{"kind":"expression","expression":{"expr_id":"276","doc_id":"276","label":"SL 38 of 2023","is_as_enacted":"t","commenced_on":null,"superseded_on":null,"valid_from":null,"valid_to":null,"is_current":"t","incorporating":null,"akn_expr_iri":"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01","akn_envelope":"{\"_canary\": {\"iri\": {\"work\": \"\/akn\/ky\/act\/sl\/2020\/95\", \"expression\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01\", \"manifestation\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01.pdf\"}, \"pdf\": {\"md5\": \"881464b6181868a3f843f85c7214d28f\", \"path\": \"\/Users\/q\/kyleg-data\/working\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.pdf\", \"pages\": 11, \"filename\": \"2020-0095_SL 38 of 2023.pdf\"}, \"errors\": [], \"extraction\": {\"model\": null, \"stats\": {\"word_count\": 2529, \"paragraph_count\": 10, \"text_char_count\": 18598}, \"usage\": null, \"method\": \"pymupdf-text\", \"version\": \"kyleg-akn-1.0\", \"extracted_at\": \"2026-07-18\"}, \"classification\": \"text_layer\", \"validation_flags\": [], \"docai_processor_id\": null}, \"akomaNtoso\": {\"act\": {\"body\": [{\"eId\": \"sec_n1\", \"num\": null, \"text\": \"_____________________________________________________________________________________________ Page 1 of 11 RULE Cybersecurity for Regulated Entities April 2023 _____________________________________________________________________________________________ Page 2 of 11 List of Acronyms IT Information Technology MAA Monetary Authority Act SOG Statement of Guidance _____________________________________________________________________________________________ Page 3 of 11 RULE Cybersecurity for Regulated Entities\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_1\", \"num\": \"1.\", \"text\": \"Statement of Objectives 1.1 To set out the Cayman Islands Monetary Authority\u2019s (\u201d the Authority\u201d) Rule on cybersecurity applicable to regulated entities, pursuant to the Monetary Authority Act (\u201cMAA\u201d). 1.2 The Authority acknowledges that technology presents important innovation, competitive advantages as well as greater efficiency, effectiveness and productivity for regulated entities and their clients. However, a significant compromise in the use of technology could impact the ability of regulated entities to meet overall business objectives or result in significant liability and reputational damage.  Therefore, it is important for regulated entities to ensure that robust cybersecurity measures are in place and that they can appropriately identify, protect, detect, respond to and recover from such cybersecurityrelated threats, incidents and breaches.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_2\", \"num\": \"2.\", \"text\": \"Statutory Authority 2.1 Section 34(1)(a) of the MAA provides that: After private sector consultation and consultation with the Minister charged with responsibility for Financial Services, the Authority may - issue or amend rules or statements of principle or guidance concerning the conduct of licensees and their officers and employees, and any other persons to whom and to the extent that the regulatory laws may apply; 2.2 This document establishes the Rule on cybersecurity for regulated entities and should be read in conjunction, with other regulatory instruments issued by the Authority from time to time, where applicable.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_3\", \"num\": \"3.\", \"text\": \"Scope of Application 3.1 This Rule applies to entities regulated by the Authority1 including controlled subsidiaries as defined in the Banks and Trust Companies Act (as amended). For the purpose of this Rule, a regulated entity is an entity that is regulated by the Authority in accordance with the regulatory Acts, as defined in the MAA (as amended). 3.2 References to any act or regulation shall be construed as references to those 1 Exceptions are a) Regulated Mutual Funds as defined in the Mutual Funds Act (as amended); and   b) Private Funds as defined in the Private Funds Act (as amended). _____________________________________________________________________________________________ Page 4 of 11 provisions as amended, modified, re-enacted, or replaced from time to time. 3.3 Regulated entities must ensure that services offered to clients are not carried out in such a way that compromises the confidentiality, integrity and availability of clients\u2019 data or the regulated entities\u2019 systems, where applicable. Regulated entities should apply this Rule and consider the corresponding Statement of Guidance (\u201cSOG\u201d) \u2013 Cybersecurity for Regulated Entities, where applicable, to ensure that there is a suitable and robust cybersecurity framework in place. 