CYBER · PRIVACY · DIGITAL TRUSTPowered by Falconry360 Book a working session

Home/Markets/United Kingdom

Market pack

United Kingdom

An outcomes-based regulatory culture rather than a control-checklist one. The platform is used differently here: less about proving a control exists, more about evidencing that a service stays inside its impact tolerance.

PRIMARY AUTHORITIES
NCSC, ICO, FCA and PRA
INSTRUMENTS IN THIS PACK
7 national and sector, plus 13 international standards
CONTRACTING
Registered UK entity. UK clients contract in the United Kingdom.

Regulatory register

What applies, to whom, and what the platform does about it. Indicative and maintained as the instruments change — applicability is confirmed per client during scoping.

United Kingdom — national and sector regulation
Authority or instrumentWhat it isWho it applies toWhat the platform does
Information Commissioner's OfficeUK GDPR and the Data Protection Act 2018, as amended; ICO accountability frameworkControllers and processorsRecords of processing, DPIA workflow, rights handling with statutory clocks, transfer risk assessment, 72-hour breach workflow
National Cyber Security CentreCyber Assessment FrameworkOperators of essential services and organisations adopting the CAF voluntarilyOutcome-based mapping across the four CAF objectives, with contributing outcomes evidenced rather than asserted
National Cyber Security CentreCyber Essentials and Cyber Essentials PlusOrganisations seeking baseline certification, including for public sector supplyReadiness position and evidence maintained between annual cycles
NIS Regulations 2018Network and information systems security dutiesOperators of essential services and relevant digital service providersDuties mapped to the control set, with incident notification workflow
FCA and PRAOperational resilience — PS21/3 and SS1/21; outsourcing and third-party risk expectationsAuthorised firmsImportant business services, impact tolerances, dependency mapping, severe but plausible scenario testing and self-assessment evidence
Bank of England, FCA and PRACritical third parties regimeDesignated critical third parties and the firms that rely on themConcentration and dependency analysis, and the supplier-side evidence firms increasingly ask for
Telecommunications (Security) Act 2021Security duties and code of practicePublic telecoms providersSector control pack mapped to the same library
International standards operating alongside the national regimes
StandardScopeHow it is used
ISO/IEC 27001:2022 and 27002Information security management system and control setCertification readiness, live Statement of Applicability, continuous gap position
ISO/IEC 27701Privacy information managementExtends the ISMS control set with privacy-specific controls and DPO workflow
ISO/IEC 27017 and 27018Cloud security and cloud personal dataApplied where the estate is cloud-hosted or cloud-delivered
ISO 22301Business continuity managementBIA, recovery objectives, plan currency and exercise evidence
ISO/IEC 42001:2023AI management systemAI inventory, impact assessment and model governance
NIST CSF 2.0Cybersecurity frameworkUsed as the neutral spine when several national regimes apply at once
NIST SP 800-53 Rev. 5Control catalogueDepth mapping where a client's control set is US-derived
CIS Controls v8Prioritised technical control setCommon baseline for technology teams
COBIT 2019Technology governanceUsed in the Govern pillar for IT and digital governance structures
SOC 2Service organisation controlsTrust services criteria for clients who serve enterprise customers
PCI DSS 4.0Payment card securityApplied where card data is in scope
IEC 62443Industrial automation and control systemsApplied to OT estates alongside the national OT controls
Open FAIRRisk quantification taxonomyThe quantification method used throughout the Anticipate pillar

Hosting and contracting

Settle residency before tenant design. It is the item most often left until too late.

Data residency

UK hosting is available. Firms with EU operations should also settle their position on EU processing and, where in scope, the EU digital operational resilience regime.

Contracting entity

Registered UK entity. UK clients contract in the United Kingdom.

How Falconry360 is hosted and secured

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.