Connect with us

Business & Technology

why this is only the beginning for financial institutions

Published

on


The rapid evolution of technology over the past decade has left many industries heavily dependent on a small number of cloud platforms and SaaS providers. Few illustrate that statement better than the UK financial sector.

It’s exactly the reason why the Government, in close collaboration with financial regulators, has introduced the Critical Third Parties (CTPs) regime.

I’m sure many in the sector will have welcomed July’s decision to designate  Microsoft, Google Cloud, AWS and Oracle as the first CTPs, and it certainly marked the point at which the UK’s new oversight regime moved from theory and policy into practice. It’s reassuring and comforting. But only to a point. 

The CTP regime establishes an important regulatory baseline. The bigger challenge for financial institutions is understanding and reducing operational risk. 

Just because designated CTPs are now subject to greater regulatory oversight doesn’t automatically give financial institutions greater visibility into the wider software ecosystem that supports them. Regulatory oversight and operational visibility don’t always go hand in hand.

A different kind of dependency

To understand why the CTP regime matters, it’s worth looking at the dramatic shift in the financial services landscape over the past two decades.

Twenty years ago, banks built, owned and managed much of their own software infrastructure. Fast forward to today and things are so different. Cloud platforms, specialist software, outsourced infrastructure and third-party services have become part of day-to-day operations. 

For everything from processing payments to managing customer data to running internal systems, financial institutions now rely on an extensive network of software suppliers, cloud platforms and SaaS providers.

That shift has brought huge benefits. It’s made the sector more efficient, more innovative and more competitive. It has also concentrated operational risk. As software has become more centralised and cloud adoption has accelerated, more firms have become dependent on the same providers for an ever-expanding range of critical services. The growth of AI services could reinforce that trend further.

That’s exactly what the CTP regime is designed to address. It recognises that some providers have become so deeply embedded in the UK’s financial system that disruption to their services could have consequences across the wider market. It also creates an opportunity for firms to have more meaningful conversations about the resilience of those providers and the risks that sit beneath them.

The responsibility still sits with businesses 

It’s easy to see how leaders might take comfort from the establishment of the new regime. If the regulator is supervising the services provided by designated CTPs, surely that’s one less thing to worry about? Well, not quite. 

Oversight of CTPs is only one part of the picture. Financial institutions need greater visibility into the software suppliers, infrastructure and services supporting those providers, as well as the risks that could affect their continued delivery. More and more, those conversations are taking place in the boardroom.

Many financial institutions already have a detailed understanding of their own critical applications and software dependencies. Visibility becomes less clear further down the chain, where designated CTPs rely on their own software suppliers, infrastructure and services. Those fourth-party dependencies have historically been opaque to financial institutions, creating the potential for a further layer of concentration risk beneath the CTPs themselves.

Historically, financial institutions have had limited visibility of those dependencies and little opportunity to ask detailed questions about them. The CTP regime gives them a stronger foundation for doing so, helping them better understand how risk is managed across the wider software ecosystem.

Preparing for stressed exits  

Building that understanding begins with looking beyond an organisation’s direct dependencies and into the wider software supply chain supporting its critical services. 

From there, firms need a clear view of how disruption would spread through the organisation, which services would be affected first, and where recovery efforts should be prioritised.

Resilience planning also needs to account for scenarios beyond a technical outage. A critical software supplier may experience financial instability, enter administration or lose the ability to provide an essential service. Those are exactly the kinds of situations that stressed exit plans are designed to address.

The objective isn’t simply to satisfy a regulatory requirement. It’s to understand how critical services would continue to operate if a supplier could no longer deliver them, and to validate those arrangements before they’re ever needed. For many organisations, that includes software escrow and other continuity mechanisms that have already been tested under realistic conditions.

Technology failures are only one source of disruption. Organisations that understand their software dependencies, test their recovery arrangements and plan for a range of failure scenarios will always be better placed to respond.

