An incident response plan sets out how a regulated firm identifies, manages, and reports significant incidents, including data breaches, operational failures, and cyberattacks. The FCA requires regulated firms to have documented incident management arrangements and to report certain incidents to the FCA and, where applicable, to the ICO.
We draft incident response plans for consumer credit businesses and other FCA-regulated firms, covering incident identification and classification, internal escalation, FCA and ICO notification requirements, customer communication obligations, and post-incident review.