Consultation Paper

Insurance Sector Operational Cyber Risk Management Code of Conduct (Consultation, December 2019)

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Current version last checked: 2026-07-07

Summary

This is a December 2019 consultation draft from the Bermuda Monetary Authority proposing a new Insurance Sector Operational Cyber Risk Management Code of Conduct. It sets out detailed governance, risk management, technical control and incident reporting standards for cyber and IT risk, to be issued under Section 2BA of the Insurance Act. The Authority invited comments on the proposals by 31 January 2020; as a consultation draft it is not yet in force.

The proposed Code would apply to all Bermuda registered insurers, insurance managers and intermediaries (agents, brokers and insurance market place providers), referred to collectively as registrants. It applies a proportionality principle so that expected controls scale with a registrant's nature, size and complexity, and expects registrants using outsourced or third-party IT services to obtain confirmation of the provider's compliance.

  • Governance: Board and senior management must have oversight of cyber risk, approve a Cyber Risk Policy at least annually, and receive regular cyber risk status updates; a CISO role must be allocated and a Three Lines of Defense model applied.
  • Risk management programme: Registrants must implement an Operational Cyber Risk Management Programme covering risk identification, evaluation and management; information security and data governance controls; and detection, protection, response and recovery controls.
  • Audit: A cyber risk audit plan must be developed and approved by the audit committee, with independent IT audit assessments reported to the board.
  • Outsourcing and third parties: Registrants must maintain oversight and accountability for outsourced or third-party IT functions, include compliance and regulatory access terms in service agreements, and require providers to meet controls at least as stringent as the registrant's own.
  • Technical and operational controls: Detailed requirements are proposed for asset identification and classification, access management, data protection and encryption, malicious code protection, patching, penetration testing, logging and monitoring, network security, and cryptography.
  • Incident and crisis management: Registrants must maintain IT and IT security incident management processes, notify the Authority of cyber risk reporting events, and maintain business continuity, disaster recovery and crisis management plans, including annual testing of disaster recovery capability.
  • Record retention: Risk assessments must be documented and retained for at least five years and made available to the Authority on request.

Because this is a consultation draft, the specific requirements described are proposals open for industry comment rather than binding rules; readers should watch for a final, adopted version of the Code before treating these as enforceable obligations.

Key obligations

  • Submit comments on the proposed Code to policy@bma.bm no later than 31 January 2020
  • If adopted as drafted, boards would need to approve a Cyber Risk Policy at least annually and maintain oversight of cyber risk
  • If adopted, registrants would need to appoint a CISO and implement an Operational Cyber Risk Management Programme covering risk identification, information security/data governance, and detection/protection/response/recovery controls
  • If adopted, registrants would need to develop a board-approved cyber risk audit plan and retain risk assessments for at least five years for provision to the Authority on request
  • If adopted, registrants would need to ensure outsourcing and third-party service agreements include compliance, regulatory access and security control terms, and confirm third-party compliance with the Code
  • If adopted, registrants would need to notify the Authority of cyber risk reporting events and test disaster recovery capability at least annually

Applies to

Bermuda registered insurers, insurance managers, insurance intermediaries (agents, brokers, insurance market place providers)

Deadlines

  • 31 January 2020: Deadline for interested persons to submit comments on the proposed Code to policy@bma.bm

Topics

Version history

2026-07-07

source file (current)