Consultation Paper

Notice - DAB Operational Cyber Risk Code (2022-05-11)

Bermuda Monetary Authority (BMA) · Bermuda

Draft

Published: 2022-05-11

Current version last checked: 2026-07-07

Summary

This is a BMA notice extending the comment period on a package of draft Digital Asset Business (DAB) cyber risk rules. It attaches a new draft Operational Cyber Risk Management Code of Practice together with revised versions of the DAB Custody Code of Practice, the DAB Code of Practice, and the Digital Asset Business (Cybersecurity/Cyber Risk) Rules. The drafts aim to align DAB cyber requirements with those already applied to Bermuda's insurance, banking, trust, corporate services and investment sectors, while imposing stricter DAB-specific controls given heightened cyber risk in that sector.

  • Scope: The draft Code applies to all entities registered or licensed as Digital Asset Business under the Digital Asset Business Act 2018.
  • Governance: Requires board and senior management oversight of cyber risk, a board-approved cyber risk policy (at least annually), and a designated Chief Information Security Officer (CISO), whether in-house or outsourced.
  • Risk management programme: DABs must run a documented risk assessment process, asset identification and classification, an annual IT audit plan approved by the audit committee, and retain risk assessments for at least five years.
  • Technical controls: Sets out detect/protect controls (multi-factor authentication, logging, penetration testing, patch management, network security) and DAB-specific requirements for smart contracts and DLT/blockchain security.
  • Outsourcing and cooperation: Requires oversight and accountability for outsourced cyber functions, service agreements permitting BMA access to data, and open cooperation with regulators.
  • Cyber Risk Rules: The draft Cyber Risk Rules would require Class F licence holders to file an annual cyber risk return and Class M and T licence holders to file on the date specified in their licence, each declaration co-signed by the CISO and a senior executive or director.
  • Consultation deadline: Comments on all the annexed draft documents must be submitted via the Authority's survey link by 6 June 2022, extended from the original 6 May 2022 deadline.

Because this is a consultation notice with draft instruments (the Rules are shown with blank operative date and unsigned), none of the substantive cyber risk requirements are yet in force; they represent proposals on which the Authority is seeking industry input before finalisation.

Key obligations

  • Interested parties, including DAB registrants, must submit comments on the draft Code, Rules and revised Codes of Practice by 6 June 2022 via the Authority's survey link
  • If adopted, DABs would be required to maintain an appropriately senior CISO and have the board approve a cyber risk policy at least annually
  • If adopted, DABs would be required to maintain a documented risk assessment process and retain risk assessments for at least five years, available to the Authority on request
  • If adopted, DABs would be required to develop and have an audit committee approve an annual IT audit plan
  • If adopted, Class F licence holders would be required to file a written cyber risk return annually, and Class M and Class T licence holders on the date specified in their licence, each accompanied by a declaration signed by the CISO and a senior executive or director

Applies to

Digital Asset Business (DAB) registrants, Class F licence holders, Class M licence holders, Class T licence holders

Deadlines

  • 6 June 2022: Extended deadline for submitting comments on the draft Operational Cyber Risk Management Code of Practice and related Consultation Documents (extended from 6 May 2022)
  • annually (Class F) / date specified in licence (Class M and T): Proposed requirement under the draft Cyber Risk Rules for filing a written cyber risk return with the Authority, if the Rules are adopted

Topics

Version history

2026-07-07

source file (current)