Code

Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)

Bermuda Monetary Authority (BMA) · Bermuda

Status not confirmed

Current version last checked: 2026-07-07

Summary

This is a Bermuda Monetary Authority Code of Practice setting out mandatory and recommended operational cyber risk management standards for Digital Asset Business (DAB) registrants. It is issued under the Digital Asset Business Act 2018 and should be read alongside the Digital Asset Business (Cybersecurity) Rules 2022, the DAB Code of Practice 2022 and the DAB Custody Code of Practice 2022. The Code is not exhaustive; DABs must build their own risk-based cyber programmes, and the Authority applies the standards proportionately based on each DAB's nature, scale and complexity.

  • Governance: Board and senior management must oversee cyber risk, approve a cyber risk policy at least annually, and appoint a suitably senior CISO (in-house or outsourced, with oversight remaining with the board).
  • Risk management programme: DABs must run an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model, with an annual IT audit plan approved by the audit committee.
  • Outsourcing, cloud and third parties: Outsourced cyber functions, cloud services and third-party blockchain/smart contract tools must be risk-assessed, with contractual terms covering compliance, cooperation with the Authority and data access.
  • Detect and protect controls: Requirements cover incident management, cyber event notification to the Authority, multi-factor authentication, access management, data classification/loss prevention, malicious code protection, patch management, network security, secure application development, smart contract and DLT/blockchain security, logging/monitoring, cryptography use, and physical security of storage facilities.
  • Response and recovery: DABs must maintain and annually test business continuity and disaster recovery plans, including business impact analyses.

The Code entered into force on 1 January 2023, with full compliance required by 30 June 2023. Non-compliance is treated as a factor in assessing whether a registrant is conducting business in a sound and prudent manner.

Key obligations

  • Board must approve a cyber risk policy document at least annually and receive regular cyber risk status updates
  • DAB must appoint a suitably senior CISO responsible for delivering the operational cyber risk management programme
  • DAB must implement an operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls
  • Risk assessments must be documented and retained for at least five years, available to the Authority on request
  • An annual IT audit plan must be developed and approved by the audit committee of the board or equivalent
  • DAB must maintain an asset inventory with information classified by value, sensitivity and criticality, owned by a designated part of the business
  • DAB must risk-assess outsourced cyber functions, third-party service providers and cloud computing arrangements before use, including third-party blockchain applications, smart contracts and platforms
  • Outsourcing contracts must include terms on compliance with laws, cooperation with the Authority, and timely access to data and records
  • DAB must implement a staff vetting process
  • DAB must notify cyber reporting events to the Authority
  • DAB must implement business continuity and disaster recovery policies, including annual documented testing of BCP/DR plans and business impact analyses
  • DABs must be in full compliance with the Code by 30 June 2023

Applies to

Digital Asset Business (DAB) registrants

Deadlines

  • 1 January 2023: Date the Code comes into force
  • 30 June 2023: Deadline for DABs to be in full compliance with the Code
  • at least annually: Board must approve the cyber risk policy document
  • at least annually: IT audit plan must be developed and approved by the audit committee
  • at least annually: Cyber insurance coverage should be reviewed
  • at least five years: Retention period for documented risk assessments, to be provided to the Authority on request
  • at least annually: BCP and DR plans must be tested

Related documents

Topics

Version history

2026-07-07

source file (current)