3.4 Regulated entities such as Class \u2018B\u2019, \u2018C\u2019 and \u2018D\u2019 insurers that are fully managed by a licensed insurance manager are only required to comply with Rule 6.3. Insurance Managers must ensure that the cybersecurity framework implemented in respect of insurers that they manage is commensurate with the size, complexity, structure, nature of business and risk profile of the operations of the said insurers and meets their specific needs and risk tolerance. 3.5 Private Trust Companies, as registrants, must consider their cybersecurity risk and their risk tolerance; and implement a framework appropriate to meet their cybersecurity needs.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_4\", \"num\": \"4.\", \"text\": \"Definitions 4.1 The following definitions are provided for the purpose of this Rule: 4.1.1 Cyber attack: An attack, via cyberspace, targeting an enterprise\u2019s use of cyberspace for the purpose of disrupting, disabling, destroying, or maliciously controlling a computing environment\/infrastructure; or destroying the integrity of the data or stealing controlled information. 4.1.2 Cyber resilience: The ability of systems and organisations to develop and execute long-term strategy to withstand cybersecurity events; practically, it is measured by the combination of mean time to failure and mean time to recovery. 4.1.3 Cyber risk: The risk of financial loss, operational disruption, or damage, from the failure of the digital technologies employed for informational and\/or operational functions introduced to a manufacturing system via electronic means from the unauthorised access, use, disclosure, disruption, modification, or destruction of the manufacturing system. 4.1.4 Cybersecurity: An approach or series of steps to prevent or manage the risk of damage to, unauthorised use of, exploitation of and, as needed, to restore electronic information and communications systems, and the information they contain, in order to strengthen the confidentiality, integrity, and availability of these systems. 4.1.5 Cybersecurity breach: Any unauthorised penetration of the defences2 2 Defences may be internal or external. _____________________________________________________________________________________________ Page 5 of 11 established to protect against cyber risk. 4.1.6 Cybersecurity framework: A complete set of organisational resources including policies, staff, processes, practices and technologies used to assess and mitigate cyber risks; and respond to and recover from cyber attacks. 4.1.7 Cybersecurity incident: A cybersecurity event that has been determined to have an impact on the organisation prompting the need for response and recovery. 4.1.8 Cybersecurity threat: Any circumstance or event with the potential to adversely impact organisational operations, organisational assets, individuals, other organisations, or the country through a system via unauthorised access, destruction, disclosure, modification of information, and\/or denial of service. 4.1.9 Cyberspace: A global domain within the information environment consisting of the interdependent network of information systems infrastructures including the internet, telecommunications networks, computer systems, and embedded processors and controllers. 4.1.10 Governing body: the Board of Directors where the entity is a corporation, the General Partner where the entity is a partnership, the manager (or equivalent) where the entity is a Limited Liability Company, and the Board of Trustees where the entity is a trust business. 4.1.11 Information technology (\u201cIT\u201d): Any equipment or interconnected system or subsystem of equipment that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information by the executive agency. The term includes computers, ancillary equipment, software, firmware, and similar procedures, services (including support services), and related resources. 4.1.12 Information technology risk: The risk of mission or business loss resulting from a particular threat source exploiting, or triggering, a particular information technology vulnerability. 4.1.13 Information system: A discrete set of electronic information resources organized for the collection, processing, maintenance, use, sharing, dissemination or disposition of electronic information, as well as any specialised system such as industrial\/process controls systems, telephone switching and private branch exchange systems, and environmental control systems. 4.1.14 Risk management: The use of structures, processes and people that identify, assess, mitigate, and monitor all internal and external sources of risk that could have a material impact on operations. _____________________________________________________________________________________________ Page 6 of 11 4.1.15 Risk tolerance: An entity\u2019s readiness to bear the risk after risk treatment in order to achieve its objectives. 