British Virgin Islands
cybersecurity
4 British Virgin Islands regulatory document(s) tagged cybersecurity.
Who is caught
The instruments indexed under this topic fall into two groups: one binding sanctions instrument addressing cyber-attacks, and a set of advisory security notices issued by BVI regulators. The Cyber (Sanctions) (Overseas Territories) Order 2020 extends the UK cyber sanctions regime to the BVI and has the broadest reach.
Cyber sanctions
The Cyber (Sanctions) (Overseas Territories) Order 2020 applies to a wide range of persons connected to the Territory, and singles out financial and professional-sector actors for its reporting duty.
- Persons in the Territory: Any person in the Territory, British-connected persons, bodies incorporated in the Territory, and persons on Territory-registered ships or aircraft.
- Relevant institutions: Deposit-taking businesses and similar institutions operating in the Territory.
- Relevant businesses or professions: Auditors, casinos, dealers in precious metals or stones, external accountants, independent legal professionals, real estate agents, tax advisers, and trust or company service providers.
Advisory notices
The remaining documents are informational security notices directed at recipients of regulator correspondence. The ITA phishing warnings address anyone receiving emails purporting to come from the ITA, while the FSC public statement is directed at customers, creditors, licensees and the public.
Sources: PHISHING SCAM (2026-01-22) · BVI ITA Issues Warning About Phishing Email (2025-04-02) · Public Statement 5 of 2026 - Fraudulent Emails (2026-03-20) · The Cyber (Sanctions) (Overseas Territories) Order 2020 (S.I. 2020 No. 281)
Key duties
The only binding continuing obligations here arise under the Cyber (Sanctions) (Overseas Territories) Order 2020. The regulator notices are advisory and, on their own terms, do not create new compliance obligations beyond ordinary vigilance.
Under the sanctions Order
- Asset freeze: Do not deal with funds or economic resources belonging to, owned, held or controlled by a designated person where you know or have reasonable cause to suspect this.
- No making available: Do not make funds or economic resources available, directly or indirectly, to or for the benefit of a designated person, on the same knowledge or suspicion standard.
- Reporting to the Governor: Relevant institutions and relevant businesses or professions must inform the Governor as soon as practicable if they know or suspect a customer is a designated person or has committed an offence under the Order, providing specified identifying and transactional details.
- Frozen account credits: A relevant institution must inform the Governor as soon as practicable if it credits a frozen account in the circumstances specified in article 5.
- Licence conditions: Any activity otherwise prohibited requires a licence from the Governor, and the conditions of any such licence must be complied with.
No fixed reporting deadline is set beyond the "as soon as practicable" standard.
Advisory guidance
The ITA phishing warnings and the FSC public statement advise recipients to verify sender addresses against official domains, avoid opening suspicious links or attachments, and report suspected phishing. The FSC confirms genuine communications come only from the @bvifsc.vg domain and asks that suspicious emails be reported to commissioner@bvifsc.vg. These notices state they do not impose new regulatory filing requirements.
Sources: PHISHING SCAM (2026-01-22) · BVI ITA Issues Warning About Phishing Email (2025-04-02) · Public Statement 5 of 2026 - Fraudulent Emails (2026-03-20) · The Cyber (Sanctions) (Overseas Territories) Order 2020 (S.I. 2020 No. 281)
Exemptions and carve-outs
The sanctions Order provides for licensing and territorial carve-outs rather than exemptions in the ordinary regulatory sense.
- Licences: The Governor, with the Secretary of State's consent, may grant, vary or revoke licences authorising otherwise-prohibited activities, such as basic expenses, legal fees, and routine account maintenance charges.
- Excluded territories: The Order applies to the territories listed in its Schedule 1, excluding Bermuda and Gibraltar, which implement sanctions domestically.
The advisory notices do not set out exemptions.
Sources: The Cyber (Sanctions) (Overseas Territories) Order 2020 (S.I. 2020 No. 281)
Enforcement and penalties
Enforcement provisions appear only in the Cyber (Sanctions) (Overseas Territories) Order 2020.
- Criminal offences: Contravention or circumvention of the sanctions is a criminal offence, with associated penalties.
- Enforcement powers: Authorised officers have powers to enforce the regime, including in relation to ships, aircraft and vehicles.
The summaries do not state specific fine amounts or terms of imprisonment. The advisory notices from the ITA and FSC do not set out penalty provisions.
Sources: The Cyber (Sanctions) (Overseas Territories) Order 2020 (S.I. 2020 No. 281)
Documents
| Citation | Regulator | Type |
|---|---|---|
| BVI ITA Issues Warning About Phishing Email (2025-04-02) | ITA | Notice |
| PHISHING SCAM (2026-01-22) | ITA | Notice |
| Public Statement 5 of 2026 - Fraudulent Emails (2026-03-20) | FSC | Notice |
| The Cyber (Sanctions) (Overseas Territories) Order 2020 (S.I. 2020 No. 281) | FSC | Regulation |