Reference Material

Cyber Security Self-Assessment Helpsheet – November 2019

Guernsey Financial Services Commission (GFSC) · Guernsey

Status not confirmed

Published: 2019-11-27

Current version last checked: 2026-07-27

Summary

This is a non-binding self-assurance helpsheet issued by the GFSC following a Cyber Thematic review. It sets out discussion topics and prompts for firms to reflect on internally when assessing their own cyber security posture against international standards. The document explicitly states it is not formal guidance and is not a checklist the Commission will assess firms against.

  • Five Pillars: Identification, Protection, Detection, Response and Recovery as a framing for cyber security programmes
  • Technical controls: Patching and vulnerability management, penetration testing, firewalls/IDS-IPS, multi factor authentication, strong passwords, email/phishing protection, antivirus, backups, mobile device management and data loss prevention
  • People controls: Staff training on phishing, passwords, clear desk, BYOD, data management, removable media, safe internet habits, physical security and incident response
  • Policies and governance: Whether the firm has acceptable use, confidential data, email, mobile device, incident response, network security, password, physical security and wireless/guest access policies
  • Board oversight: Suggested management information for boards, including patching status, unsupported systems, staff training completion, phishing simulation results, penetration test findings, third party management, emerging threats, incident statistics and regulatory compliance status

The helpsheet also recaps the core information security concepts of confidentiality, integrity and availability, and links to external resources such as the NCSC 10 Steps to Cyber Security, the NCSC Board Toolkit and the NIST Cybersecurity Framework.

Applies to

GFSC licensed and regulated firms

Topics

Version history

2026-07-12

source file (current)