Circular
Cybersecurity Circular (2016-05-25)
IssuedView on CIMA's website Source document
Summary
This is a 2016 circular from the Cayman Islands Monetary Authority (CIMA) addressed to all licensees, raising awareness about cybersecurity risks facing the financial services sector. It highlights the growing frequency and sophistication of cyber-attacks, particularly against institutions in international financial centers like the Cayman Islands, and references industry data (PwC's 2016 Global State of Information Security Survey) showing rising incident rates and security spending.
The circular explains that CIMA itself is adopting the NIST Cybersecurity Framework internally, working with the Information and Communication Technology Authority and Central Government, and is developing internal policies covering the five NIST functions: Identify, Protect, Detect, Respond, and Recover. It notes CIMA works with the Financial Crimes Unit and is aware of escalating attacks targeting the Cayman Islands financial industry.
The document does not impose new binding rules, but strongly encourages licensees to take certain steps and puts them on notice of future supervisory attention.
- Assess risks: Licensees are encouraged to assess their cybersecurity risks.
- Update strategies: Licensees are encouraged to reassess and update their security strategies.
- Test programs: Licensees are encouraged to test their security programs to identify vulnerabilities.
- Future supervisory reviews: Going forward, CIMA will review licensees' data security risk management approaches during supervisory reviews, potentially examining technical controls, incident response, and staff training, as well as licensees' ability to protect the confidentiality, integrity and availability of sensitive customer information.
Key obligations
- Licensees are strongly encouraged to assess their cybersecurity risks and identify vulnerabilities.
- Licensees are strongly encouraged to reassess and update their cybersecurity strategies to ensure they are comprehensive and current.
- Licensees are strongly encouraged to test their security programs to identify system vulnerabilities.
- Licensees should be prepared for CIMA supervisory reviews of their data security risk management, which may examine technical controls, incident response, and staff training.
Applies to
Licensees (all CIMA-regulated financial services licensees)