Cayman Islands
cybersecurity
28 Cayman Islands regulatory document(s) tagged cybersecurity.
Who is caught
The core instruments on cybersecurity are CIMA's Rule and accompanying Statement of Guidance on Cybersecurity for Regulated Entities (both April 2023), supported by a series of awareness circulars and, for the virtual asset sector, dedicated rules, a policy and a statement of principles. Together they reach broadly across CIMA-regulated business, with the Rule and Guidance setting the general standard and the virtual asset instruments layering sector-specific expectations.
General regulated entities
- Cybersecurity Rule and Guidance: The Rule and Statement of Guidance apply to all entities regulated by CIMA, including controlled subsidiaries as defined in the Banks and Trust Companies Act.
- Proportionate application: Entities are expected to apply the framework in proportion to their size, complexity, structure and risk profile.
- Awareness circulars: CIMA's cybersecurity circulars (2016, 2017) and related supervisory circulars address all CIMA licensees and financial service providers generally.
Virtual asset providers
- Custodians and trading platforms: A separate December 2024 Rule imposes IT and cybersecurity requirements on virtual asset custodians and virtual asset trading platforms licensed or registered under the Virtual Asset (Service Providers) Act.
- VASPs generally: The Statement of Principles (February 2021) applies to all persons providing virtual asset services under the VASP Act, including those registered, licensed or granted a waiver, and includes maintenance of cyber security systems among its conduct principles.
- Applicants: CIMA's Regulatory Policy on registration or licensing of VASPs treats IT and cyber security as matters it assesses when deciding applications.
Sources: Statement of Principles – Conduct of Virtual Asset Services (February 2021) · Information Circular - Cybersecurity (2017-10-30) · Rule - Cybersecurity for Regulated Entities (April 2023) · Statement of Guidance – Cybersecurity for Regulated Entities (April 2023) · Cybersecurity Circular (2017-10-17) · Regulatory Policy - Registration or Licensing of Virtual Asset Service Providers · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024) · Cybersecurity Circular (2016-05-25)
Key duties
The central continuing obligations sit in the Cybersecurity Rule, which requires a documented framework and mandatory incident notification, with the Statement of Guidance setting out how CIMA expects that framework to operate. The virtual asset instruments add sector-specific expectations.
Cybersecurity framework
- Documented framework: Under the Rule, entities must establish, implement and maintain a documented cybersecurity framework to identify, assess, monitor and control cyber risks and to respond to and recover from breaches with material impact.
- Governing body responsibility: The governing body (board, general partner, manager or board of trustees) holds ultimate responsibility and must approve the risk management strategy, risk assessments, the framework and the cybersecurity audit plan, and periodically review it and ensure remediation of audit findings.
- Recovery objectives: Incident response and recovery processes must be tied to approved Recovery Point and Recovery Time Objectives.
- Training and staffing: Entities must maintain a governing-body-endorsed training and awareness programme and ensure sufficient and suitable personnel.
- Outsourcing oversight: For outsourced IT functions, entities remain ultimately responsible, must assess provider compliance with the Rule and related guidance, and maintain oversight as if the functions were performed in-house.
- Group arrangements: Group-related entities must assess and document an appropriate framework on both a group-wide and legal-entity basis.
- Data protection: Data protection must be incorporated into the framework, taking into account the Data Protection Act and Ombudsman guidance.
Self-assessment and testing
- Annual self-assessment: The Guidance expects at least annual self-assessments against the framework, the Rule and relevant standards.
- Independent assurance: Entities should establish an internal audit function or equivalent to provide independent, regular assurance to the governing body.
- Asset inventory: Maintain an up-to-date inventory and criticality classification of information systems and assets, and conduct regular risk assessments.
- Monitoring and controls: Implement monitoring and detection systems, encryption of confidential data in transit and at rest, least-privilege access controls, and secure disposal of data on decommissioned systems.
- Post-incident review: Conduct a post-incident review for material incidents and make it available to CIMA on request.