4.1.16 Recovery Point Objective: The point in time to which data must be recovered after an outage. 4.1.17 Recovery Time Objective: The overall length of time an information system\u2019s components can be in the recovery phase before negatively impacting the organization\u2019s mission or mission\/business processes.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_5\", \"num\": \"5.\", \"text\": \"Rules 5.1 The Cybersecurity Framework 5.1.1 Regulated entities must establish, implement, and maintain a documented cybersecurity framework that is designed to promptly identify, measure, assess, report, monitor and control or minimise cybersecurity risks as well as responding to and recovering from cybersecurity breaches that could have a material impact on their operations. 5.1.2 The cybersecurity framework of regulated entities must include, but is not be limited to the following: a) a well-documented cybersecurity risk management strategy, approved by the governing body, which addresses all material cybersecurity risks to which the regulated entities are likely to be exposed based on their business activities and use of technology; b) cybersecurity and IT security policies and procedures that are adequate to identify, assess, mitigate, control, monitor and report on such risks to which regulated entities are exposed; c) clearly identified managerial responsibilities and controls, designed to ensure that the policies and procedures established for cybersecurity and risk management are always adhered to; and d) clear, documented, and effective processes for responding to, containing, and recovering from cyber attacks, cybersecurity breaches and incidents as quickly as possible or within regulated entities\u2019 governing body\u2019s approved Recover Point Objective or Recovery Time Objective depending on the type of attack or incident. _____________________________________________________________________________________________ Page 7 of 11 5.1.3 Regulated entities must regularly review the emerging (or evolving) cybersecurity threats and IT landscape and assess their cybersecurity framework to ensure that the framework continues to be appropriate to manage adverse impacts of the cyber risks and IT risks related to the regulated entities\u2019 business.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_6\", \"num\": \"6.\", \"text\": \"Role of the Governing Body 6.1 Regulated entities\u2019 governing bodies are ultimately responsible for cybersecurity and their duties must include, but not be limited to: a) approval of a written cybersecurity risk management strategy aligned with the overall business strategy and risk tolerance as well as approval of completed cybersecurity risk assessments and cybersecurity risk management as part of regulated entities\u2019 overall risk management strategies and programmes; b) approval of a comprehensive cybersecurity framework; c) appropriate oversight of the risk management framework to ensure that policies and processes are implemented effectively; d) periodic review of the cybersecurity framework; and e) approval of the cybersecurity audit plan; and ensuring that any findings are addressed in a timely manner. 6.2 Group and related entities 6.2.1 The Authority recognises that some regulated entities\u2019 risk management forms part of their parent company\u2019s risk management function. In these cases, the Authority does not expect regulated entities to duplicate functions that are already carried out by the parent. However, regulated entities should assess and document that, an appropriate cybersecurity framework is in place on a  group-wide basis and at the legal entity\u2019s level. 6.2.2 The cybersecurity framework should be implemented on a consolidated basis and must at a minimum cover the requirements noted in this Rule. 6.3 Managed Entities 6.3.1 The Authority recognises that certain regulated entities are fully managed by a licensed service provider. Furthermore, these entities might not develop their own cybersecurity framework but rather rely on the framework of their service provider. Such regulated entities that are managed by entities licensed by the Authority must make appropriate enquiries, through their governing body, to satisfy themselves with the level of cybersecurity applied by that service provider. _____________________________________________________________________________________________ Page 8 of 11 6.3.2 Regulated entities, as referred to in 6.3.1: a) are ultimately responsible for their cybersecurity and for assessing the service provider(s)\u2019 compliance with this Rule and the related SOG on Cybersecurity for Regulated Entities; and b) must satisfy themselves that the cybersecurity framework that will be applied in respect of the services provided to them is appropriate for the cybersecurity risks posed to them as a result of the use of technology and emerging cybersecurity threats. 