A competitive, strong economy can withstand disruption or attack. Read firms’ views on systemic risk, our work strengthening resilience and how to assess your own exposure.
Strong defence starts with investment in solutions that can keep our financial services and economy running throughout a hostile attack.
That’s why we brought together around 120 leaders from financial services, government and defence for our Defence, Security, and Resilience (DSR) Lab.
Held in partnership with the Ministry of Defence (MoD), the DSR Lab took attendees through a deliberately challenging scenario. This included: regional Global Navigation Satellite System (GNNS) spoofing, multiple damaged subsea cables, and a cyberattack on a cable landing station.
Working with the MoD brought defence insight into the discussion and helped firms consider how hostile activity, supply chain disruption and dual-use technologies (equipment that has both military and civilian use, like drones) can affect both market integrity and the UK’s wider security.
Unlike traditional firm-level exercises, it focused on opportunities for investment to strengthen national resilience as well as systemic risks across the sector.
Our findings
Firms felt less confident about spotting shared risks
Firms may understand their own vulnerabilities and invest accordingly, but the exercise showed a gap in how they think about dependencies, and risks at a system level.
Firms want clearer signals before committing capital
They want more clarity on national threats and priorities before they commit capital. Firms may find it difficult to identify where resilience investment is most needed and how to measure its value.
International dependencies need to be considered when planning for resilience
The UK relies on global technology providers for parts of its financial services infrastructure. It’s, therefore, important to understand where key, global dependencies are and how UK resilience can be strengthened.
There are multiple shared dependencies between firms
These include communications networks, satellite systems, subsea cables, and public sector databases. These support the sector's access to the information and systems, such as precision timing, that it needs to function.
Firms may rely on the same infrastructure to serve customers or deliver services to one another but often don't know how much they share these dependencies. For example, several firms may rely on the same cable route, software or hardware supplier without realising the extent of that overlap.
It is also important to consider whether back-up systems are genuinely independent, share the same points of failure or can withstand additional traffic when under stress during an incident.
Some risks can't be solved alone
There’s appetite for stronger cross-industry collaboration to tackle shared risks. Cyber security was given as a topic where information-sharing and joint working already deliver results.
FCA's role
The Government has called for a whole-of-society approach[1] to preparedness and resilience, recognising that the UK cannot rely on any single sector to protect itself against modern, complex threats.
When core systems or technology the sector depends on are disrupted, it directly affects the integrity of financial markets. Building resilience is crucial to protecting these markets.
Many of the dependencies raised in the DSR Lab, including power and telecoms, sit entirely outside the sector's control.
Participants were clear that the UK needs a broader conversation about the threat landscape and the value of preparedness, one that challenges long-held assumptions about defence, resilience, and the trade-offs built into global supply chains. That conversation must include the wider economy, not just financial services, and many want to keep engaging as it develops.
What’s next
We’re committed to supporting the financial sector in understanding these risks, building resilience, and engaging with UK defence and dual-use sectors.
We plan to further investigate these themes:
- How we can support intelligence sharing with the financial sector.
- Whether more focus is needed on back-up, ‘fail-safe’ technologies that can be used when disruption hits.
- Exploring access to banking and finance frictions.
How to assess your firm’s risk and support UK resilience
Questions to help firms think about their exposure to systemic risk and how they can support UK resilience. These aren't requirements, they're a starting point to review your own position.
- Have you mapped your firm’s systemic vulnerabilities: are they internal, external or supply chain dependencies? For example, if you rely on public sector databases, cloud services or payment infrastructures operating outside your business. How are your vulnerabilities spread across the technology, service providers, locations and people within your firm?
- Have you tested whether your back-up systems would be resilient if a disruption also affected other firms relying on the same back-up provider or infrastructure?
- Have you considered how your firm's crisis communications would need to change if disruption or conflict-related events were affecting multiple firms, or the whole sector, simultaneously, rather than just you? How would you sustain your communications over a longer period?
- Does your firm provide a single point of failure, and if so, how quickly could your disruption impact others?
- Can your firm access defence sector expertise to support defence and dual-use clients’ access to finance?
- (For investors) Do you ask investee companies about their resilience measures?
This information reflects discussion at the DSR Lab under the Chatham House Rule. The scenario used was chosen to frame discussion and doesn’t reflect any prediction or risk assessment by the FCA or Government.
It does not represent FCA or Government guidance on firms' regulatory obligations, nor any assessment of specific risks or investment priorities.