Circular

Cybersecurity Circular (2017-10-17)

Cayman Islands Monetary Authority (CIMA) · Cayman Islands

Issued 2017-10-17

Current version last checked: 2026-07-05

Summary

This is a 2017 circular from the Cayman Islands Monetary Authority (CIMA) raising awareness about cybersecurity risks facing the financial services industry. It follows an earlier notice from earlier in 2017 and highlights the growing frequency, sophistication, and cost of cyber-attacks targeting financial institutions, including those in the Cayman Islands specifically. The circular references industry data (a PwC survey) on rising security incidents.

Key Challenges Identified

  • Third-party vendor security
  • Rapidly evolving technology
  • Cross-border data exchange
  • Mobile technology use
  • External threats

CIMA's Internal Steps

The circular also describes CIMA's own internal steps: adopting the NIST Cybersecurity Framework (covering the functions Identify, Protect, Detect, Respond, Recover) in conjunction with the Information and Communication Technology Authority and Central Government, and developing internal policies to strengthen its own security posture.

Expectations for Licensees

For licensees, the circular is primarily advisory. It strongly encourages them to take the following actions.

  • Assess cybersecurity risks
  • Reassess and update their security strategies
  • Test their security programs for vulnerabilities

The circular also puts licensees on notice that, going forward, CIMA will review licensees' data security risk management approaches as part of supervision, potentially examining technical controls, incident response, and staff training, depending on a licensee's business and risk profile, and will assess licensees' ability to protect the confidentiality, integrity and availability of customer and other sensitive information. The circular does not impose specific new binding rules, filing requirements, or deadlines.

Key obligations

  • Licensees are encouraged to assess their cybersecurity risks and reassess their security strategies to ensure they are comprehensive and up-to-date.
  • Licensees are encouraged to test their security programs to identify system vulnerabilities.
  • Licensees should be prepared for CIMA to review their data security risk management approach, including technical controls, incident response, and staff training, as part of ongoing supervision.

Applies to

licensees (Cayman Islands financial services industry)

Topics

Version history

2026-07-05

source file (current)

2026-07-05

source file