Bermuda

cybersecurity

68 Bermuda regulatory document(s) tagged cybersecurity.

Practice-note overview · reflects instruments as at 2026-07-10. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

The instruments indexed here impose cybersecurity and operational cyber risk obligations across most BMA-regulated sectors. They take the form either of rules made under a sectoral Act or of codes of practice or conduct issued under a sector Act's prudential provisions. Scope is defined by licence or registration status in each sector.

  • Digital asset businesses: Undertakings licensed or registered under the Digital Asset Business Act 2018, including Class T, M and F licence holders, and DABs acting as custodians of client digital assets.
  • Virtual currency businesses: Undertakings licensed under the Virtual Currency Business Act 2018.
  • Digital asset issuers: Undertakings conducting a digital asset issuance in or from within Bermuda under the Digital Asset Issuance Act 2020.
  • Insurance groups: Insurance groups for which the BMA acts as group supervisor, together with their designated insurers and parent companies.
  • Insurers and intermediaries: Bermuda-registered insurers (including Special Purpose Insurers and insurance marketplace providers), insurance managers, and intermediaries such as brokers and agents.
  • Other licensed sectors: Banks, deposit companies, corporate service providers, trust companies, money service businesses, investment businesses and fund administration providers, described in the Operational Cyber Risk Management Code of Conduct as Relevant Licensed Entities.
  • Operational resilience scope: The Operational Resilience and Outsourcing Code applies across banks and deposit companies, corporate service providers, trust businesses, money service businesses, investment businesses, fund administration providers, Class F digital asset businesses and a range of insurance entities.

Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Group Supervision) Rules 2011 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business Custody Code of Practice (February 2024) · Digital Asset Business - Code of Practice (February 2024) · Code of Practice Virtual Currency Business Act 2018 · Virtual Currency (Cybersecurity) Rules 2018 · Virtual Currency Business (Prudential Standards) (Annual Return) Rules 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023)


Key duties

The recurring core of these instruments is a documented cyber risk programme overseen by the board, a Chief Information Security Officer, mandatory notification of cyber reporting events to the Authority, and periodic reporting or returns. Codes are applied proportionately to each entity's nature, scale and complexity.

Programme and governance

  • CISO appointment: Regulated entities must appoint a Chief Information Security Officer (which may be outsourced, with board oversight retained) to deliver the operational cyber risk management programme; insurance groups must also appoint a CISO.
  • Board-approved policy: Boards must have oversight of cyber risk and approve a cyber risk policy at least annually, receiving regular status updates.
  • Risk management programme: Entities must run a documented programme covering risk assessment, data governance and classification, and detection, protection, response and recovery controls, following a Three Lines of Defense model.

Reporting and returns

  • DAB cyber risk return: Under the Digital Asset Business (Cyber Risk) Rules 2023, Class F licence holders must file an annual written cyber risk return, and Class M and T holders on a date set by the Authority, each accompanied by a declaration signed by the CISO and a senior executive or director.
  • VCB annual report: Under the Virtual Currency (Cybersecurity) Rules 2018, virtual currency licensees must file an annual written cybersecurity report prepared by their CISO and obtain an independent audit opinion on their cyber security program.
  • Insurance annual returns: Insurance managers, brokers, agents, marketplace providers and Special Purpose Insurers must include a cyber risk management schedule in their annual statutory returns.

Incident notification

  • Cyber reporting events: Entities under the operational cyber risk codes and insurance groups must notify the Authority of defined cyber reporting events.
  • Client disclosure: Under the Digital Asset Business (Client Disclosure) Rules 2018, licensed undertakings must disclose to affected clients any cyber reporting event involving unauthorized access to or misuse of client information.

Records and testing

  • Record retention: Risk assessments must be documented and retained for at least five years and produced to the Authority on request.
  • Testing: Business continuity and disaster recovery plans must be tested at least annually; the Virtual Currency (Cybersecurity) Rules require penetration testing and vulnerability assessments at least quarterly.
  • Audit: An annual IT audit plan approved by the audit committee is required under the DAB operational cyber and custody codes, with independent audit of controls required for virtual currency businesses.

Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Business (Cyber Risk) Rules 2023 · Digital Asset Business (Client Disclosure) Rules 2018 · Insurance (Group Supervision) Rules 2011 · Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - Schedule · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - Schedules · Insurance (Group Supervision) Rules 2011 (BR 76 / 2011) · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Virtual Currency (Cybersecurity) Rules 2018 · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)


Exemptions and carve-outs

The instruments provide proportionality and several specific carve-outs rather than blanket exemptions.

