Bermuda
cybersecurity
68 Bermuda regulatory document(s) tagged cybersecurity.
Who is caught
The instruments indexed here impose cybersecurity and operational cyber risk obligations across most BMA-regulated sectors. They take the form either of rules made under a sectoral Act or of codes of practice or conduct issued under a sector Act's prudential provisions. Scope is defined by licence or registration status in each sector.
- Digital asset businesses: Undertakings licensed or registered under the Digital Asset Business Act 2018, including Class T, M and F licence holders, and DABs acting as custodians of client digital assets.
- Virtual currency businesses: Undertakings licensed under the Virtual Currency Business Act 2018.
- Digital asset issuers: Undertakings conducting a digital asset issuance in or from within Bermuda under the Digital Asset Issuance Act 2020.
- Insurance groups: Insurance groups for which the BMA acts as group supervisor, together with their designated insurers and parent companies.
- Insurers and intermediaries: Bermuda-registered insurers (including Special Purpose Insurers and insurance marketplace providers), insurance managers, and intermediaries such as brokers and agents.
- Other licensed sectors: Banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers, described in the Operational Cyber Risk Management Code of Conduct as Relevant Licensed Entities.
- Operational resilience scope: The Operational Resilience and Outsourcing Code applies across banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers, Class F digital asset businesses and a range of insurance entities.
Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Group Supervision) Rules 2011 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Digital Asset Business - Code of Practice (February 2024) · Code of Practice Virtual Currency Business Act 2018 · Virtual Currency (Cybersecurity) Rules 2018 · Virtual Currency Business (Prudential Standards) (Annual Return) Rules 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023)
Key duties
The recurring core of these instruments is a documented cyber risk programme overseen by the board, a Chief Information Security Officer, mandatory notification of cyber reporting events to the Authority, and periodic reporting or returns. Codes are applied proportionately to each entity's nature, scale and complexity.
Programme and governance
- CISO appointment: Regulated entities must appoint a Chief Information Security Officer (which may be outsourced, with board oversight retained) to deliver the operational cyber risk management programme; insurance groups must also appoint a CISO.
- Board-approved policy: Boards must have oversight of cyber risk and approve a cyber risk policy at least annually, receiving regular status updates.
- Risk management programme: Entities must run a documented programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.
Reporting and returns
- DAB cyber risk return: Under the Digital Asset Business (Cyber Risk) Rules 2023, Class F licence holders must file an annual written cyber risk return, and Class M and T holders on a date set by the Authority, each accompanied by a declaration signed by the CISO and a senior executive or director.
- VCB annual report: Under the Virtual Currency (Cybersecurity) Rules 2018, virtual currency licensees must file an annual written cybersecurity report prepared by their CISO and obtain an independent audit opinion on their cyber security program.
- Insurance annual returns: Insurance managers, brokers, agents, marketplace providers and Special Purpose Insurers must include a cyber risk management schedule in their annual statutory returns.
Incident notification
- Cyber reporting events: Entities under the operational cyber risk codes and insurance groups must notify the Authority of defined cyber reporting events.
- Client disclosure: Under the Digital Asset Business (Client Disclosure) Rules 2018, licensed undertakings must disclose to affected clients any cyber reporting event involving unauthorized access to or misuse of client information.
Records and testing
- Record retention: Risk assessments must be documented and retained for at least five years and produced to the Authority on request.
- Testing: Business continuity and disaster recovery plans must be tested at least annually; the Virtual Currency (Cybersecurity) Rules require penetration testing and vulnerability assessments at least quarterly.
- Audit: An annual IT audit plan approved by the audit committee is required under the DAB operational cyber and custody codes, with independent audit of controls required for virtual currency businesses.
Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Insurance (Group Supervision) Rules 2011 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Virtual Currency (Cybersecurity) Rules 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)
Exemptions and carve-outs
The instruments provide proportionality and several specific carve-outs rather than blanket exemptions.
- Proportionality: The cyber risk codes are applied proportionately to each entity's nature, scale and complexity, so control expectations scale with the business.
- SPI reliance on manager: A Special Purpose Insurer need not file its own Schedule of Cyber Risk Management where it relies on its insurance manager's cyber security systems and the manager files the schedule and confirms that reliance.
- Reduced AML content: Insurance brokers, agents and marketplace providers that are not AML/ATF regulated financial institutions need only complete the Corporate Governance section of the AML/ATF schedule rather than the full questionnaire.
- Digital asset issuance: Digital asset issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.
- Sandbox and test licensees: Entities under a regulatory sandbox or test licence are excluded from the Operational Resilience and Outsourcing Code.
- No qualifying business services: Under the operational resilience guidance, entities that determine they have no important business service meeting the harm or contagion criteria need not perform the full resilience review, but remain subject to the outsourcing and third-party oversight requirements.
Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Resilience and Outsourcing - Guidance Notes · Operational Resilience and Outsourcing Guidance Notes (September 2025, Tracked Changes) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised)
Enforcement and penalties
The instruments indexed here do not set out specific fines or monetary penalty provisions. Enforcement is expressed through the Authority's prudential supervision rather than prescribed sanctions.
- Sound and prudent assessment: Under the cyber risk and DAB codes of practice, failure to adhere to the code is a factor the Authority weighs when assessing whether an entity is conducting its business in a sound and prudent manner.
- Licensing threshold: The Operational Resilience and Outsourcing Code is issued under sectoral licensing provisions, so non-compliance can be treated as a failure to meet minimum licensing criteria.
Sources: Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business - Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023)