Cyber incidents and inside information
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
If a business faces a cyber incident, then a number of operational plans and procedures are brought in to navigate the situation as effectively as possible. For some companies, this will include consideration of whether or not the incident constitutes “inside information” and the consequential steps which need to be taken depending on the outcome of that assessment.
To help companies who are either in that position or making preparations for that type of incident the Financial Conduct Authority’s (FCA’s) latest Primary Market Bulletin 66 provides some guidance based on recent conversations it has had with issuers and their advisors on the issuer disclosure obligations which can arise in these situations.
Not every cyber incident will constitute inside information. When an issuer initially becomes aware of an incident, it must make an independent assessment of whether it is “inside information” as defined in Article 7 of the UK Market Abuse Regulation (UK MAR).
Factors to consider in this assessment could be:
For example, where the situation affects an issuer’s ability to interact with its customers or clients such that it makes proactive or reactive communications in response, the issuer must closely consider its disclosure obligations under Article 17 of UK MAR.
An issuer may also need to issue a holding announcement, if there is a danger of a leak of inside information before the facts and their impact can be confirmed.
Even historic incidents, which no longer represent a current threat, must be assessed when they are discovered.
A key point here is that under Article 17 of UK MAR the disclosure of inside information can only be delayed where its confidentiality can be ensured. As the perpetrator of the incident likely holds this information, the issuer must continually assess whether it remains confidential. Article 17(7) of UK MAR is clear that where an issuer can no longer ensure the confidentiality of the information, it must be disclosed to the public as soon as possible.
That said, the FCA then go on to provide some examples of where it may be appropriate to delay the disclosure of the cyber incident.
Pursuant to DTR 2.2.8G an issuer must “continuously and carefully monitor” whether changes in its circumstances mean an announcement obligation has arisen under Article 17 of UK MAR. This is clearly relevant where a cyber incident is ongoing and even where an incident is resolved (for example the consequential impact of an incident on the issuer’s financial position may be inside information).
As a related point, the FCA reminds issuers of its guidance in Technical Note 521.4 that it is not permissible to justify non-disclosure by offsetting negative and positive news.
Article 10(1) of UK MAR allows an issuer to disclose inside information to another person when the issuer is acting in the normal exercise of their employment, profession or duties and in the context of a cyber incident, an issuer may either be required, or choose, to disclose the information to a government department or law enforcement, regulatory or crime agencies in their relevant jurisdiction.
The FCA suggest that disclosing inside information about a cyber incident to an agency, such as the National Cyber Security Centre (NCSC) or the Information Commission in connection with the performance of their functions, or to information-sharing communities set up and overseen by the NCSC to assist others in preventing or mitigating cyber threats may indicate that the issuer is acting in the normal exercise of their employment, profession or duties.
To assist with this analysis, the FCA have pointed to the following guidance.
In this context, the FCA encourages issuers to inform any recipients that (i) the information they are about to receive is or could be inside information and (ii) they should keep the information confidential and be aware of their obligations under UK MAR.
Issuers should also document (a) the information that has been disclosed, (b) whether they consider it to be inside information and (c) their justification for disclosing it under Article 10 of UK MAR.
The FCA conclude by reminding regulated firms that its Operational Incident and Third-Party Reporting rules, set out in PS26/2, will come into force on 18 March 2027. This is a new reporting framework requiring firms to notify the FCA of qualifying cyber and operational incidents, providing timely information on the impact, severity and lifecycle of incidents.
For further information about any of the issues raised in this post, please contact Hamish Corner (Partner, Commercial and Technology), AJ Venter (Partner, Corporate and M&A), Guy Francis (Director, Corporate and M&A) or Charlotte Hamilton (Senior Associate, Corporate and M&A).
Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.
Update your preferred sourcesBe sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.
Follow us