Incident notification
- Notify CIMA within 72 hours: Under the Rule, entities must notify the Authority in writing immediately of any incident with material impact or the potential to become material, and in any event no later than 72 hours after discovery.
- Notify affected persons: Entities must notify affected persons where a cyber attack breaches non-public information or disrupts a utilised service, including containment, remediation and recovery details.
- Ongoing updates: The Guidance expects notification to CIMA (and affected individuals and the Ombudsman where applicable) as quickly as possible on loss of financial assets or personal data, with updates until the incident is resolved.
- BEC and cyber fraud reporting: A 2019 supervisory circular states that on suspecting a Business Email Compromise or other cybercrime, a licensee must immediately report to the Financial Crime Unit and the Financial Reporting Authority, notify CIMA, and complete CIMA's Cyber Incident Report.
Virtual asset providers
- IT and cyber controls: The 2024 VASP Rule requires custodians and trading platforms to maintain IT and cybersecurity arrangements, robust risk management and internal controls, and appropriate insurance (including cyber security cover) where appropriate.
- Application requirements: The VASP registration and licensing policy requires applicants to demonstrate IT and blockchain infrastructure, risk assessments and a business continuity framework.
Sources: General Overview: Audit Firms, BEC Schemes, Board Proxies & Other (2019-09-06) · Rule - Cybersecurity for Regulated Entities (April 2023) · Statement of Guidance – Cybersecurity for Regulated Entities (April 2023) · Regulatory Policy - Registration or Licensing of Virtual Asset Service Providers · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024)
Exemptions and carve-outs
The Cybersecurity Rule and Statement of Guidance carve out certain funds and provide lighter treatment for specified entities.
- Regulated funds excluded: Both the Rule and the Guidance expressly exclude regulated mutual funds (under the Mutual Funds Act) and private funds (under the Private Funds Act).
- Fully managed insurers: Class B, C and D insurers fully managed by a licensed insurance manager receive lighter treatment (needing only to comply with Rule 6.3), with the insurance manager required to ensure the framework used is commensurate with the insurers' size, complexity and risk profile.
- Managed entities: Entities fully managed by a licensed service provider may rely on the provider's framework but must make appropriate enquiries, remain ultimately responsible, and require the provider to report breaches pertaining to them.
- Private Trust Companies: Private Trust Companies must consider their own cyber risk and risk tolerance and implement a proportionate framework, rather than the full set of requirements.
- Sandbox applicants: The VASP registration and licensing policy states it does not apply to sandbox licence applicants.
Sources: Rule - Cybersecurity for Regulated Entities (April 2023) · Statement of Guidance – Cybersecurity for Regulated Entities (April 2023) · Regulatory Policy - Registration or Licensing of Virtual Asset Service Providers
Enforcement and penalties
The instruments indexed here point to CIMA's general enforcement regime rather than setting out cybersecurity-specific penalties.
- Enforcement powers: Breach of the Cybersecurity Rule and of the VASP Rule exposes entities to CIMA's enforcement powers under its Enforcement Manual and the relevant regulatory Acts and the Monetary Authority Act.
- Statement of Principles: Contraventions of the virtual asset conduct principles may trigger enforcement action under CIMA's Enforcement Manual and other statutory powers.
- Status of guidance: The Statement of Guidance is not directly enforceable in the same way as the Rule, but CIMA uses it to interpret and assess compliance with the Rule and incorporates cybersecurity reviews into its examinations.
- Fining powers: A 2023 regulatory update refers to legislative amendments expanding CIMA's administrative fining powers and liability provisions, but the summaries do not set out specific fine amounts for cybersecurity breaches.
Sources: Statement of Principles – Conduct of Virtual Asset Services (February 2021) · CIMA Regulatory Update: June 2023 to December 2023 (2024-03-31) · Rule - Cybersecurity for Regulated Entities (April 2023) · Statement of Guidance – Cybersecurity for Regulated Entities (April 2023) · Rule - Virtual Asset Custodians and Virtual Asset Trading Platforms (December 2024)