The designation of CTPs is an important milestone for the sector and raises the standard for resilience across some of the UK’s most important technology providers. Financial institutions should see the designation of CTPs as an opportunity to look beyond the providers themselves and better understand the wider software ecosystem that supports them. That’s how the sector could build greater operational resilience over the years ahead.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Business & Technology

Phoenix Software staff win Broadcom VCF Knight status

Published

on



JOSEPH GABRIEL LAGONSIN

News Editor

Phoenix Software has announced that two employees have achieved Broadcom VCF Knight status, Broadcom’s highest recognition for partner professionals.

Infrastructure Practise Lead Richard Worth and Senior Technical Consultant Robert Dent both received the Broadcom VCF Knight – Storage certification, recognising expertise in VMware Cloud Foundation-related storage.

The achievement strengthens Phoenix’s position within Broadcom’s partner network, where it holds UK Pinnacle and Expert Advantage status. It also reflects continued investment by the York-based business in technical staff with specialist VMware expertise.

Broadcom’s Knight programme identifies partner specialists with experience in the architecture, design, implementation and support of Broadcom technologies. In this case, the focus was on VMware Cloud Foundation and related storage work.

The process involves several stages rather than a single exam. Candidates must pass multiple advanced technical tests, submit evidence of customer designs, deliver a live technical demonstration to a Broadcom sponsor, and then undergo nomination and review by a Broadcom panel.

The certification typically takes several months to complete and requires periodic renewal, making it a relatively rare qualification within the VMware and Broadcom partner ecosystem.

Worth has worked in IT for more than 25 years, including nine at Phoenix, where he leads the infrastructure practice. His background spans networking, storage and virtualisation, all closely tied to the technologies covered by VMware Cloud Foundation.

Dent has worked with VMware technologies for more than 20 years, beginning during an early IT apprenticeship and later implementing virtualisation environments at the University of Hull. His experience also includes servers, storage, NetApp and vSAN, and he gained his first VMware certification while working at the university.

Technical route

The certifications come as many customers reassess their VMware environments following Broadcom’s acquisition of the software business. That has increased scrutiny on partners able to demonstrate deep product knowledge and delivery experience.

Both men completed the same rigorous process to secure the designation, which Phoenix described as evidence of its ability to support organisations running complex virtualised infrastructure.

Worth said: “The difference with the Knight programme is that it recognises not just what you know, but what you’ve actually delivered. It reflects real-world experience – designing, implementing, and solving problems for customers. For me, VCF brings together everything we do across networking, storage, and virtualisation into one cohesive platform.”

Dent linked the certification to customer expectations around complex infrastructure projects.

Dent said: “This is one of the highest standards a consultant can achieve. It’s exactly the level of expertise customers expect when they’re investing in complex platforms like VMware Cloud Foundation. For me, it’s also about continuing to learn and building environments where the wider team can develop their skills.”

Phoenix operates across software licensing, hardware, software asset management and managed IT services, and has been in the market for more than 30 years. It works with public and private sector customers on IT strategy, infrastructure design, deployment and software management.

The latest certifications suggest the company is seeking to deepen specialist skills in core infrastructure areas as customers continue to assess how they manage virtualisation, storage and networking in consolidated cloud environments.



Source link

Continue Reading

Business & Technology

Connected building systems pose growing cyber risk

Published

on


Restore Information Management has warned that connected building systems are becoming a cyber security risk for organisations, with many businesses failing to secure operational technology such as building management systems, access control and CCTV.

The warning comes as attackers expand their focus beyond traditional IT to target the technology that supports day-to-day building operations. These systems are increasingly internet-connected, remotely managed and linked to cloud services, widening the number of potential entry points for attackers.

Official figures underline the scale of the issue. The latest UK Government Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the past 12 months.

David Robinson, Head of Cybersecurity at Restore Information Management, said many organisations have basic weaknesses across their operational technology environments, particularly default settings and poor access controls.

“Many building systems still rely on default credentials straight out of the box. If these credentials aren’t changed, cyber criminals can gain access to critical systems with relative ease. As today’s digital building systems become increasingly connected, remotely managed and cloud-based, they are evolving faster than many organisations can secure them. Without the right controls, attackers could disrupt critical building systems, disable physical security measures or use them as a route into the wider corporate network,” Robinson said.

