Bermuda
cybersecurity
67 Bermuda regulatory document(s) tagged cybersecurity.
Who is caught
Cybersecurity obligations in Bermuda are not contained in a single instrument. They are spread across sector-specific operational cyber risk codes, digital asset rules and codes of practice, insurance annual-return schedules, and the data-protection regime administered by the Privacy Commissioner. What brings a person within scope is holding a relevant BMA licence or registration, or, for the privacy rules, holding personal information.
BMA-regulated sectors
- Insurance sector: The Insurance Sector Operational Cyber Risk Management Code of Conduct applies to all Bermuda-registered insurers, insurance managers and intermediaries (agents, brokers and insurance marketplace providers), and limited purpose insurers.
- Other licensed entities: The Operational Cyber Risk Management Code of Conduct applies to Relevant Licensed Entities: banks and deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers.
- Digital asset businesses: The Digital Asset Business operational cyber, custody and general codes of practice, and the Digital Asset Business (Cyber Risk) Rules 2023, apply to DAB licensees and registrants, including Class F, Class M and Class T licence holders.
- Insurance groups: The Insurance (Group Supervision) Rules 2011 apply to insurance groups, designated insurers and parent companies for which the BMA acts as group supervisor, with cyber risk requirements added effective 1 January 2023.
- Digital asset issuers: The Digital Asset Issuance Rules 2020 apply to any undertaking conducting a digital asset issuance in or from within Bermuda, imposing IT and cybersecurity infrastructure standards.
- Annual-return filers: Insurance managers, brokers, agents, insurance marketplace providers and special purpose insurers are within scope of cyber risk management schedules that form part of their annual statutory returns.
Operational resilience and data protection
- Operational resilience: The Operational Resilience and Outsourcing Code applies to a broad range of BMA-regulated entities, including banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers, Class F digital asset businesses, and specified insurers and intermediaries.
- Personal information holders: PIPA's security safeguards requirement (Section 13) applies to organisations, as defined under PIPA, that handle personal information.
Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Digital Asset Business - Code of Practice (February 2024) · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023) · Guide to PIPA: Security safeguards
Key duties
The core cyber duties are recurring and largely annual: maintaining a documented cyber risk programme with board-approved policy, appointing a CISO, testing continuity plans, retaining records, and notifying the BMA of cyber reporting events. Digital asset businesses additionally file a periodic cyber risk return.
Operational cyber risk programmes
- Board-approved policy: Boards must oversee cyber risk and approve a cyber risk policy document at least annually, receiving regular status updates. This applies across the insurance sector code, the Relevant Licensed Entities code and the DAB operational cyber code.
- CISO appointment: A Chief Information Security Officer (which may be outsourced, though board oversight cannot be) must be appointed to deliver the operational cyber risk management programme.
- Risk management programme: Entities must run a documented programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.
- Record retention: Risk assessments must be documented and retained for at least five years and made available to the Authority on request; the DAB custody code sets the same five-year retention for audit records and evidence.
- IT audit and continuity: DAB codes require an annual IT audit plan approved by the audit committee; all cyber codes require business continuity and disaster recovery plans to be maintained and tested at least annually.
Cyber risk returns and schedules
- DAB cyber risk return: Under the Digital Asset Business (Cyber Risk) Rules 2023, Class F licence holders must file a written cyber risk return annually, and Class M and Class T holders on a date determined by the Authority, in the form directed by the Authority and accompanied by a declaration signed by the CISO and a senior executive or director.
- Insurance return schedules: Insurance managers, brokers, agents and marketplace providers must complete a Cyber Risk Management schedule within their annual return (generally due 30 June), and special purpose insurers must file a Schedule of Cyber Risk Management with their annual statutory financial statements.
- Insurance group cyber programme: Insurance groups must establish and maintain a cyber risk programme, appoint a Chief Information Security Officer, ensure board oversight, and report cyber reporting events to the Authority.
Incident notification
- Cyber reporting events: Registrants under the insurance, RLE and DAB operational cyber codes must notify the Authority of cyber reporting events; insurance groups have the same duty under the Group Supervision Rules.
