Consultation Paper
Response to Industry Comments - Insurance Sector Operational Cyber Risk Management Code of Conduct (2020-10)
IssuedView on BMA's website Source document
Summary
This is the Bermuda Monetary Authority's response to industry comments on its Insurance Sector Operational Cyber Risk Management Code of Conduct, following a consultation that began in late 2019. It summarises how the Authority revised specific sections of the Code in response to stakeholder feedback and confirms the Code's implementation timeline.
- Staff training (Section 4): Annual staff cyber risk awareness training must still be completed, but the requirement to test staff was removed.
- Outsourcing oversight (Section 5.10): Clarified that the Authority expects to review outsourcing controls with the registrant directly, not normally with the outsource service provider.
- End user developed systems (Section 5.12): No prescribed list of examples; each registrant must assess its own risks from end user developed systems.
- Security review of new projects (Section 5.14): Required for projects involving critical assets; minor changes should be reviewed through standard change management instead.
- Encryption (Section 6.13): Where encryption of non-public information is not feasible, mitigating controls may be used by exception.
- Cyber incident reporting (Section 6.5): Clarified which cyber reporting events must be reported and requires incident investigation logs (not system event logs) to be retained for a minimum of five years.
- Business continuity and disaster recovery (Section 7.1): Both BCP and DR tests must be carried out at least annually.
The Code comes into force on 1 January 2021. Its enforcement date, originally set for 30 June 2021, has been pushed back to 31 December 2021 due to pandemic-related disruption.
Key obligations
- Registrants must complete annual staff cyber risk awareness training.
- Registrants must carry out both Business Continuity Plan (BCP) and Disaster Recovery (DR) tests at least annually.
- Registrants must retain incident investigation logs for cyber reporting events for a minimum of five years.
- Registrants must apply mitigating controls where encryption of non-public information is not feasible.
- Registrants must conduct security reviews for new projects and IT systems involving critical assets.
- Registrants must assess their own risks arising from End User Developed Systems and determine an appropriate risk response.
- Registrants must review outsourcing and third-party service provider cyber risk controls, expected to be discussed directly with the Authority rather than the outsource provider.
Applies to
insurance registrants, insurers regulated by the BMA
Deadlines
- 1 January 2021: The Insurance Sector Operational Cyber Risk Management Code of Conduct comes into force.
- 31 December 2021: Revised enforcement date for the Code (pushed back from the original 30 June 2021 due to pandemic disruption).
Topics
Version history
2026-07-07