Operational Resilience Consulting for FCA-Regulated Firms
Practical, senior-led operational resilience consulting for UK financial services, from important business service mapping to DORA readiness and board reporting.
FCA and PRA operational resilience obligations
UK regulated firms must identify their important business services, set impact tolerances and demonstrate they can remain within them through severe but plausible disruption. We help boards translate PS21/3 and SS1/21 into practical scenarios, mapped dependencies and evidenced testing, not paperwork.
DORA readiness for UK firms
The Digital Operational Resilience Act applies to EU financial entities and reaches UK firms via EU counterparties, group entities and cross-border services. We assess DORA exposure, map it against existing FCA obligations and build a single, non-duplicative control set.
Important business services and impact tolerances
Defining what actually matters to customers and the market, then quantifying how long a disruption can last before harm becomes intolerable. We facilitate the analysis with business, technology and risk leaders together, so tolerances are owned, not imposed.
Third-party and concentration risk
Most resilience failures start with a supplier. We strengthen due diligence, exit planning, sub-outsourcing visibility, incident notification and continuous monitoring, aligned with the FCA critical third-parties regime and DORA's ICT third-party rules.
Incident response and cyber resilience
Preparation, executive decision-making, communications, recovery and lessons-learned, so incidents do not become crises. Includes cyber incident exercising, ransomware scenarios and regulator-facing reporting.
Cyber security board reporting
Clear, comparable reporting for boards and audit committees covering material risks, control effectiveness, supplier exposure, incident trends, regulatory obligations and progress against the resilience roadmap.
Related
Operational resilience guide
A practical guide to PS21/3, SS1/21 and DORA for FCA-regulated firms.
Read the guide →ISO/IEC 27001 consulting
Certification support and ISMS design for regulated organisations.
Read more →Virtual CISO and vCISO
Senior cyber security leadership without a permanent hire.
Explore vCISO services →