Guernsey

cybersecurity

23 Guernsey regulatory document(s) tagged cybersecurity.

Practice-note overview · reflects instruments as at 2026-07-13. Generated from the indexed documents below and human-reviewed — not legal advice.

Who is caught

The core instrument is the GFSC's Cyber Security Rules and Guidance, 2021, which imposes mandatory requirements on all licensees of the Commission and applies proportionately to the size, nature and complexity of each licensee's business. The remaining indexed documents address related technology and outsourcing risk and apply to GFSC licensees or defined subsets of them.

  • GFSC licensees: The Cyber Security Rules apply to all licensees licensed under the Regulatory Laws, under Board oversight and on a proportionate basis.
  • Prescribed and non-regulated businesses: Prescribed Businesses and Non-Regulated Financial Services Business are not bound by the Rules but are encouraged to have regard to the accompanying guidance.
  • POI-licensed entities: The outsourcing guidance note applies to entities licensed under the Protection of Investors (Bailiwick of Guernsey) Law, 2020, whether functions are outsourced to a group entity or external third party and whether the provider is inside or outside the Bailiwick.
  • Firms and technology risk: The Dear CEO letter on AI issues addresses technology risk for GFSC-licensed financial services firms, and the phone spoofing risk warning is addressed to licensees generally.

Sources: Cyber Security Rules and Guidance, 2021 · Dear CEO Letter on AI Issues - July 2026 (2026-07-07) · Guidance Note on the Outsourcing of Functions by Entities Licensed Under The Protection of Investors (Bailiwick of Guernsey) Law, 2020 · Risk Warning Regarding Phone Spoofing (2015-03-11)


Key duties

The principal continuing obligations sit in the Cyber Security Rules, 2021, which frame cyber risk management around identifying, protecting, detecting, responding and recovering, with Board-level accountability. Notification of significant events and periodic review carry the clearest timing expectations.

Cyber security controls

  • Identify: Licensees must identify their material assets (including systems, people and data) and assess the significant associated cyber risks.
  • Protect and detect: Licensees must maintain appropriate policies and controls to mitigate identified risks, support delivery of critical infrastructure during a cyber event, and have mechanisms to detect cyber security events.
  • Respond and recover: Licensees must maintain and be able to demonstrate a plan to mitigate disruption and restore business capabilities, including awareness of relevant group-level or outsourced provider plans.
  • Notification: Licensees must notify the Commission as soon as reasonably practicable on becoming aware of a cyber security event causing significant loss of user data, IT availability, cost, business capability or service to users, providing specified event details.
  • Governance and evidence: The Board (or equivalent) is responsible for compliance and must be able to evidence, on request, that the Rules have been considered and implemented proportionately.
  • Review: Licensees must review their cyber security measures following trigger events or identified incidents, or periodically, and record those reviews; the Commission expects review no less often than every 24 months.
  • Transitional compliance: The Rules came into force on 8 February 2021, with firms required to implement the necessary changes to their internal controls by 9 August 2021.

Outsourcing arrangements

  • Due diligence and monitoring: POI licensees must conduct due diligence before selecting a service provider and maintain documented procedures to monitor ongoing performance and compliance.
  • Written contract: There must be a legally binding written contract covering matters proportionate to materiality, including subcontracting, confidentiality, IT security, liability, business continuity and termination/exit.
  • Data protection and recovery: Licensees must protect proprietary and client data and software and ensure providers maintain emergency and disaster recovery procedures with periodic testing.
  • Access rights: The Commission, the licensee and its auditors must have access to and inspection rights over service providers' books and records relating to outsourced activities.
  • Notify the Commission: Licensees must communicate with the Commission at an early stage about outsourcing proposals or changes; the Commission does not pre-approve arrangements but expects to be informed.
  • Retained accountability: Ultimate responsibility remains with the Guernsey licensee, whose Board and Senior Management must retain sufficient expertise to oversee the delegate and keep the mind and management within the Bailiwick.
  • Concentration risk: Licensees must consider and manage concentration risk where a single provider serves multiple licensees.

