Notice
Notice - Cyber Code (2021-10-29)
Issued 2021-10-29View on BMA's website Source document
Summary
This is a BMA notice announcing a consultation paper on a proposed Operational Cyber Risk Management Code of Conduct. It sets minimum requirements and expectations for managing and reporting cybersecurity risks and incidents, mirroring an approach already taken for the insurance sector, and invites stakeholder feedback before finalisation.
- Scope: Applies to licensed banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers.
- Purpose: Formalises the BMA's minimum requirements and expectations regarding cybersecurity risk management and incident reporting as part of its operational resilience strategy.
- Action requested: Stakeholders are invited to review the draft code and consultation paper and submit written comments to policy@bma.bm.
No obligations are yet legally binding; this is a consultation stage document, and any actual compliance requirements will follow once the code is finalised.
Key obligations
- Stakeholders wishing to comment must submit feedback to policy@bma.bm by close of business on 10 December 2021
Applies to
banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses, fund administration providers
Deadlines
- 10 December 2021: Deadline for submitting comments on the consultation paper and draft Cyber Code to policy@bma.bm
Topics
Version history
2026-07-07