This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.

Search the website
Thought Leadership

Cyber incidents and inside information

Picture of Charlotte Hamilton
Passle image

If a business faces a cyber incident, then a number of operational plans and procedures are brought in to navigate the situation as effectively as possible. For some companies, this will include consideration of whether or not the incident constitutes “inside information” and the consequential steps which need to be taken depending on the outcome of that assessment.

To help companies who are either in that position or making preparations for that type of incident the Financial Conduct Authority’s (FCA’s) latest Primary Market Bulletin 66 provides some guidance based on recent conversations it has had with issuers and their advisors on the issuer disclosure obligations which can arise in these situations.

Initial assessment and disclosure

Not every cyber incident will constitute inside information. When an issuer initially becomes aware of an incident, it must make an independent assessment of whether it is “inside information” as defined in Article 7 of the UK Market Abuse Regulation (UK MAR).

Factors to consider in this assessment could be:

  1. the scale and nature of the incident;
  2. the reputational impact of the information; and
  3. any immediate or anticipated disruption to the issuer’s operations or financial position.

For example, where the situation affects an issuer’s ability to interact with its customers or clients such that it makes proactive or reactive communications in response, the issuer must closely consider its disclosure obligations under Article 17 of UK MAR.

An issuer may also need to issue a holding announcement, if there is a danger of a leak of inside information before the facts and their impact can be confirmed.

Even historic incidents, which no longer represent a current threat, must be assessed when they are discovered.

Delay of disclosure

A key point here is that under Article 17 of UK MAR the disclosure of inside information can only be delayed where its confidentiality can be ensured. As the perpetrator of the incident likely holds this information, the issuer must continually assess whether it remains confidential. Article 17(7) of UK MAR is clear that where an issuer can no longer ensure the confidentiality of the information, it must be disclosed to the public as soon as possible.

That said, the FCA then go on to provide some examples of where it may be appropriate to delay the disclosure of the cyber incident.

  • Where an issuer is negotiating with the perpetrators and immediate disclosure of the incident may jeopardise that process.
  • Where a vulnerability in the issuer’s systems is discovered (even where there is no active incident) and disclosing it could open up the issuer to threats.

Ongoing review of the position

Pursuant to DTR 2.2.8G an issuer must “continuously and carefully monitor” whether changes in its circumstances mean an announcement obligation has arisen under Article 17 of UK MAR. This is clearly relevant where a cyber incident is ongoing and even where an incident is resolved (for example the consequential impact of an incident on the issuer’s financial position may be inside information).

As a related point, the FCA reminds issuers of its guidance in Technical Note 521.4 that it is not permissible to justify non-disclosure by offsetting negative and positive news.

Sharing inside information with government departments, law enforcement, regulatory or crime agencies

Article 10(1) of UK MAR allows an issuer to disclose inside information to another person when the issuer is acting in the normal exercise of their employment, profession or duties and in the context of a cyber incident, an issuer may either be required, or choose, to disclose the information to a government department or law enforcement, regulatory or crime agencies in their relevant jurisdiction.

The FCA suggest that disclosing inside information about a cyber incident to an agency, such as the National Cyber Security Centre (NCSC) or the Information Commission in connection with the performance of their functions, or to information-sharing communities set up and overseen by the NCSC to assist others in preventing or mitigating cyber threats may indicate that the issuer is acting in the normal exercise of their employment, profession or duties.

To assist with this analysis, the FCA have pointed to the following guidance.

  • The FCA’s Market Conduct Sourcebook MAR 1.4.3G: sharing inside information with a government department, the Bank of England, the Competition Commission, the Takeover Panel or any other regulatory body or authority for the purposes of fulfilling a legal or regulatory obligation, or otherwise to such a body in connection with the performance of the functions of that body is a description of behaviour that does not indicate unlawful disclosure. 
  • DTR 2.5.7G: an issuer may be justified in disclosing inside information to certain categories of recipient (including for example the Bank of England or the Competition Commission) as long as the recipients are bound by a duty of confidentiality.

In this context, the FCA encourages issuers to inform any recipients that (i) the information they are about to receive is or could be inside information and (ii) they should keep the information confidential and be aware of their obligations under UK MAR.  

Issuers should also document (a) the information that has been disclosed, (b) whether they consider it to be inside information and (c) their justification for disclosing it under Article 10 of UK MAR.

Operational Incidence and Third-Party Reporting Rules

The FCA conclude by reminding regulated firms that its Operational Incident and Third-Party Reporting rules, set out in PS26/2, will come into force on 18 March 2027. This is a new reporting framework requiring firms to notify the FCA of qualifying cyber and operational incidents, providing timely information on the impact, severity and lifecycle of incidents.

 

For further information about any of the issues raised in this post, please contact Hamish Corner (Partner, Commercial and Technology), AJ Venter (Partner, Corporate and M&A), Guy Francis (Director, Corporate and M&A) or Charlotte Hamilton (Senior Associate, Corporate and M&A).

See more from Burges Salmon

Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.

Update your preferred sources

Follow us on LinkedIn

Be sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.

Follow us