Circular
Cybersecurity Circular (2017-10-17)
Issued 2017-10-17View on CIMA's website Source document
Summary
This is a 2017 circular from the Cayman Islands Monetary Authority (CIMA) raising awareness about cybersecurity risks facing the financial services industry. It follows an earlier notice from earlier in 2017 and highlights the growing frequency, sophistication, and cost of cyber-attacks targeting financial institutions, including those in the Cayman Islands specifically. The circular references industry data (a PwC survey) on rising security incidents.
Key Challenges Identified
- Third-party vendor security
- Rapidly evolving technology
- Cross-border data exchange
- Mobile technology use
- External threats
CIMA's Internal Steps
The circular also describes CIMA's own internal steps: adopting the NIST Cybersecurity Framework (covering the functions Identify, Protect, Detect, Respond, Recover) in conjunction with the Information and Communication Technology Authority and Central Government, and developing internal policies to strengthen its own security posture.
Expectations for Licensees
For licensees, the circular is primarily advisory. It strongly encourages them to take the following actions.
- Assess cybersecurity risks
- Reassess and update their security strategies
- Test their security programs for vulnerabilities
The circular also puts licensees on notice that, going forward, CIMA will review licensees' data security risk management approaches as part of supervision, potentially examining technical controls, incident response, and staff training, depending on a licensee's business and risk profile, and will assess licensees' ability to protect the confidentiality, integrity and availability of customer and other sensitive information. The circular does not impose specific new binding rules, filing requirements, or deadlines.
Key obligations
- Licensees are encouraged to assess their cybersecurity risks and reassess their security strategies to ensure they are comprehensive and up-to-date.
- Licensees are encouraged to test their security programs to identify system vulnerabilities.
- Licensees should be prepared for CIMA to review their data security risk management approach, including technical controls, incident response, and staff training, as part of ongoing supervision.
Applies to
licensees (Cayman Islands financial services industry)