6.3.3 The governing body of a regulated entity referred to in 6.3.1 must require the service provider to report any cybersecurity related breaches that pertain to the regulated entity. A mechanism must be in place to ensure that the regulated entities are aware through the governing body what services are being provided to them by their insurance managers. 6.4 Cybersecurity Awareness, Training and Resources 6.4.1 Regulated entities must establish a comprehensive training and awareness programme3 relating to cybersecurity and cyber-resilience that is endorsed by its governing body and\/or senior management. It should be reviewed and updated to ensure that the contents of the programme remain current and relevant by taking into consideration the evolving nature of technology as well as emerging risks, including risk areas for the regulated entity. 6.4.2 Regulated entities must ensure that they have sufficient and suitable personnel to maintain their cybersecurity framework, commensurate with the size, complexity, structure, nature of business and risk profile of its operations. 6.5 Management of Outsourcing Risks 6.5.1 Regulated entities that outsource IT functions either externally to third parties or internally to affiliated entities: a) remain ultimately responsible for outsourced IT functions and their cybersecurity; b) must ensure that they assess the service provider(s)\u2019 compliance with this Rule and related SOG on Cybersecurity for Regulated Entities and the SOG - Outsourcing: Regulated Entities; and c) must have oversight and clear accountability for all outsourced functions as if these functions were performed by the regulated entities themselves and subject to the normal standards of their 3 Training seeks to teach skills, which allow a person to perform a specific function, while awareness seeks to focus an individual\u2019s attention on an issue or set of issues. (Source: NIST Special Publication 800-16) _____________________________________________________________________________________________ Page 9 of 11 cybersecurity and IT security framework. 6.5.2 Regulated entities should also make considerations for outsourcing arrangements that go beyond IT-related functions that may also present a cybersecurity risk.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_7\", \"num\": \"7.\", \"text\": \"Data Protection 7.1 Regulated entities must demonstrate that data protection is part of their strategy and cybersecurity framework taking into consideration the provisions of the Data Protection Act and the guidance issued by the Cayman Islands Ombudsman on data protection.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_8\", \"num\": \"8.\", \"text\": \"Notification Requirements 8.1 Regulated entities must immediately notify the Authority in writing of an incident when it is deemed to have a material impact or has the potential to become a material incident, and no later than 72 hours following the discovery of said incident. 8.2 Regulated entities should define incident criticality in their incident management framework. When in doubt about the level of seriousness of an event, regulated entities should consult the Authority. Incidents should be reported to the Authority if they fall under one or more of the following: a) Material impact to the regulated entity\u2019s internal operations. b) The event results in the unauthorised dissemination of any personal data either internally or externally. c) Significant operational impact to internal users that is material to customers or business operations. d) Extended disruptions to critical business systems or internal operations. e) Number of external customers impacted is significant or growing. f) If determined that there is potential reputational impact, either to the regulated entity or the Cayman Islands as a whole, notification to the Authority must occur immediately if there is any risk of premature public disclosure. g) Any loss of any card payment information, beneficial owner details, or any personally identifiable information. h) Loss or exposure of any data in violation of any applicable data protection Acts and other regulatory requirements both foreign and domestic. 8.3 For regulated entities that have risk ratings in respect of their cyber risks, the Authority expects that the required notification includes ratings that correspond to a material incident. 8.4 Regulated entities must notify affected persons if a cyber attack results in the _____________________________________________________________________________________________ Page 10 of 11 breach of non-public information or disrupts a service that is utilised including information on the action taken to contain (as necessary), remedy and recover from the breach.\", \"element\": \"section\", \"heading\": null}, {\"eId\": \"sec_9\", \"num\": \"9.