Bermuda

cybersecurity

67 Bermuda regulatory document(s) tagged cybersecurity.

Practice-note overview · reflects instruments as at 2026-08-18. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

Cybersecurity obligations in Bermuda are not contained in a single instrument. They are spread across sector-specific operational cyber risk codes, digital asset rules and codes of practice, insurance annual-return schedules, and the data-protection regime administered by the Privacy Commissioner. What brings a person within scope is holding a relevant BMA licence or registration, or, for the privacy rules, holding personal information.

BMA-regulated sectors

  • Insurance sector: The Insurance Sector Operational Cyber Risk Management Code of Conduct applies to all Bermuda-registered insurers, insurance managers and intermediaries (agents, brokers and insurance marketplace providers), and limited purpose insurers.
  • Other licensed entities: The Operational Cyber Risk Management Code of Conduct applies to Relevant Licensed Entities: banks and deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers.
  • Digital asset businesses: The Digital Asset Business operational cyber, custody and general codes of practice, and the Digital Asset Business (Cyber Risk) Rules 2023, apply to DAB licensees and registrants, including Class F, Class M and Class T licence holders.
  • Insurance groups: The Insurance (Group Supervision) Rules 2011 apply to insurance groups, designated insurers and parent companies for which the BMA acts as group supervisor, with cyber risk requirements added effective 1 January 2023.
  • Digital asset issuers: The Digital Asset Issuance Rules 2020 apply to any undertaking conducting a digital asset issuance in or from within Bermuda, imposing IT and cybersecurity infrastructure standards.
  • Annual-return filers: Insurance managers, brokers, agents, insurance marketplace providers and special purpose insurers are within scope of cyber risk management schedules that form part of their annual statutory returns.

Operational resilience and data protection

  • Operational resilience: The Operational Resilience and Outsourcing Code applies to a broad range of BMA-regulated entities, including banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers, Class F digital asset businesses, and specified insurers and intermediaries.
  • Personal information holders: PIPA's security safeguards requirement (Section 13) applies to organisations, as defined under PIPA, that handle personal information.

Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Digital Asset Business - Code of Practice (February 2024) · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023) · Guide to PIPA: Security safeguards


Key duties

The core cyber duties are recurring and largely annual: maintaining a documented cyber risk programme with board-approved policy, appointing a CISO, testing continuity plans, retaining records, and notifying the BMA of cyber reporting events. Digital asset businesses additionally file a periodic cyber risk return.

Operational cyber risk programmes

  • Board-approved policy: Boards must oversee cyber risk and approve a cyber risk policy document at least annually, receiving regular status updates. This applies across the insurance sector code, the Relevant Licensed Entities code and the DAB operational cyber code.
  • CISO appointment: A Chief Information Security Officer (which may be outsourced, though board oversight cannot be) must be appointed to deliver the operational cyber risk management programme.
  • Risk management programme: Entities must run a documented programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.
  • Record retention: Risk assessments must be documented and retained for at least five years and made available to the Authority on request; the DAB custody code sets the same five-year retention for audit records and evidence.
  • IT audit and continuity: DAB codes require an annual IT audit plan approved by the audit committee; all cyber codes require business continuity and disaster recovery plans to be maintained and tested at least annually.

Cyber risk returns and schedules

  • DAB cyber risk return: Under the Digital Asset Business (Cyber Risk) Rules 2023, Class F licence holders must file a written cyber risk return annually, and Class M and Class T holders on a date determined by the Authority, in the form directed by the Authority and accompanied by a declaration signed by the CISO and a senior executive or director.
  • Insurance return schedules: Insurance managers, brokers, agents and marketplace providers must complete a Cyber Risk Management schedule within their annual return (generally due 30 June), and special purpose insurers must file a Schedule of Cyber Risk Management with their annual statutory financial statements.
  • Insurance group cyber programme: Insurance groups must establish and maintain a cyber risk programme, appoint a Chief Information Security Officer, ensure board oversight, and report cyber reporting events to the Authority.

Incident notification

  • Cyber reporting events: Registrants under the insurance, RLE and DAB operational cyber codes must notify the Authority of cyber reporting events; insurance groups have the same duty under the Group Supervision Rules.
  • Client notification: Under the Digital Asset Business (Client Disclosure) Rules 2018, a licensed undertaking must disclose to affected clients any cyber reporting event involving a breach leading to unauthorized access to or misuse of client information.
  • PIPA breach notification: From 1 January 2025, organisations must notify the Privacy Commissioner, without undue delay, of a security breach involving an action such as unauthorised access that is likely to adversely affect an individual, and notify affected individuals accordingly.