  • Proportionality: The cyber risk codes are applied proportionately to each entity's nature, scale and complexity, so control expectations scale with the business.
  • SPI reliance on manager: A Special Purpose Insurer need not file its own Schedule of Cyber Risk Management where it relies on its insurance manager's cyber security systems and the manager files the schedule and confirms that reliance.
  • Reduced AML content: Insurance brokers, agents and marketplace providers that are not AML/ATF regulated financial institutions need only complete the Corporate Governance section of the AML/ATF schedule rather than the full questionnaire.
  • Digital asset issuance: Digital asset issuers relying on an accredited digital asset business, qualifying as a local issuer, or whose issuance is authorised by another competent authority benefit from reduced rule sets, but must file an exemption form with the Authority before proceeding.
  • Sandbox and test licensees: Entities under a regulatory sandbox or test licence are excluded from the Operational Resilience and Outsourcing Code.
  • No qualifying business services: Under the operational resilience guidance, entities that determine they have no important business service meeting the harm or contagion criteria need not perform the full resilience review, but remain subject to the outsourcing and third-party oversight requirements.

Sources: Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018 · Digital Asset Issuance Rules 2020 · Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - Schedules · Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Resilience and Outsourcing - Guidance Notes · Operational Resilience and Outsourcing Guidance Notes (September 2025, Tracked Changes) · Operational Resilience and Outsourcing Code (September 2025) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised)


Enforcement and penalties

The instruments indexed here do not set out specific fines or monetary penalty provisions. Enforcement is expressed through the Authority's prudential supervision rather than prescribed sanctions.

  • Sound and prudent assessment: Under the cyber risk and DAB codes of practice, failure to adhere to the code is a factor the Authority weighs when assessing whether an entity is conducting its business in a sound and prudent manner.
  • Licensing threshold: The Operational Resilience and Outsourcing Code is issued under sectoral licensing provisions, so non-compliance can be treated as a failure to meet minimum licensing criteria.

Sources: Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020) · Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes) · Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024) · Digital Asset Business - Code of Practice (February 2024) · Operational Cyber Risk Management Code of Conduct (September 2022 Revised) · Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022) · Digital Asset Business Act 2018 - Code of Practice (April 2023)