\", \"text\": \"Enforcement 9.1 Whenever a breach of these Rules occurs, the Authority\u2019s policies and procedures, as contained in its Enforcement Manual, will apply, in addition to any other powers provided in the regulatory Acts and the MAA. _____________________________________________________________________________________________ Page 11 of 11\", \"element\": \"section\", \"heading\": null}], \"meta\": {\"notes\": null, \"workflow\": null, \"lifecycle\": {\"source\": \"#cilegis\", \"eventRef\": [{\"eId\": \"e_commence_2023_01_01\", \"date\": \"2023-01-01\", \"type\": \"generation\", \"source\": \"#cilegis\"}]}, \"references\": {\"source\": \"#canary\", \"TLCRole\": [], \"TLCEvent\": [{\"eId\": \"ev_commencement\", \"href\": \"\/akn\/ontology\/canary\/event\/commencement\", \"showAs\": \"commencement\"}], \"TLCPerson\": [], \"TLCConcept\": [{\"eId\": \"inForce\", \"href\": \"\/akn\/ontology\/canary\/concept\/temporal\/in-force\", \"showAs\": \"in force\"}], \"TLCProcess\": [], \"TLCLocation\": [], \"TLCOrganization\": [{\"eId\": \"cilegis\", \"href\": \"\/akn\/ontology\/canary\/organization\/editor\/cilegis\", \"showAs\": \"Cayman Islands legislation mirror (kyleg)\"}]}, \"temporalData\": {\"source\": \"#cilegis\", \"temporalGroup\": [{\"eId\": \"tg_inforce_2023_01_01\", \"timeInterval\": [{\"end\": null, \"start\": \"#e_commence_2023_01_01\", \"duration\": null, \"refersTo\": \"#inForce\"}]}]}, \"classification\": null, \"identification\": {\"source\": \"#cilegis\", \"FRBRWork\": {\"FRBRuri\": \"\/akn\/ky\/act\/sl\/2020\/95\", \"FRBRdate\": [{\"date\": \"2023-01-01\", \"name\": \"generation\"}], \"FRBRthis\": \"\/akn\/ky\/act\/sl\/2020\/95\/!main\", \"FRBRalias\": [{\"name\": \"cmsId\", \"value\": \"2020-0095\"}], \"FRBRauthor\": [{\"as\": \"#editor\", \"href\": \"\/akn\/ontology\/canary\/organization\/editor\/cilegis\"}], \"FRBRnumber\": \"95 of 2020\", \"FRBRcountry\": \"ky\", \"FRBRsubtype\": \"subordinate\"}, \"FRBRExpression\": {\"FRBRuri\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01\", \"FRBRdate\": [{\"date\": \"2023-01-01\", \"name\": \"generation\"}], \"FRBRthis\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01\/!main\", \"FRBRauthor\": [{\"as\": \"#editor\", \"href\": \"\/akn\/ontology\/canary\/organization\/editor\/cilegis\"}], \"FRBRlanguage\": \"eng\"}, \"FRBRManifestation\": {\"FRBRuri\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01.xml\", \"FRBRdate\": [{\"date\": \"2026-07-18\", \"name\": \"generation\"}], \"FRBRthis\": \"\/akn\/ky\/act\/sl\/2020\/95\/eng@2023-01-01.xml\", \"FRBRauthor\": [{\"as\": \"#editor\", \"href\": \"\/akn\/ontology\/canary\/organization\/editor\/cilegis\"}], \"FRBRformat\": \"application\/xml\"}}}, \"name\": \"act\", \"header\": {\"title\": \"Rule \u2013 Cybersecurity for Regulated Entities\", \"actNumber\": \"95 of 2020\", \"longTitle\": null}}, \"doc\": null, \"bill\": null, \"judgment\": null}}","akn_full_text":"_____________________________________________________________________________________________\n\n                         Page 1 of 11\n\nRULE\n Cybersecurity for Regulated Entities\n\nApril 2023\n\n_____________________________________________________________________________________________\n\n                         Page 2 of 11\n\nList of Acronyms\n\nIT\nInformation Technology\nMAA\nMonetary Authority Act\nSOG\nStatement of Guidance\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 3 of 11\n\nRULE\n\nCybersecurity for Regulated Entities\n\n1. Statement of Objectives\n\n1.1\nTo set out the Cayman Islands Monetary Authority\u2019s (\u201d the Authority\u201d) Rule on\ncybersecurity applicable to regulated entities, pursuant to the Monetary\nAuthority Act (\u201cMAA\u201d).\n\n1.2\nThe Authority acknowledges that technology presents important innovation,\ncompetitive advantages as well as greater efficiency, effectiveness and\nproductivity for regulated entities and their clients. However, a significant\ncompromise in the use of technology could impact the ability of regulated\nentities to meet overall business objectives or result in significant liability and\nreputational damage.  Therefore, it is important for regulated entities to ensure\nthat robust cybersecurity measures are in place and that they can appropriately\nidentify, protect, detect, respond to and recover from such cybersecurityrelated threats, incidents and breaches.\n\n2. Statutory Authority\n\n2.1\nSection 34(1)(a) of the MAA provides that:\n\nAfter private sector consultation and consultation with the Minister charged with\nresponsibility for Financial Services, the Authority may -\n\nissue or amend rules or statements of principle or guidance concerning the\nconduct of licensees and their officers and employees, and any other persons\nto whom and to the extent that the regulatory laws may apply;\n\n2.2\nThis document establishes the Rule on cybersecurity for regulated entities and\nshould be read in conjunction, with other regulatory instruments issued by the\nAuthority from time to time, where applicable.