimum applies
Get a quote

Everything is quoted in writing before any work starts, and no VAT is chargeable — the figure quoted is the figure you pay. Cyber Essentials certification fees are set by the certification body and passed through at cost.

Why me

Regulated-sector security, at small firm scale

Regulated-sector security background

Before founding Lewis McKee Consulting I worked in information security across the legal sector, including securing systems at five top-100 law firms and rewriting firm policy sets to meet Lexcel requirements aligned with ISO 27001. Regulated professions share a shape of problem: a body that expects evidence, and nobody in-house to produce it.

Microsoft stack, properly configured

Microsoft 365, Entra ID, Intune and Defender — configured and managed rather than merely licensed. Most of what makes an incident detectable is already in the licence you pay for, switched off.

Managed password manager

Bitwarden, deployed per person with role-based sharing, so paraplanners and administrators get the access they need without a shared credential that makes it impossible to say who did what.

Lancashire, and one person

Based in Chorley, working with small firms across Lancashire and the North West. You deal with me, not a ticket queue.

Works alongside

The pieces that make an incident visible

FAQ

Common questions

Does PS26/2 apply to my firm?+

That is a question for your compliance adviser or your network, not for us — and you should be cautious of any IT supplier who answers it definitively. What the FCA says is that the operational incident reporting rules apply to all firms with a Part 4A permission, alongside several other categories. The policy statement and the finalised guidance set out the detail, and we have linked them above. Our part is technical: making sure that if something happens, you notice it and can describe it.

Does the FCA require Cyber Essentials?+

No. The FCA does not require Cyber Essentials, ISO 27001 or any particular product or control — its expectations are framed around adequate systems and controls rather than a named certificate. Cyber Essentials is still worth doing, for reasons that stand on their own: it forces the basics into place, networks and platforms increasingly ask about it, and insurers ask cyber questions at renewal. Buy it because it is useful, not because someone told you it was mandatory.

We’re an appointed representative — doesn’t our network handle this?+

Your network sets requirements for you, and those come first. Check them before you buy anything from anyone, ourselves included. What networks generally do not do is configure your Microsoft 365, manage your laptops or hold your logs — they tell you what standard to meet and expect you to meet it. That gap is where we help: meeting the network’s requirements and packaging the evidence the way they ask for it. If your network already provides something, we should not be selling it to you twice.

Do we need a third-party register?+

The material third party reporting requirements in PS26/2 apply to a defined list of firm types — enhanced scope SM&CR firms, banks, designated investment firms, building societies, Solvency II firms, CASS large firms, UK recognised investment exchanges, authorised electronic money and payment institutions, and consolidated tape providers. That will not typically include a small advice firm, though your own categorisation is a matter for your compliance adviser. Separately from any of that, keeping a list of who your firm depends on is simply useful, and we provide a template. We do not dress it up as a regulatory register.

We’re a one- or two-adviser firm — is this proportionate?+

The work scales down; the data does not. Two advisers can hold identity documents, bank details, pension holdings and health information for several hundred clients, and arrange transfers large enough to make the firm a deliberate target. For a firm your size the review is a short job and most of the remediation is configuration in a tenant you already pay for. What does not shrink is the need to be able to say what happened.

Do you replace our compliance consultant?+

No, and the relationship works best when both exist. Your compliance consultant advises on your obligations and on whether something is reportable. We make sure the systems produce the facts they need to advise you on, and that the escalation route gets those facts in front of them quickly. We hand off at the point where the question stops being technical — that hand-off is written into the incident plan deliberately, so nobody is improvising about it on the day.

Find out what you could actually evidence

A fixed-fee readiness review tells you what your systems would detect, what they would record, and what it would take to be ready by 18 March 2027.

Book a readiness review
Enquire

Book an incident readiness review.

Tell me roughly how many of you there are, whether you're directly authorised or an appointed representative, and which platforms you use. I'll come back within one working day with a straight answer on what is involved and what it costs.

I'll only use your details to reply to your enquiry. No newsletters, no sharing.