UK Conduct Regulator Fines Retail Bank for Failures During a Cyber Attack

A&O Shearman
Contact

Shearman & Sterling LLP

The UK Financial Conduct Authority has published a final notice issued to a UK Retail Bank for breaches of Principle 2 of the FCA's Principles for Businesses. Principle 2 requires authorized firms to conduct their business with due skill, care and diligence. The Bank was subjected to a cyber-attack in November 2016, when attackers deployed an algorithm to generate authentic debit card numbers that were then used to make unauthorized transactions. While the attack did not involve loss or theft of customers' personal data, the FCA found that the attack left the Bank's personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours.

The FCA has fined the Bank £16.4 million, finding that the Bank breached Principle 2 by failing to exercise due skill, care and diligence to:

  • design and distribute its debit card;
  • configure specific authentication and fraud detection rules;
  • take appropriate action to prevent the foreseeable risk of fraud; or
  • respond to the November 2016 cyber-attack with sufficient rigor, skill or urgency.

In a press release accompanying the final notice, the FCA reminds financial institutions that ensuring cyber crime controls are adequately resilient is ultimately a responsibility for the Board.

View the final notice.

View the press release.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Attorney Advertising.

© A&O Shearman

Written by:

A&O Shearman
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

A&O Shearman on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide