ARTICLE
17 October 2018

UK Conduct Regulator Fines Retail Bank For Failures During A Cyber Attack

SS
Shearman & Sterling LLP

Contributor

Our success is built on our clients’ success. We have a long and distinguished history of supporting our clients wherever they do business, from major financial centers to emerging and growth markets. We represent many of the world’s leading corporations and major financial institutions, as well as emerging growth companies, governments and state-owned enterprises, often working on ground-breaking, precedent-setting matters. With a deep understanding of our clients' businesses and the industries they operate in, our work is driven by their need for outstanding legal and commercial advice.
On October 1, 2018, the FCA published a final notice issued to a U.K. Retail Bank for breaches of Principle 2 of the FCA's Principles for Businesses.
UK Criminal Law
To print this article, all you need is to be registered or login on Mondaq.com.

On October 1, 2018, the FCA published a final notice issued to a U.K. Retail Bank for breaches of Principle 2 of the FCA's Principles for Businesses. Principle 2 requires authorized firms to conduct their business with due skill, care and diligence. The Bank was subjected to a cyber-attack in November 2016, when attackers deployed an algorithm to generate authentic debit card numbers that were then used to make unauthorized transactions. While the attack did not involve loss or theft of customers' personal data, the FCA found that the attack left the Bank's personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours.

The FCA has fined the Bank £16.4 million, finding that the Bank breached Principle 2 by failing to exercise due skill, care and diligence to:

  1. design and distribute its debit card;
  2. configure specific authentication and fraud detection rules;
  3. take appropriate action to prevent the foreseeable risk of fraud; or
  4. respond to the November 2016 cyber-attack with sufficient rigor, skill or urgency.

In a press release accompanying the final notice, the FCA reminds financial institutions that ensuring cyber crime controls are adequately resilient is ultimately a responsibility for the Board.

The final notice is available at: https://www.fca.org.uk/publication/final-notices/tesco-personal-finance-plc-2018.pdf  and the press release is available at: https://www.fca.org.uk/news/press-releases/fca-fines-tesco-bank-failures-2016-cyber-attack.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More