Rule
Cyber Security Rules and Guidance, 2021
In forceView on GFSC's website Source document
Summary
These Rules set out mandatory cyber security requirements for all licensees of the Guernsey Financial Services Commission, supported by extensive non-binding guidance on how firms might meet them. They require licensees, under Board oversight, to identify assets and risks, implement protective and detective controls, maintain response and recovery plans, and notify the Commission of significant cyber security events. The Rules apply proportionately based on the size, nature and complexity of each licensee's business, and non-licensed businesses such as Prescribed Businesses are encouraged to have regard to the accompanying guidance.
- Identify: Licensees must identify their material assets (including systems, people and data) and assess significant associated cyber risks.
- Protect and Detect: Licensees must have appropriate policies and controls to mitigate identified risks, maintain delivery of critical infrastructure during a cyber event, and have mechanisms in place to detect cyber security events.
- Respond and Recover: Licensees must have a plan to mitigate disruption from a cyber security event and be aware of appropriate steps to restore business capabilities, including awareness of group-level or outsourced provider plans where relevant.
- Notification: Licensees must notify the Commission as soon as reasonably practicable upon becoming aware of a cyber security event causing significant loss of user data, IT availability, cost, business capability or service to users, providing specified details of the event.
- Governance and review: The Board (or equivalent) is responsible for ensuring compliance, must be able to evidence implementation on request, and must review measures following trigger events, identified cyber incidents, or periodically (the Commission expects no less often than every 24 months).
- Derogation: The Commission may, by written notice, exclude or modify application of any provision for a licensee if satisfied this would not prejudice client interests or the Bailiwick's reputation.
The Rules came into force on 8 February 2021, with a transitional period requiring firms to implement necessary changes to their internal controls to achieve compliance by 9 August 2021.
Key obligations
- Licensees must identify their material assets and carry out an assessment of significant associated cyber risks.
- Licensees must have appropriate policies and controls to mitigate identified cyber risks and support delivery of critical infrastructure during and after a cyber security event.
- Licensees must have appropriate mechanisms in place to identify the occurrence of a cyber security event.
- Licensees must maintain and be able to demonstrate a plan to mitigate disruption caused by a cyber security event, including awareness of any relevant group-level or outsourced provider plans.
- Licensees must be able to demonstrate awareness of the steps needed to restore business capabilities and essential activities following a cyber security event.
- Licensees must notify the Commission as soon as reasonably practicable upon becoming aware of a cyber security event causing significant loss of user data, IT availability, cost, business capability or service to users, including specified event details in the notification.
- Licensees must be able to provide evidence to the Commission, on request, that the Rules have been considered and implemented in line with the size, nature and complexity of their business.
- Licensees must review their cyber security measures in response to trigger events, following identified cyber security events, or at least periodically, and record such reviews.
- Firms must implement changes to their internal controls to ensure compliance with the Rules by 9 August 2021.
Applies to
licensees licensed under the Regulatory Laws, Prescribed Businesses (guidance only), Non-Regulated Financial Services Business (guidance only)
Deadlines
- 8th February 2021: Date on which the Cyber Security Rules, 2021 come into force.
- 9th August 2021: Deadline by which firms must implement changes to their internal controls to ensure compliance with the Rules (transitional arrangement).
- at least every 24 months: Expected minimum frequency for periodic review of cyber security measures adopted to comply with the Rules.
- annually: Boards should report to shareholders that they are comfortable with their cyber policies, controls and reporting.