The UK financial regulator has released its findings after looking into the impact the CrowdStrike incident had on operational resilience in the UK financial services sector.
“Since the beginning of 2023, we’ve seen a continued trend of third-party related incidents,” said the Financial Conduct Authority (FCA). Between 2022 and 2023, third-party related issues were the leading cause of operational incidents reported, it added.
The outages emphasise firms’ increasing dependence on unregulated third parties to deliver essential services that can impact a firm’s ability to operate.
The regulator has reminded firms that they must ensure they can continue to provide essential business services during an event such as CrowdStrike, in line with operational resilience guidelines (PS21/3). Firms have until March 2025 to ensure the necessary measures are in place to achieve this.
The FCA’s analysis of the incident found that firms that had mapped their important business services – and the resources necessary to deliver these services – were able to prioritise getting key services back online to reduce the overall impact the incident had on their operations.
It also found that firms benefited from having tested scenarios that were severe but plausible, including those impacting multiple important business services at the same time. Firms who had clearly defined and tested communications strategies were able to quickly and efficiently respond to and communicate with, customers and stakeholders, it said.
You can view the full analysis, including recommendations for next steps, here.





