Skip to main content

AFB Seminar: How to Manage Cybersecurity Risks Arising from Third Party and Outsourced Services

Regulators in the UK and EU have designated operational resilience as a critical regulatory requirement to protect consumers and safeguard financial stability in the event of severe disruption. This impacts non-UK banks given the increasing reliance on a networked business model and the highly interconnected digital frameworks. Cybersecurity is a key component of this, given the increasing reliance on external cybersecurity service providers.

AFB, in partnership with Pathlight Associates, invites members to an in-person seminar which will explore the regulatory and business requirements for third-party risk management (TPRM), with a key focus on cyber risk.

We are grateful to AFB member bank Banco do Brasil for hosting this event.

Why attend?

As reliance has increased over the years, robust TPRM requires a strengthening of the entire management lifecycle, including:

  • due diligence
  • contractual safeguards
  • continuous monitoring
  • access controls for digitally connected vendors
  • concentration risk
  • fourth party dependencies
  • exit planning
  • regulatory reporting

These considerations have particular implications for cybersecurity, given the vulnerabilities that can arise from reliance on third-party services and the increasing use of external cybersecurity service providers. This is especially relevant for smaller financial institutions, which may have limited capacity to maintain internal cybersecurity expertise and therefore rely more heavily on niche specialist providers.

Pathlight Associates will be joined by CyberKainos, a cybersecurity and risk advisory firm, and together will provide members with the following key takeaways:

  • How members can prepare for greater TPRM and incident reporting requirements and scrutiny
  • Preparation for greater regulatory scrutiny of cyber security arrangements
  • Assessing where outsourced cyber security capability itself constitutes a material third party arrangement and how to evidence oversight
  • Reconciling UK reporting obligations with DORA or other parent group requirements
  • An opportunity to discuss how peer group institutions are tackling these issues

Who should attend?

This seminar is aimed at Operations, IT, Information Security, Risk and Compliance teams, and those with senior accountability for operational resilience and outsourcing at AFB member banks.

Speakers

Arun Aggarwal, Associate Partner, Pathlight Associates

Formerly a Partner at PwC Management Consultants, MD of SWIFT UK and Deputy CEO of Bank of Baroda UK, Arun is a senior financial services executive and strategic advisor with over 40 years of experience across banking, fintech, payments, capital markets, and management consulting. He brings deep expertise in strategy, business transformation, corporate governance, regulatory compliance, risk management and operational excellence. In particular his recent experience has covered operational resilience and TPRM both as an Executive and adviser, across multiple sectors including large banks, small banks, wealth managers and insurance companies.  

Nick Prescot, Founder and CEO, CyberKainos

Nick is a practising Chief Information Security Officer and cyber security adviser with over 20 years of experience across financial services, pensions, pharmaceuticals, manufacturing and managed security services. His recent work has centred on third party and supply chain assurance, cyber resilience governance at board level and the practical evidencing of control effectiveness. He currently holds multiple virtual CISO roles and was security adviser to a managed security service provider, giving him a view from both sides of the cyber security vendor relationship. Nick is ISO 27001 Lead Auditor and qualified Data Protection Officer.

Logistics

Fee: Included in membership

Venue: Banco do Brasil, 3/F Floor, 280 Bishopsgate, London EC2M 4AG

Date: Tuesday 20 October 2026

Time: 09:00 – 10:15 (arrivals and breakfast from 08:30)

If you would like to submit a question or have any specific areas that you would like the session to address, please send them to AFB at secretariat@foreignbanks.org.uk. You will receive details on how to join this session a week before the event.