\n\n3. Scope of Application\n\n3.1\nThis Rule applies to entities regulated by the Authority1 including controlled\nsubsidiaries as defined in the Banks and Trust Companies Act (as amended).\nFor the purpose of this Rule, a regulated entity is an entity that is regulated by\nthe Authority in accordance with the regulatory Acts, as defined in the MAA (as\namended).\n\n3.2\nReferences to any act or regulation shall be construed as references to those\n\n1 Exceptions are a) Regulated Mutual Funds as defined in the Mutual Funds Act (as amended); and   b) Private Funds\nas defined in the Private Funds Act (as amended).\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 4 of 11\n\nprovisions as amended, modified, re-enacted, or replaced from time to time.\n\n3.3\nRegulated entities must ensure that services offered to clients are not carried\nout in such a way that compromises the confidentiality, integrity and availability\nof clients\u2019 data or the regulated entities\u2019 systems, where applicable. Regulated\nentities should apply this Rule and consider the corresponding Statement of\nGuidance (\u201cSOG\u201d) \u2013 Cybersecurity for Regulated Entities, where applicable, to\nensure that there is a suitable and robust cybersecurity framework in place.\n\n3.4\nRegulated entities such as Class \u2018B\u2019, \u2018C\u2019 and \u2018D\u2019 insurers that are fully managed\nby a licensed insurance manager are only required to comply with Rule 6.3.\nInsurance\nManagers\nmust\nensure\nthat\nthe\ncybersecurity\nframework\nimplemented in respect of insurers that they manage is commensurate with the\nsize, complexity, structure, nature of business and risk profile of the operations\nof the said insurers and meets their specific needs and risk tolerance.\n\n3.5\nPrivate Trust Companies, as registrants, must consider their cybersecurity risk\nand their risk tolerance; and implement a framework appropriate to meet their\ncybersecurity needs.\n\n4. Definitions\n\n4.1\nThe following definitions are provided for the purpose of this Rule:\n4.1.1 Cyber attack: An attack, via cyberspace, targeting an enterprise\u2019s use\nof cyberspace for the purpose of disrupting, disabling, destroying, or\nmaliciously controlling a computing environment\/infrastructure; or\ndestroying the integrity of the data or stealing controlled information.\n4.1.2 Cyber resilience: The ability of systems and organisations to develop\nand execute long-term strategy to withstand cybersecurity events;\npractically, it is measured by the combination of mean time to failure\nand mean time to recovery.\n4.1.3 Cyber risk: The risk of financial loss, operational disruption, or damage,\nfrom the failure of the digital technologies employed for informational\nand\/or operational functions introduced to a manufacturing system via\nelectronic means from the unauthorised access, use, disclosure,\ndisruption, modification, or destruction of the manufacturing system.\n4.1.4 Cybersecurity: An approach or series of steps to prevent or manage\nthe risk of damage to, unauthorised use of, exploitation of and, as\nneeded, to restore electronic information and communications systems,\nand the information they contain, in order to strengthen the\nconfidentiality, integrity, and availability of these systems.\n4.1.5 Cybersecurity breach: Any unauthorised penetration of the defences2\n\n2 Defences may be internal or external.\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 5 of 11\n\nestablished to protect against cyber risk.\n4.1.6 Cybersecurity framework: A complete set of organisational resources\nincluding policies, staff, processes, practices and technologies used to\nassess and mitigate cyber risks; and respond to and recover from cyber\nattacks.\n4.1.7 Cybersecurity incident: A cybersecurity event that has been\ndetermined to have an impact on the organisation prompting the need\nfor response and recovery.\n4.1.8 Cybersecurity threat: Any circumstance or event with the potential to\nadversely impact organisational operations, organisational assets,\nindividuals, other organisations, or the country through a system via\nunauthorised\naccess,\ndestruction,\ndisclosure,\nmodification\nof\ninformation, and\/or denial of service.\n4.1.9 Cyberspace: A global domain within the information environment\nconsisting of the interdependent network of information systems\ninfrastructures including the internet, telecommunications networks,\ncomputer systems, and embedded processors and controllers.