Latest Market Alert | 21 July 2026
Executive Summary
Cybersecurity is increasingly being viewed as a supply-chain and governance risk rather than simply an IT issue, with governments, regulators and insurers placing greater emphasis on third-party resilience following a series of high-profile cyber incidents.
The UK Government recently launched its Cyber Resilience Pledge, encouraging organisations to strengthen board-level oversight, improve supply-chain security and adopt recognised National Cyber Security Centre (NCSC) guidance. The initiative forms part of the Government’s wider Cyber Action Plan, with cyber-attacks estimated to cost the UK economy £14.7 billion each year.
At the same time, the UK has designated Microsoft, Google, Amazon Web Services and Oracle as Critical Third Parties to the financial sector. They are now subject to direct oversight by the Bank of England, Prudential Regulation Authority and Financial Conduct Authority because disruption at a major cloud provider could affect multiple financial institutions simultaneously.
Why it matters
Many organisations now depend upon hundreds of external software providers, cloud platforms and technology suppliers. Recent incidents involving major technology providers have reinforced the importance of third-party operational resilience, prompting regulators to place greater emphasis on concentration risk and dependency on a small number of critical cloud providers.
For many businesses, the greatest cyber exposure now lies not within their own networks, but within those of third parties over which they have limited control. The Financial Conduct Authority has said that more than 40% of cyber incidents reported to it during 2025 involved third parties.
UK impact
Boards should expect increasing scrutiny from insurers, lenders, regulators and major customers regarding cyber governance, supplier due diligence and operational resilience.
Businesses may increasingly be asked to demonstrate supplier risk assessments, incident response plans, business continuity arrangements and recognised cybersecurity standards before contracts are awarded or insurance cover is renewed.
Failure to demonstrate appropriate cyber governance could result in higher insurance premiums, reduced policy cover or more restrictive lending conditions.
Global impact
Governments across Europe and North America are moving towards greater regulation of digital infrastructure and critical technology suppliers.
As organisations become more dependent on cloud computing, artificial intelligence and outsourced software development, resilience throughout the supply chain is becoming a strategic business issue rather than solely a technical concern.
Investors are also paying closer attention to operational resilience, recognising that a significant cyber incident can rapidly affect earnings, reputation, regulatory compliance and shareholder value.
Our View
Cyber resilience should now be considered a core enterprise risk alongside liquidity, supply chain continuity and regulatory compliance.
Boards should ensure they understand not only their own cyber controls but also the resilience of critical suppliers. Immediate priorities should include identifying key third-party dependencies, reviewing contractual cyber obligations, testing incident response and business continuity plans, and confirming that cyber insurance accurately reflects today’s supply-chain risks.
Immediate actions for boards should include:
• identifying critical third-party technology providers;
• reviewing contractual cyber obligations and notification requirements;
• confirming cyber insurance reflects third-party outage scenarios;
• testing business continuity plans for cloud-service disruption;
• ensuring cyber resilience is a standing Board agenda item rather than solely an IT responsibility.
Risk Indicator: HIGH
Disclaimer
The information contained within this Market Alert is provided for general market awareness and informational purposes only. It does not constitute financial, investment, legal or insurance advice, nor should it be relied upon when making commercial or investment decisions. Whilst every effort has been made to ensure the accuracy of the information at the time of publication using reputable and independently verified sources, market conditions can change rapidly. Readers should seek appropriate professional advice before acting on any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
