FAQ

Questions regulated firms ask us.

Short, sourced answers on FCA, PRA and SRA expectations, Microsoft 365, ISO 27001, Cyber Essentials and working with Cre8 IT.
UK regulators

The rules behind the questions

What is the difference between the FCA, the PRA and the SRA?

The FCA regulates the conduct of financial services firms in the UK, and the prudential standards of firms the PRA does not supervise. The PRA, part of the Bank of England, supervises the safety and soundness of banks, building societies, insurers and major investment firms, which are regulated by both. The SRA regulates solicitors and law firms in England and Wales.

Which rules cover IT and cyber security for FCA and PRA regulated firms?

Mainly SYSC (systems and controls), SYSC 8 on outsourcing and, for in-scope firms, SYSC 15A on operational resilience. Dual-regulated firms also follow the PRA’s SS1/21 and SS2/21. See our FCA and PRA guide and our page for law firms.

How quickly must we report a cyber incident?

FCA-regulated firms must tell the FCA promptly about significant operational incidents today, and from 18 March 2027 most firms must report within 24 hours of deciding that an incident meets the new threshold. Law firms should report cyber incidents that affect clients to the SRA promptly. Personal data breaches go to the ICO without undue delay and, where feasible, within 72 hours.

Are these pages legal advice?

No. They summarise what regulators publish and how firms can meet it. Confirm the current rules and take advice from your compliance officer or legal adviser about your own obligations.
Microsoft 365 and security basics

Plain answers to common security questions

What is Microsoft 365 governance?

It is the set of decisions, settings and records that control who can reach your data, from which devices, how long it is kept and how you would prove it. It covers identity, devices, sharing, retention and logging. See the full guide.

What is multi-factor authentication and why do regulators expect it?

Multi-factor authentication (MFA) asks for a second proof of identity, such as an authenticator app, as well as a password. Stolen passwords are a common way in, and MFA stops most of those attacks. Cyber Essentials now requires MFA on cloud services wherever it is available, and regulators expect strong authentication for remote and privileged access.

What is the difference between ISO 27001 and Cyber Essentials?

ISO 27001 certifies a full information security management system covering governance, risk, people, suppliers and technology. Cyber Essentials is a UK scheme that verifies five technical controls. Cyber Essentials is a quicker, cheaper baseline; ISO 27001 is broader. See our guides to ISO 27001 and Cyber Essentials.

What does “audit ready” mean for IT?

It means you can produce, on request, evidence that your controls exist, operate and are reviewed: registers, dated reports and records with named owners. Our audit readiness checklist shows how to build it.

What is SOC as a Service?

SOC as a Service is round-the-clock threat monitoring by a dedicated security operations centre, delivered as a managed service, so you get 24/7 detection without building your own team.
Working with Cre8 IT

About our service

Where is Cre8 IT based and who do you support?

Our UK office is in Blackwood, South Wales, and we also have offices in Dubai and Riyadh. In London we focus on financial services firms, law firms and other regulated businesses in Canary Wharf and the City. We have supported businesses since 2012 across hospitality, retail, finance and education, including regulated financial firms.

Which certifications does Cre8 IT hold?

We are certified to ISO 27001:2022 for information security and ISO 9001 for quality management, and we are a certified Microsoft Partner.

What does managed IT support include?

A helpdesk phone line and ticketing system, proactive monitoring of networks and devices, virus detection and removal, scheduled backups with tested recovery, on-site visits as often as you need, and 24/7 emergency support.

How is managed IT support priced?

A fixed monthly rate shaped around your requirements, your budget and how often you want us on site. Ask for a free estimate.

Do you offer 24/7 support?

Yes. We provide 24/7 emergency IT support, on site or remote.

Can start-ups and non-profits get a free consultation?

Yes. New start-ups and non-profits can book a complimentary 30-minute consultation.

Talk to a specialist about your obligations

Tell us about your firm and your regulator, and we will suggest a practical first step, whether that is a gap assessment or ongoing support.