Documents

CitationRegulatorType
Advice to the Public in Response to the Cyberattack on Government Services (2023-09-29)PRIVCOMAdvisory
BMA Public Warning – Fraudulent Demand for Payment (2026-07-22)BMANotice
BMA Public Warning – Fraudulent Email Domain: BMA-BM.com (2025-08-14)BMANotice
Breach of Security Notification FormPRIVCOMForm
CP - Amendment to the Group Supervision Rules (May 2021)BMAConsultation Paper
CP - Digital Asset Issuance Rules 2020BMAConsultation Paper
Code of Practice Virtual Currency Business Act 2018BMACode
Comments from the Privacy Commissioner on PIPA's First Breach Notification (2025-01-20)PRIVCOMNotice
Consultation Paper - Cyber Risk Management Code of ConductBMAConsultation Paper
Consultation Paper - DAB Operational Cyber Risk CodeBMAConsultation Paper
Consultation Paper - Digital Asset Business Amendment Act 2021BMAConsultation Paper
Consultation Paper - Operational Resilience and Outsourcing Package (2025-01-14)BMAConsultation Paper
Consultation Paper - Proposed Adoption of the Revised Operational Risk Principles for BanksBMAConsultation Paper
Consultation Paper - Regulation of Digital Identity Service Provider Business (2024-11-22)BMAConsultation Paper
Digital Asset Business (Client Disclosure) Rules 2018BMARule
Digital Asset Business (Cyber Risk) Rules 2022BMARule
Digital Asset Business (Cyber Risk) Rules 2023BMARule
Digital Asset Business - Code of Practice (February 2024)BMACode
Digital Asset Business - Operational Cyber Risk Management Code of Practice (January 2024)BMACode
Digital Asset Business Act 2018 - Code of Practice (April 2023)BMACode
Digital Asset Business Custody Code of Practice (February 2024)BMACode
Digital Asset Business FAQ's (2019-06-20)BMANotice
Digital Asset Business Operational Cyber Risk Management Code of Practice (April 2022)BMACode
Digital Asset Custody Code of Practice 2018BMAConsultation Paper
Digital Asset Issuance Rules 2020BMARule
Discussion Paper - Asset Tokenisation (2025-11-05)BMAConsultation Paper
Discussion Paper - The Responsible Use of Artificial Intelligence in Bermuda's Financial Services Sector (2025-07-30)BMAConsultation Paper
Draft Schedule I – Insurance Marketplace Provider Return (2019)BMAForm
Guidance Note - Digital Asset Business - Guidance for prospective applicants for licensing (September 2025)BMAStatement of Guidance
Guide to PIPA: Security safeguardsPRIVCOMStatement of Guidance
Insurance (Group Supervision) Rules 2011BMARule
Insurance (Group Supervision) Rules 2011 (BR 76 / 2011)BMARule
Insurance (Insurance Marketplace Provider) (Statutory Financial Return) Rules 2020 - SchedulesBMARule
Insurance (Prudential Standards) (Insurance Brokers and Agents Annual Return) Rules 2018BMARule
Insurance (Prudential Standards) (Insurance Marketplace Provider Annual Return) Rules 2019 (BR 155/2019)BMARule
Insurance (Prudential Standards)(Insurance Managers Annual Return) Rules 2017 - ScheduleBMARule
Insurance (Special Purpose Insurers) (Statements, Returns and Solvency Requirements) Rules 2020 - SchedulesBMARule
Insurance Sector Operational Cyber Risk Management Code of Conduct (Consultation, December 2019)BMAConsultation Paper
Insurance Sector Operational Cyber Risk Management Code of Conduct (October 2020)BMACode
NOTICE-Draft Rules for Annual Filing Requirements of Insurance Marketplace Providers and Class IIGB Insurers (2019-10-31)BMAConsultation Paper
Notice - 2020 Year-End BSCR Model for Class 3A and 3B Insurers - Schedule V(e) Stress/Scenario Tests (2021-02-23)BMANotice
Notice - 2021 Year-End BSCR Model Schedule V(e) Cyber Risk Stress Test Scenarios (2022-03-08)BMANotice
Notice - 2022 Annual Return Templates for Insurance Intermediaries (2022-04-20)BMANotice
Notice - BMA Public Warning - Fraudulent Email Domain: BMA-BM.com used to Misdirect Wire Payment (2025-08-14)BMANotice
Notice - Consultation - Digital Asset Business (Custody of Client Assets) Rules 2024 (2024-02-29)BMAConsultation Paper
Notice - Cyber Code (2021-10-29)BMANotice
Notice - Cyber Risk Management for Insurance Managers, Brokers and Agents (2021-12-17)BMANotice
Notice - DAB Operational Cyber Risk Code (2022-05-11)BMAConsultation Paper
Notice - Digital Asset Business - Operational Cyber Risk Management Code of Practice (2022-04-05)BMANotice
Notice - Digital Asset Issuance Statement of Principles and Digital Asset Issuance Rules 2020 (2020-06-23)BMANotice
Notice - Insurance Managers Annual Return Template (2018-04-11)BMANotice
Notice - Operational Cyber Risk Management Code of Conduct: Banks and Deposit Companies (2022-09-26)BMANotice
Operational Cyber Risk Management Code of Conduct (September 2022 Revised)BMACode
Operational Cyber Risk Management Code of Conduct - Corporate Service Providers, Trust Companies, Money Service Businesses, Investment Businesses and Fund Administration Providers (2022-03-15)BMACode
Operational Resilience and Outsourcing - Guidance NotesBMAStatement of Guidance
Operational Resilience and Outsourcing Code (September 2025)BMACode
Operational Resilience and Outsourcing Code (September 2025) (Tracked Changes)BMACode
Operational Resilience and Outsourcing Guidance Notes (September 2025, Tracked Changes)BMAStatement of Guidance
PrivCom Advises the Public on Cyberattacks (2024-03-28)PRIVCOMAdvisory
Public Warning: Phishing Attempts from Individuals Misrepresenting the BMA (2024-10-01)BMANotice
Public Warning: Phishing Attempts on Bermuda Financial Services Licensees (2024-05-09)BMANotice
Response to Industry Comments - Insurance Sector Operational Cyber Risk Management Code of Conduct (2020-10)BMAConsultation Paper
Stakeholder Letter - Consultation on the Proposed Framework for Digital Identity Service Providers (DISP) (2025-04-29)BMAConsultation Paper
Stakeholder Letter - Operational Cyber Risk Management Code of Conduct (2022-03-14)BMACircular
Update to the Schedule of Cyber Risk Management (2021-12-17)BMANotice
Virtual Currency (Cybersecurity) Rules 2018BMARule
Virtual Currency Business (Prudential Standards) (Annual Return) Rules 2018BMARule
WEBSITE FALSELY LINKED TO BMA - WWW.BMAFINANCIER.COM (2020-09-08)BMANotice