Attack surface

Robinson said one of the main steps organisations should take is to establish a full inventory of connected building systems, including building management systems, access control platforms, CCTV networks and environmental controls.

In practice, that means knowing what equipment is connected to the network, who is responsible for managing it and how users, contractors and suppliers can access it. Security teams often have a clearer view of laptops, servers and business applications than of operational technology embedded in buildings, creating a gap that can persist for years.

He also highlighted the risk posed by shared and default credentials. Manufacturer-set passwords remain common across a range of connected systems, and shared accounts can make it difficult to trace activity or remove access when a staff member or contractor leaves.

Restore urged organisations to replace default credentials as soon as systems are deployed, remove shared logins and ensure each employee or contractor has an individual account. That allows access to be monitored and withdrawn when required.

Remote access

Another area of concern is remote access for suppliers and maintenance providers. Building systems often rely on outside specialists for configuration, support and servicing, but these links can remain open long after a project has ended.

Robinson said access should be formally approved, reviewed regularly and removed once work is complete or contracts expire. Dormant contractor accounts, he added, should not remain active.

The issue has become more pressing as facilities technology has become easier to access from outside a site. Remote management can help operators maintain systems across multiple buildings, but it also creates another route that needs oversight from both facilities and cyber security teams.

Network separation

Restore also called for stronger segmentation between operational technology and corporate IT environments. Separating building systems from wider business networks can limit the damage if one part of the estate is compromised.

This matters because attackers who gain access to a connected operational system may try to move laterally into more sensitive parts of the organisation. Segmenting networks can make that movement harder and reduce the impact of a breach.

Security and facilities teams should work together to review legacy environments and identify where older systems can be better isolated. In many organisations, building technology has evolved in stages over a long period, leaving a mix of old and new equipment with varying security controls.

Strategic priority

Robinson’s final point was that operational technology should no longer sit outside mainstream cyber planning. He argued that connected building systems need to be included in an organisation’s wider security strategy, with regular reviews, staff awareness and stronger security design at the point of deployment.

That view reflects a broader shift in cyber risk management as physical infrastructure becomes more digital. Systems once treated mainly as facilities assets are now part of an organisation’s connected estate and can affect both physical security and business continuity if disrupted.

Restore Information Management is one of the UK’s larger information management providers and says it works with more than 6,000 clients, including more than 80% of NHS trusts. “Cyber security is no longer confined to servers and laptops. As buildings become smarter, the systems that control them require the same level of protection as every other critical asset,” Robinson said.



Source link

Continue Reading

Business & Technology

Prince William-backed helicopter company profits rise

Published

on



Airbus Helicopters opened a new £50m headquarters and factory facilities at Oxford Airport in Yarnton.

Opened in September 2024 by Prince William, Airbus Helicopters employs around 250 people in Oxford and has room for 32 helicopters.

New accounts published by the company shows the business reported an annual profit of £10.1m in the calendar year 2025 also its first full year from Oxford.

This was up 13 per cent from £8.9m the year before.

READ MORE: Jeremy Clarkson praised for his efforts as he admits ‘no feeling like it’

Airbus Helicopters said this profit was boosted by a £2.5m foreign exchange gain and was despite a drop in turnover.

“The company has now completed its first full year of operations at the new, larger hangar facility at London Oxford Airport, following the move in July 2024 and the commencement of a 25-year lease agreement,” said Yann Rozo of Airbus Helicopters in a report.

“The company would like to recognise the positive contribution of its customers, employees and other stakeholders in achieving the results of 2025 and looks to further enhance these relationships during 2026.”

Revenue for 2025 was at £138.9m compared with £158.6m the year before.

The decrease in turnover compared to the prior year has been attributed to the timing of aircraft deliveries and the expiry of a Ministry of Defence contract.

Airbus completes helicopters built in France and Germany at its Oxford site before selling on to customers including the National Police Air Service.





Source link

Continue Reading

Trending