Code

Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020)

Bermuda Monetary Authority (BMA) · Bermuda

In force

Current version last checked: 2026-07-07

Summary

This Code sets out the Bermuda Monetary Authority's requirements for operational cyber risk management in the insurance sector. It applies to all Bermuda-registered insurers, insurance managers, and intermediaries (agents, brokers and insurance market place providers), collectively termed 'registrants'. Compliance is assessed proportionately to each registrant's nature, scale and complexity, and failure to comply is a factor the Authority will weigh in assessing whether a registrant is conducting business in a sound and prudent manner.

  • Governance: Board and senior management must have oversight of cyber risk; the board must approve a cyber risk policy document at least annually and receive regular status updates.
  • CISO: A Chief Information Security Officer role (which may be outsourced) must be allocated to deliver the operational cyber risk management programme, though Board oversight responsibility cannot be outsourced.
  • Risk programme: Registrants must operate a documented operational cyber risk management programme covering risk assessment, data governance/classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.
  • Record retention: Risk assessments must be documented and retained for at least five years and made available to the Authority on request.
  • Outsourcing and cloud: Outsourced and third-party/cloud services must be risk-assessed, with contractual terms covering governance, compliance, regulator cooperation and data access, and oversight maintained as if performed internally.
  • Detect and protect controls: Registrants must implement controls across areas including incident management, logical access, data loss prevention, mobile computing, malicious code protection, patch management, network security, logging/monitoring and cryptography.
  • Incident notification: Registrants must notify the Authority of cyber reporting events.
  • Business continuity: Registrants must implement and test Business Continuity and Disaster Recovery plans at least annually, with issues tracked to remediation.

The Code entered into force on 1 January 2021, with registrants required to achieve full compliance by 31 December 2021.

Key obligations

  • Board of directors must approve a cyber risk policy document at least annually and receive regular updates on cyber risk status.
  • Registrants must allocate the CISO role (internally or outsourced) to deliver the operational cyber risk management programme.
  • Registrants must implement an operational cyber risk management programme including risk assessment, data governance/classification, and detection, protection, response and recovery controls.
  • Risk assessments must be documented and retained for at least five years and made available to the Authority upon request.
  • Registrants must maintain oversight and accountability for outsourced functions and ensure service agreements include terms on jurisdictional compliance, cooperation with the Authority, and timely data/records access.
  • Cloud computing use must be risk-assessed, covering governance/ERM, legal issues, compliance/audit, and information governance.
  • Registrants must review the adequacy of cyber insurance coverage at least annually.
  • System event logs and security logs must be retained, protected, and monitored for anomalous activity per business and regulatory requirements.
  • Registrants must implement and test Business Continuity and Disaster Recovery plans at least annually, documenting and remediating issues identified.
  • Registrants must notify the Authority of cyber reporting events.
  • Registrants must be in full compliance with the Code by 31 December 2021.

Applies to

Insurers, Insurance Managers, Intermediaries (Agents, Brokers and Insurance Market Place Providers), Limited purpose insurers

Deadlines

  • 1 January 2021: The Code comes into force.
  • 31 December 2021: Registrants are required to be in full compliance with the Code.
  • at least on an annual basis: Board must approve the cyber risk policy document.
  • at least annually: Registrants should review the adequacy of cyber insurance coverage.
  • at least five years: Risk assessments must be documented and retained for this period.
  • at least annually: BCP and DR plans must be tested.

Topics

Version history

2026-07-07

source file (current)