ARTICLE
17 October 2018

UK Conduct Regulator Fines Retail Bank For Failures During A Cyber Attack

AO
A&O Shearman

Contributor

A&O Shearman was formed in 2024 via the merger of two historic firms, Allen & Overy and Shearman & Sterling. With nearly 4,000 lawyers globally, we are equally fluent in English law, U.S. law and the laws of the world’s most dynamic markets. This combination creates a new kind of law firm, one built to achieve unparalleled outcomes for our clients on their most complex, multijurisdictional matters – everywhere in the world. A firm that advises at the forefront of the forces changing the current of global business and that is unrivalled in its global strength. Our clients benefit from the collective experience of teams who work with many of the world’s most influential companies and institutions, and have a history of precedent-setting innovations. Together our lawyers advise more than a third of NYSE-listed businesses, a fifth of the NASDAQ and a notable proportion of the London Stock Exchange, the Euronext, Euronext Paris and the Tokyo and Hong Kong Stock Exchanges.
On October 1, 2018, the FCA published a final notice issued to a U.K. Retail Bank for breaches of Principle 2 of the FCA's Principles for Businesses.
United Kingdom Criminal Law

On October 1, 2018, the FCA published a final notice issued to a U.K. Retail Bank for breaches of Principle 2 of the FCA's Principles for Businesses. Principle 2 requires authorized firms to conduct their business with due skill, care and diligence. The Bank was subjected to a cyber-attack in November 2016, when attackers deployed an algorithm to generate authentic debit card numbers that were then used to make unauthorized transactions. While the attack did not involve loss or theft of customers' personal data, the FCA found that the attack left the Bank's personal current account holders vulnerable to a largely avoidable incident that occurred over 48 hours.

The FCA has fined the Bank £16.4 million, finding that the Bank breached Principle 2 by failing to exercise due skill, care and diligence to:

  1. design and distribute its debit card;
  2. configure specific authentication and fraud detection rules;
  3. take appropriate action to prevent the foreseeable risk of fraud; or
  4. respond to the November 2016 cyber-attack with sufficient rigor, skill or urgency.

In a press release accompanying the final notice, the FCA reminds financial institutions that ensuring cyber crime controls are adequately resilient is ultimately a responsibility for the Board.

The final notice is available at: https://www.fca.org.uk/publication/final-notices/tesco-personal-finance-plc-2018.pdf  and the press release is available at: https://www.fca.org.uk/news/press-releases/fca-fines-tesco-bank-failures-2016-cyber-attack.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More