- Client notification: Under the Digital Asset Business (Client Disclosure) Rules 2018, a licensed undertaking must disclose to affected clients any cyber reporting event involving a breach leading to unauthorized access to or misuse of client information.
- PIPA breach notification: From 1 January 2025, organisations must notify the Privacy Commissioner, without undue delay, of a security breach involving an action such as unauthorised access that is likely to adversely affect an individual, and notify affected individuals accordingly.
Operational resilience and data safeguards
- Operational resilience lifecycle: Under the Operational Resilience and Outsourcing Code, entities must identify important business services, map supporting resources, set impact tolerances, prepare communication plans, test against severe but plausible disruption scenarios, and prepare an annual board-approved self-assessment retained for at least five years, notifying the BMA of significant developments affecting delivery of those services.
- PIPA security safeguards: Organisations must protect personal information with safeguards against loss, unauthorised access, destruction, use, modification or disclosure, proportional to the likelihood and severity of harm, sensitivity and context, subject to periodic review; encryption is recommended but not legally mandated.
- Compliance deadlines: Full compliance dates vary by instrument: 31 December 2021 for the insurance cyber code, 15 February 2023 for Relevant Licensed Entities, 30 June 2024 for the DAB operational cyber code, and generally 31 March 2028 (1 January 2027 for banks and deposit companies) for the Operational Resilience and Outsourcing Code.
Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26) · Guide to PIPA: Security safeguards · Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20) · PrivCom Advises the Public on Cyberattacks (2024-03-28) · Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)
Exemptions and carve-outs
The instruments provide proportionality rather than wholesale exemptions, together with a small number of specific carve-outs.
- Proportionality: The insurance, RLE and DAB cyber codes are applied proportionately to each entity's nature, scale and complexity, so the depth of controls expected varies rather than the applicability of the code.
- SPI cyber schedule waiver: A special purpose insurer need not file its own Schedule of Cyber Risk Management where it relies on its insurance manager's cyber security systems and the manager files the schedule on its behalf and confirms that reliance.
- Digital asset issuance exemptions: Issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised or vetted by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.
- Operational resilience exclusions: Entities under a regulatory sandbox or test licence are excluded from the Operational Resilience and Outsourcing Code; entities that determine they have no qualifying important business service need not perform the full operational resilience review but remain subject to the outsourcing and third-party oversight requirements.
- Outsourced CISO and custody: The CISO role may be outsourced (for example to a group CISO) under the cyber codes, though board oversight responsibility cannot be outsourced; where DAB custody is outsourced to a qualified custodian, the DAB remains responsible for ensuring comparable standards.
- PIPA encryption: Encryption is highlighted as best practice under the PIPA security safeguards guidance but is not a legally mandated technical measure.
Sources: Digital Asset Issuance Rules 2020 · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Stakeholder Letter - Operational Cyber Risk Management Code of Conduct (2022-03-14) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Guide to PIPA: Security safeguards
Enforcement and penalties
The instruments indexed here do not set out specific monetary penalties or fine amounts for cybersecurity non-compliance. Enforcement is expressed primarily through the BMA's supervisory framework and, for data protection, the Privacy Commissioner's investigative role.
- Sound and prudent test: Under the DAB codes of practice, the operational cyber codes and the insurance sector cyber code, failure to comply is a factor the BMA weighs when assessing whether a registrant is conducting business in a sound and prudent manner.
- Licensing threshold: The Operational Cyber Risk Management Code implements the statutory requirement to maintain adequate systems, and the Operational Resilience and Outsourcing Code is issued under sectoral licensing provisions, so non-compliance can be treated as a failure to meet minimum licensing criteria.
- PrivCom powers: Under PIPA, once in effect, the Privacy Commissioner can instruct organisations on further steps after a breach and will investigate whether the organisation's risk analysis and safeguards were reasonable.
Beyond these supervisory consequences, the documents provided do not specify enforcement sanctions such as fines, licence revocation procedures or penalty calculations for cyber breaches.
Sources: Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business - Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023) · Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20) · PrivCom Advises the Public on Cyberattacks (2024-03-28)