Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The FCA’s cyber-insurance report was still in production when director of insurance Chris Knight spoke on 1 October 2026. The regulator’s schedule says its focused review is due to conclude later in 2026, but neither source gives a publication date. The findings and any recommendations have not yet been published.

What Chris Knight said about the FCA report

Knight spoke at the Chartered Insurance Institute’s Navigating Future Risks event in London on 1 October. Insurance Age reported his remarks the following day. He said the FCA was examining cyber-insurance coverage and barriers to adoption, and that the report was in production.

In the available portion of his remarks, Knight said: “We announced earlier this year that we look at cyber insurance coverage and examine the risks, opportunities and barriers to adoption.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

He also described the review as intended to explain the value and role of cover, build broader capability, highlight incident response, and address misconceptions among businesses.

What the FCA is reviewing, and when

The FCA’s 2026 Insurance Regulatory Priorities report describes the work as a “Focused product review – Cyber insurance” to improve the regulator’s understanding of the risks, opportunities, and barriers to purchase. The schedule marks the work as started and says it would conclude later in 2026.

That is a timetable for the review, not a confirmed release date for its report. Neither Knight’s remarks nor the published schedule states when the report will appear. Until it is published, no conclusions or recommendations should be attributed to this review.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How related FCA cyber work fits in

Frontier AI and cyber resilience

In a 15 May 2026 joint statement, the FCA, Bank of England and HM Treasury said regulated firms should consider whether they have appropriate insurance as part of planning for cyber risks associated with frontier AI. The statement also addresses governance, vulnerability management, third-party and supply-chain risks, protection, response and recovery. It says it is not intended to introduce new expectations. This is adjacent guidance, not a finding from the pending insurance review.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Incident and third-party reporting

Separately, the FCA announced on 18 March 2026 that new incident and third-party reporting rules for financial-services firms will take effect on 18 March 2027. The FCA said over 40% of cyber incidents reported to it in 2025 involved a third party. That figure applies to incidents reported to the FCA; it is not a measure of all UK cyber incidents or cyber-insurance uptake.

Earlier cyber-security work

The FCA’s March 2019 cyber-security industry-insights document said that, since 2017, its cyber coordination groups had brought together over 175 firms across financial sectors. The document explicitly says it is not FCA guidance. It is historical context, not a current membership figure or regulatory requirement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.