Operational resilience and data safeguards

  • Operational resilience lifecycle: Under the Operational Resilience and Outsourcing Code, entities must identify important business services, map supporting resources, set impact tolerances, prepare communication plans, test against severe but plausible disruption scenarios, and prepare an annual board-approved self-assessment retained for at least five years, notifying the BMA of significant developments affecting delivery of those services.
  • PIPA security safeguards: Organisations must protect personal information with safeguards against loss, unauthorised access, destruction, use, modification or disclosure, proportional to the likelihood and severity of harm, sensitivity and context, subject to periodic review; encryption is recommended but not legally mandated.
  • Compliance deadlines: Full compliance dates vary by instrument: 31 December 2021 for the insurance cyber code, 15 February 2023 for Relevant Licensed Entities, 30 June 2024 for the DAB operational cyber code, and generally 31 March 2028 (1 January 2027 for banks and deposit companies) for the Operational Resilience and Outsourcing Code.

Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26) · Guide to PIPA: Security safeguards · Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20) · PrivCom Advises the Public on Cyberattacks (2024-03-28) · Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)


Exemptions and carve-outs

The instruments provide proportionality rather than wholesale exemptions, together with a small number of specific carve-outs.

  • Proportionality: The insurance, RLE and DAB cyber codes are applied proportionately to each entity's nature, scale and complexity, so the depth of controls expected varies rather than the applicability of the code.
  • SPI cyber schedule waiver: A special purpose insurer need not file its own Schedule of Cyber Risk Management where it relies on its insurance manager's cyber security systems and the manager files the schedule on its behalf and confirms that reliance.
  • Digital asset issuance exemptions: Issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised or vetted by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.
  • Operational resilience exclusions: Entities under a regulatory sandbox or test licence are excluded from the Operational Resilience and Outsourcing Code; entities that determine they have no qualifying important business service need not perform the full operational resilience review but remain subject to the outsourcing and third-party oversight requirements.
  • Outsourced CISO and custody: The CISO role may be outsourced (for example to a group CISO) under the cyber codes, though board oversight responsibility cannot be outsourced; where DAB custody is outsourced to a qualified custodian, the DAB remains responsible for ensuring comparable standards.
  • PIPA encryption: Encryption is highlighted as best practice under the PIPA security safeguards guidance but is not a legally mandated technical measure.

Sources: Digital Asset Issuance Rules 2020 · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Stakeholder Letter - Operational Cyber Risk Management Code of Conduct (2022-03-14) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Guide to PIPA: Security safeguards


Enforcement and penalties

The instruments indexed here do not set out specific monetary penalties or fine amounts for cybersecurity non-compliance. Enforcement is expressed primarily through the BMA's supervisory framework and, for data protection, the Privacy Commissioner's investigative role.

  • Sound and prudent test: Under the DAB codes of practice, the operational cyber codes and the insurance sector cyber code, failure to comply is a factor the BMA weighs when assessing whether a registrant is conducting business in a sound and prudent manner.
  • Licensing threshold: The Operational Cyber Risk Management Code implements the statutory requirement to maintain adequate systems, and the Operational Resilience and Outsourcing Code is issued under sectoral licensing provisions, so non-compliance can be treated as a failure to meet minimum licensing criteria.
  • PrivCom powers: Under PIPA, once in effect, the Privacy Commissioner can instruct organisations on further steps after a breach and will investigate whether the organisation's risk analysis and safeguards were reasonable.

Beyond these supervisory consequences, the documents provided do not specify enforcement sanctions such as fines, licence revocation procedures or penalty calculations for cyber breaches.

Sources: Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business - Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023) · Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20) · PrivCom Advises the Public on Cyberattacks (2024-03-28)