Ongoing technology risk

  • Patching regime: Firms should understand their IT patching regime and confirm it remains appropriate, including the ability to remediate vulnerabilities in a significantly shortened timeframe without reducing checks and controls.
  • Evolving exposure: Firms should treat technology risk as an ongoing exposure subject to continuous monitoring and review rather than a static, one-off assessment, and ensure outsourced providers can meet ongoing needs.
  • Staff awareness of fraud: Licensees should ensure employees are aware of phone/number spoofing, treat reliance on caller ID as a red flag, and notify the appropriate authorities, including the Financial Intelligence Unit, of suspicious calls.

Sources: Cyber Security Rules and Guidance, 2021 · Dear CEO Letter on AI Issues - July 2026 (2026-07-07) · Guidance Note on the Outsourcing of Functions by Entities Licensed Under The Protection of Investors (Bailiwick of Guernsey) Law, 2020 · Risk Warning Regarding Phone Spoofing (2015-03-11)


Exemptions and carve-outs

The Cyber Security Rules provide a discretionary derogation, and treat certain business types as outside their mandatory scope.

  • Commission derogation: The Commission may, by written notice, exclude or modify the application of any provision of the Rules for a licensee where satisfied this would not prejudice client interests or the Bailiwick's reputation.
  • Non-licensed businesses: Prescribed Businesses and Non-Regulated Financial Services Business are outside the mandatory Rules and are only encouraged to have regard to the guidance.
  • Proportionality: The Rules apply proportionately to the size, nature and complexity of each licensee's business rather than uniformly.

The other indexed documents do not set out specific exemptions or carve-outs.

Sources: Cyber Security Rules and Guidance, 2021


Enforcement and penalties

The instruments indexed here do not set out specific penalty provisions or enforcement powers for non-compliance.

Documents

CitationRegulatorType
Bailiwick Data Protection Advisory (2025-03-03)ODPAAdvisory
Bailiwick Data Protection Advisory (2025-08-27)ODPAAdvisory
Bailiwick Data Protection Advisory - Data Scraping (2025-01-31)ODPAAdvisory
Cloud ComputingODPAStatement of Guidance
Cyber Security Rules and Guidance Consultation Paper (September 2020)GFSCConsultation Paper
Cyber Security Rules and Guidance, 2021GFSCRule
Cyber Security Self-Assessment Helpsheet – November 2019GFSCReference Material
Cyber security checklistODPAStatement of Guidance
Data Security - A Thematic Report on Practices within the Fiduciary Sector (2014-04)GFSCAdvisory
Dear CEO Letter on AI Issues - July 2026 (2026-07-07)GFSCCircular
Determination - ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)ODPANotice
Determination - ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)ODPANotice
Determination - The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)ODPANotice
Following ODPA investigation into IT outage, SoG confirms completion of recommendations (2025-02-12)ODPANotice
Guidance Note on the Outsourcing of Functions by Entities Licensed Under The Protection of Investors (Bailiwick of Guernsey) Law, 2020GFSCStatement of Guidance
Handling Data BreachesODPAStatement of Guidance
ODPA sanctions First Contact Health for phishing attack breach (2026-02-12)ODPANotice
ODPA sanctions Fresh Dental for phishing attack breach (2025-12-11)ODPANotice
Protect against phishingODPAStatement of Guidance
Risk Warning Regarding Phone Spoofing (2015-03-11)GFSCNotice
Risk Warning Regarding the Increased Use of Compromised E-mail Accounts to Commit Fraud (2015-03-11)GFSCAdvisory
The Ladies' College ordered to improve security measures following breach (2025-12-04)ODPANotice
The Medical Specialist Group fined £100,000 following cyber-attack breach (2025-10-20)ODPANotice