Regulated UK financial services firms are estimated to spend 7 to 10% of revenue on IT, against a general UK SME benchmark of 4 to 6%. The investment is real, but for many firms, the resilience it’s meant to buy is not fully arriving. That gap, between what a regulated business spends on IT and what it can actually evidence when a regulator asks, is the more useful story than the raw spending figure itself. It is not a failure of technology. It is a failure of what the extra spend gets pointed at.
What the Numbers Say
The clearest national picture comes from the government’s Cyber Security Breaches Survey 2025/2026. 43% of UK businesses reported a breach or attack in the last 12 months, a figure that has barely moved in three years. Larger and more mature organisations, the segment most regulated financial firms sit within, report breaches at a considerably higher rate than small businesses: 74% of large businesses and 67% of medium-sized businesses identified an attack, against 42% of small businesses and 35% of micro businesses. Read carefully, that’s at least partly a visibility effect. Bigger, better-resourced IT functions detect more of what’s actually happening rather than facing more genuine risk.
The FCA’s own review tells a more direct story. Firms in scope of its operational resilience rules were required, by 31 March 2025, to map their important business services and be able to demonstrate they could stay within defined impact tolerances under a severe but plausible disruption. A year on, the FCA found real progress, firms have invested in data vaulting, immutable back-ups, and standby data centres specifically to meet this bar. But the same review is candid that many firms would still struggle to remain within their impact tolerances during a severe cyber attack or a significant outage at a third-party provider. That review covers firms large enough to sit directly within the FCA’s scope. For smaller regulated SMEs, the gap between IT spend and demonstrable resilience is likely wider still, because the governance and testing discipline hasn’t caught up with the compliance tooling being bought.
Why the Resilience Isn’t Arriving
Three patterns explain most of the gap, and they compound each other.
The Documentation Gap: Buying Tools Without Producing Evidence
Spend on monitoring and patch management tooling doesn’t automatically produce what a regulator wants to see. A platform can enforce policy perfectly and still leave a business unable to answer a simple audit question, because nobody checked that the tool exports a usable patch history and change log as a matter of course, rather than as a report someone has to remember to run.
The Supplier Gap: Reviewing Your Own Controls While Ignoring Theirs
Only 15% of UK businesses formally review the cyber risk posed by their immediate suppliers, and just 6% look at the wider supply chain, per the same 2025/2026 survey. FCA rules are explicit that a firm remains accountable for the resilience of a third party it relies on, whether that’s a cloud provider or an outsourced IT function. Spending more on internal controls while leaving supplier risk largely unreviewed is spending against the wrong line item.
The Testing Gap: Mapping a Plan Without Rehearsing It
Mapping important business services and setting impact tolerances is necessary but not sufficient. The FCA’s own observation, a year past the deadline, is that many firms could still struggle under a genuinely severe scenario. A plan that exists on paper and a plan that’s actually been tested against a realistic disruption are different things, and only one of them holds up under scrutiny.
What Closing the Gap Actually Looks Like
Three observable differences between businesses whose IT spend is converting into demonstrable resilience and those where it isn’t.
One: They treat compliance evidence as a by-product of the tooling itself, not a separate project someone has to remember to run. Patch history and device compliance records are exportable on demand, not reconstructed under audit pressure.
Two: They review supplier and third-party risk with the same rigour they apply to their own systems, rather than assuming a supplier’s size or reputation is a substitute for actually checking.
Three: They test the plan against a realistic scenario before a regulator, a client due-diligence review, or an actual incident does it for them.
What This Means for Your Business
The implication isn’t that regulated firms are spending too much on IT. It’s that the extra spend needs to be pointed at evidence, supplier oversight, and tested resilience specifically, not just at more tooling layered on top of the same underlying gaps. Spend is easy to measure. Whether it’s converting into something that holds up under a regulator’s questions is a harder, more useful question to keep asking.
This is the second edition of the Dr Logic Index, a regular look at what the data says about how UK businesses and technology are getting on together.
Read the first edition here: The Dr Logic Index: UK Businesses Are Spending More on Technology Than Ever. So, Why Is Productivity Flat?



















