Documents

CitationRegulatorType
Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)PRIVCOMAdvisory
BMA Public Warning – Fraudulent Demand for Payment (2026-07-22)BMANotice
Breach of Security Notification FormPRIVCOMForm
CP - Amendment to the Group Supervision Rules (May 2021)BMAConsultation Paper
CP - Digital Asset Issuance Rules 2020BMAConsultation Paper
Code of Practice Virtual Currency Business Act 2018BMACode
Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20)PRIVCOMNotice
Consultation Paper - Cyber Risk Management Code of ConductBMAConsultation Paper
Consultation Paper - DAB Operational Cyber Risk CodeBMAConsultation Paper
Consultation Paper - Digital Asset Business Amendment Act 2021BMAConsultation Paper
Consultation Paper - Guidance Note - The Responsible Use of Artificial Intelligence in Bermuda's Financial Services Sector (2026-08-14)BMAConsultation Paper
Consultation Paper - Operational Resilience and Outsourcing Package (2025-01-14)BMAConsultation Paper
Consultation Paper - Proposed Adoption of the Revised Operational Risk Principles for BanksBMAConsultation Paper
Consultation Paper - Regulation of Digital Identity Service Provider Business (2024-11-22)BMAConsultation Paper
Digital Asset Business (Client Disclosure) Rules 2018BMARule
Digital Asset Business (Cyber Risk) Rules 2022BMARule
Digital Asset Business (Cyber Risk) Rules 2023BMARule
Digital Asset Business - Code of Practice (February 2024)BMACode
Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024)BMACode
Digital Asset Business Act 2018 - Code of Practice (April 2023)BMACode
Digital Asset Business Custody Code of Practice (February 2024)BMACode
Digital Asset Business FAQ's (2019-06-20)BMANotice
Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)BMACode
Digital Asset Custody Code of Practice 2018BMAConsultation Paper
Digital Asset Issuance Rules 2020BMARule
Discussion Paper - Asset Tokenisation (2025-11-05)BMAConsultation Paper
Discussion Paper - The Responsible Use of Artificial Intelligence in Bermuda's Financial Services Sector (2025-07-30)BMAConsultation Paper
Draft Schedule I – Insurance Marketplace Provider Return (2019)BMAForm
Guidance Note - Digital Asset Business - Guidance for prospective applicants for licensing (September 2025)BMAStatement of Guidance
Guide to PIPA: Security safeguardsPRIVCOMStatement of Guidance
Insurance (Group Supervision) Rules 2011 (BR 76 / 2011)BMARule
Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - SchedulesBMARule
Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018BMARule
Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019)BMARule
Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - ScheduleBMARule
Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - SchedulesBMARule
Insurance Sector Operational Cyber Risk Management Code of Conduct (Consultation, December 2019)BMAConsultation Paper
Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020)BMACode
NOTICE-Draft Rules for Annual Filing Requirements of Insurance Marketplace Providers and Class IIGB Insurers (2019-10-31)BMAConsultation Paper
Notice - 2020 Year-End BSCR Model for Class 3A and 3B Insurers - Schedule V(e) Stress/Scenario Tests (2021-02-23)BMANotice
Notice - 2021 Year-End BSCR Model Schedule V(e) Cyber Risk Stress Test Scenarios (2022-03-08)BMANotice
Notice - 2022 Annual Return Templates for Insurance Intermediaries (2022-04-20)BMANotice
Notice - BMA Public Warning - Fraudulent Email Domain: BMA-BM.com used to Misdirect Wire Payment (2025-08-14)BMANotice
Notice - Consultation - Digital Asset Business (Custody of Client Assets) Rules 2024 (2024-02-29)BMAConsultation Paper
Notice - Consultation Paper - The Responsible Use of Artificial Intelligence in Financial Services (2026-08-14)BMANotice
Notice - Cyber Code (2021-10-29)BMANotice
Notice - Cyber Risk Management for Insurance Managers, Brokers and Agents (2021-12-17)BMANotice
Notice - Digital Asset Business - Operational Cyber Risk Management Code of Practice (2022-04-05)BMANotice
Notice - Digital Asset Issuance Statement of Principles and Digital Asset Issuance Rules 2020 (2020-06-23)BMANotice
Notice - Insurance Managers Annual Return Template (2018-04-11)BMANotice
Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26)BMANotice
Operational Cyber Risk Management Code of Conduct (September 2022 Revised)BMACode
Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15)BMACode
Operational Resilience and Outsourcing - Guidance NotesBMAStatement of Guidance
Operational Resilience and Outsourcing Code (September 2025)BMACode
Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes)BMACode
Operational Resilience and Outsourcing Guidance Notes (September 2025, Tracked Changes)BMAStatement of Guidance
PrivCom Advises the Public on Cyberattacks (2024-03-28)PRIVCOMAdvisory
Public Warning: Phishing Attempts from Individuals Misrepresenting the BMA (2024-10-01)BMANotice
Public Warning: Phishing Attempts on Bermuda Financial Services Licensees (2024-05-09)BMANotice
Response to Industry Comments - Insurance Sector Operational Cyber Risk Management Code of Conduct (2020-10)BMAConsultation Paper
Stakeholder Letter - Consultation on the Proposed Framework for Digital Identity Service Providers (DISP) (2025-04-29)BMAConsultation Paper
Stakeholder Letter - Operational Cyber Risk Management Code of Conduct (2022-03-14)BMACircular
Update to the Schedule of Cyber Risk Management (2021-12-17)BMANotice
Virtual Currency (Cybersecurity) Rules 2018BMARule
Virtual Currency Business (Prudential Standards) (Annual Return) Rules 2018BMARule
WEBSITE FALSELY LINKED TO BMA - WWW.BMAFINANCIER.COM (2020-09-08)BMANotice