Consultation Paper

Response to Industry Comments - Insurance Sector Operational Cyber Risk Management Code of Conduct (2020-10)

Bermuda Monetary Authority (BMA) · Bermuda

Issued

Current version last checked: 2026-07-07

Summary

This is the Bermuda Monetary Authority's response to industry comments on its Insurance Sector Operational Cyber Risk Management Code of Conduct, following a consultation that began in late 2019. It summarises how the Authority revised specific sections of the Code in response to stakeholder feedback and confirms the Code's implementation timeline.

  • Staff training (Section 4): Annual staff cyber risk awareness training must still be completed, but the requirement to test staff was removed.
  • Outsourcing oversight (Section 5.10): Clarified that the Authority expects to review outsourcing controls with the registrant directly, not normally with the outsource service provider.
  • End user developed systems (Section 5.12): No prescribed list of examples; each registrant must assess its own risks from end user developed systems.
  • Security review of new projects (Section 5.14): Required for projects involving critical assets; minor changes should be reviewed through standard change management instead.
  • Encryption (Section 6.13): Where encryption of non-public information is not feasible, mitigating controls may be used by exception.
  • Cyber incident reporting (Section 6.5): Clarified which cyber reporting events must be reported and requires incident investigation logs (not system event logs) to be retained for a minimum of five years.
  • Business continuity and disaster recovery (Section 7.1): Both BCP and DR tests must be carried out at least annually.

The Code comes into force on 1 January 2021. Its enforcement date, originally set for 30 June 2021, has been pushed back to 31 December 2021 due to pandemic-related disruption.

Key obligations

  • Registrants must complete annual staff cyber risk awareness training.
  • Registrants must carry out both Business Continuity Plan (BCP) and Disaster Recovery (DR) tests at least annually.
  • Registrants must retain incident investigation logs for cyber reporting events for a minimum of five years.
  • Registrants must apply mitigating controls where encryption of non-public information is not feasible.
  • Registrants must conduct security reviews for new projects and IT systems involving critical assets.
  • Registrants must assess their own risks arising from End User Developed Systems and determine an appropriate risk response.
  • Registrants must review outsourcing and third-party service provider cyber risk controls, expected to be discussed directly with the Authority rather than the outsource provider.

Applies to

insurance registrants, insurers regulated by the BMA

Deadlines

  • 1 January 2021: The Insurance Sector Operational Cyber Risk Management Code of Conduct comes into force.
  • 31 December 2021: Revised enforcement date for the Code (pushed back from the original 30 June 2021 due to pandemic disruption).

Topics

Version history

2026-07-07

source file (current)