Rule
Rule - Cybersecurity for Regulated Entities (April 2023)
Status not confirmedView on CIMA's website Source document
Summary
This is CIMA's Rule on Cybersecurity for Regulated Entities (April 2023), issued under section 34(1)(a) of the Monetary Authority Act. It establishes binding, minimum cybersecurity requirements for entities regulated by CIMA, replacing/complementing the accompanying Statement of Guidance on the same topic. The Rule applies to all CIMA-regulated entities (including controlled subsidiaries under the Banks and Trust Companies Act), but expressly excludes Regulated Mutual Funds and Private Funds.
- Class B, C and D insurers fully managed by a licensed insurance manager: Special, lighter treatment applies; the insurer must instead ensure the manager's framework is adequate.
- Private Trust Companies: Must consider their own risk tolerance and implement a proportionate cybersecurity framework.
The Rule requires regulated entities to build, document and maintain a comprehensive cybersecurity framework covering a governance-approved risk management strategy, policies/procedures, managerial accountability, and incident response/recovery processes tied to approved Recovery Point/Time Objectives. It assigns ultimate responsibility for cybersecurity to the entity's governing body (board, general partner, manager or board of trustees, as applicable), including approval of the framework, risk assessments, audit plans and periodic reviews.
- Group-wide arrangements: The Rule addresses cybersecurity arrangements that span a group.
- Managed entities: Entities relying on a service provider's framework are covered.
- Training and awareness: Programmes for staff must be maintained.
- Staffing adequacy: Entities must ensure sufficient staffing for cybersecurity functions.
- Outsourcing oversight: Entities must oversee outsourced cybersecurity functions.
- Data protection integration: Cybersecurity measures must incorporate data protection considerations consistent with the Data Protection Act and Ombudsman guidance.
A key operational requirement is mandatory incident notification to CIMA: entities must notify the Authority immediately upon identifying a material (or potentially material) cybersecurity incident, and in any event no later than 72 hours after discovery, using specified criteria to judge materiality. Entities must also notify affected persons where a cyber attack breaches non-public information or disrupts a utilised service, including remediation details. Breach of the Rule exposes entities to CIMA's enforcement powers under its Enforcement Manual and the regulatory Acts/MAA.
Key obligations
- Establish, implement and maintain a documented cybersecurity framework designed to identify, measure, assess, report, monitor and control cybersecurity risks and to respond to and recover from breaches with material impact.
- Ensure the cybersecurity framework includes a governing-body-approved risk management strategy, adequate cybersecurity/IT security policies and procedures, clearly identified managerial responsibilities/controls, and documented incident response/recovery processes aligned to approved Recovery Point/Time Objectives.
- Regularly review emerging cybersecurity threats and the IT landscape and reassess the cybersecurity framework's adequacy.
- Governing body must approve the cybersecurity risk management strategy, risk assessments, the overall framework, and the cybersecurity audit plan, and must periodically review the framework and ensure timely remediation of audit findings.
- For group-related entities, assess and document that an appropriate cybersecurity framework exists on both a group-wide and legal-entity basis, implemented on a consolidated basis meeting the Rule's minimum requirements.
- Entities fully managed by a licensed service provider (e.g., certain insurers) must, through their governing body, make appropriate enquiries to satisfy themselves of the service provider's cybersecurity level, remain ultimately responsible, and require the service provider to report cybersecurity breaches pertaining to them.
- Class B, C and D insurers fully managed by a licensed insurance manager need only comply with Rule 6.3; the insurance manager must ensure the framework used for those insurers is commensurate with their size, complexity and risk profile.
- Private Trust Companies must consider their cybersecurity risk and risk tolerance and implement an appropriate framework.
- Establish a comprehensive cybersecurity training and awareness programme endorsed by the governing body/senior management, reviewed and updated to remain current.
- Ensure sufficient and suitable personnel to maintain the cybersecurity framework, commensurate with the entity's size, complexity and risk profile.
- For outsourced IT functions (external or intra-group), remain ultimately responsible, assess service providers' compliance with this Rule and related SOGs, and maintain oversight/accountability as if functions were performed in-house.
- Demonstrate that data protection is incorporated into the entity's strategy and cybersecurity framework, considering the Data Protection Act and Ombudsman guidance.
- Notify the Authority in writing immediately of any incident with material impact or potential to become material, and in any event no later than 72 hours after discovery.
- Notify affected persons where a cyber attack breaches non-public information or disrupts a utilised service, including information on containment, remediation and recovery actions taken.
Applies to
entities regulated by the Cayman Islands Monetary Authority, controlled subsidiaries (as defined in the Banks and Trust Companies Act), Class 'B' insurers, Class 'C' insurers, Class 'D' insurers, licensed insurance managers, Private Trust Companies
Deadlines
- no later than 72 hours following the discovery of said incident: Deadline for regulated entities to notify the Authority in writing of a cybersecurity incident deemed to have (or potentially have) a material impact.