
FCA CP24/28: What’s changing and why security teams should act now
FCA CP24/28 will change how firms report operational incidents and manage critical third parties. What’s changing and why security teams should act now.
Talk to an expert +44 (0) 208 132 9267

FCA CP24/28 will change how firms report operational incidents and manage critical third parties. What’s changing and why security teams should act now.

Cyber security in 2026 is shaped by AI-driven attacks, identity-based risk, deepfakes, and fragile supply chains. Discover what security and risk leaders must prioritise now to strengthen resilience and recovery.

At Toro, physical security training is about behaviour, not just rules. We teach people how real incidents start, how attackers exploit politeness and routine, and how small actions by ordinary staff prevent serious harm.

Resilience isn’t built on plans alone. Learn how breaking down silos, improving communication and connecting people strengthens real organisational resilience.

Lost or stolen devices are a common cause of security incidents. A calm, methodical response in the first few minutes helps contain the situation and protects both personal and organisational information.

Vishing, or voice phishing, uses impersonation, urgency and confidence to manipulate people over the phone. A calm and structured response in the first few minutes can prevent account compromise, data loss or financial harm.

Every organisation runs on technology. It keeps teams connected, systems running and data flowing but that reliance on IT and cloud services comes with risk. That is why more organisations are turning to cyber security consulting.

If one supplier experiences a security breach or operational failure, the impact can spread quickly through your business. That is why third party risk management is now a critical part of building organisational resilience.

Cyber security threats are rising at an unprecedented pace in both frequency and sophistication. From phishing emails and ransomware to AI-powered attacks, businesses of all sizes are now at risk.

Cyber-attacks are no longer rare events; they are an everyday risk for businesses of all sizes. A well-executed cyber security review is one of the most effective ways to reduce this risk.

A Physical Security Review is a structured evaluation of how well an organisation’s physical environment protects its people, assets, and operations.

Learn how Secure by Design unites physical, cyber and people to reduce risk, cut rework and build resilience with a clear, measurable roadmap.