\n4.1.10 Governing body: the Board of Directors where the entity is a\ncorporation, the General Partner where the entity is a partnership, the\nmanager (or equivalent) where the entity is a Limited Liability Company,\nand the Board of Trustees where the entity is a trust business.\n4.1.11 Information technology (\u201cIT\u201d): Any equipment or interconnected\nsystem or subsystem of equipment that is used in the automatic\nacquisition, storage, manipulation, management, movement, control,\ndisplay, switching, interchange, transmission, or reception of data or\ninformation by the executive agency. The term includes computers,\nancillary equipment, software, firmware, and similar procedures,\nservices (including support services), and related resources.\n4.1.12 Information technology risk: The risk of mission or business loss\nresulting from a particular threat source exploiting, or triggering, a\nparticular information technology vulnerability.\n4.1.13 Information system: A discrete set of electronic information resources\norganized for the collection, processing, maintenance, use, sharing,\ndissemination or disposition of electronic information, as well as any\nspecialised system such as industrial\/process controls systems,\ntelephone switching and private branch exchange systems, and\nenvironmental control systems.\n4.1.14 Risk management: The use of structures, processes and people that\nidentify, assess, mitigate, and monitor all internal and external sources\nof risk that could have a material impact on operations.\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 6 of 11\n\n4.1.15 Risk tolerance: An entity\u2019s readiness to bear the risk after risk\ntreatment in order to achieve its objectives.\n4.1.16 Recovery Point Objective: The point in time to which data must be\nrecovered after an outage.\n4.1.17 Recovery Time Objective: The overall length of time an information\nsystem\u2019s components can be in the recovery phase before negatively\nimpacting the organization\u2019s mission or mission\/business processes.\n5. Rules\n\n5.1\nThe Cybersecurity Framework\n5.1.1 Regulated entities must establish, implement, and maintain a\ndocumented cybersecurity framework that is designed to promptly\nidentify, measure, assess, report, monitor and control or minimise\ncybersecurity risks as well as responding to and recovering from\ncybersecurity breaches that could have a material impact on their\noperations.\n5.1.2 The cybersecurity framework of regulated entities must include, but is\nnot be limited to the following:\na)\na well-documented cybersecurity risk management strategy,\napproved by the governing body, which addresses all material\ncybersecurity risks to which the regulated entities are likely to\nbe exposed based on their business activities and use of\ntechnology;\nb)\ncybersecurity and IT security policies and procedures that are\nadequate to identify, assess, mitigate, control, monitor and\nreport on such risks to which regulated entities are exposed;\nc)\nclearly identified managerial responsibilities and controls,\ndesigned to ensure that the policies and procedures established\nfor cybersecurity and risk management are always adhered to;\nand\nd)\nclear, documented, and effective processes for responding to,\ncontaining, and recovering from cyber attacks, cybersecurity\nbreaches and incidents as quickly as possible or within regulated\nentities\u2019 governing body\u2019s approved Recover Point Objective or\nRecovery Time Objective depending on the type of attack or\nincident.\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 7 of 11\n\n5.1.3 Regulated entities must regularly review the emerging (or evolving)\ncybersecurity threats and IT landscape and assess their cybersecurity\nframework to ensure that the framework continues to be appropriate to\nmanage adverse impacts of the cyber risks and IT risks related to the\nregulated entities\u2019 business.\n\n6. Role of the Governing Body\n\n6.1\nRegulated entities\u2019 governing bodies are ultimately responsible for\ncybersecurity and their duties must include, but not be limited to:\na)\napproval of a written cybersecurity risk management strategy\naligned with the overall business strategy and risk tolerance as\nwell as approval of completed cybersecurity risk assessments\nand cybersecurity risk management as part of regulated entities\u2019\noverall risk management strategies and programmes;\nb)\napproval of a comprehensive cybersecurity framework;\nc)\nappropriate oversight of the risk management framework to\nensure that policies and processes are implemented effectively;\nd)\nperiodic review of the cybersecurity framework; and\ne)\napproval of the cybersecurity audit plan; and ensuring that any\nfindings are addressed in a timely manner.\n\n6.2\nGroup and related entities\n6.2.1 The Authority recognises that some regulated entities\u2019 risk management\nforms part of their parent company\u2019s risk management function. In\nthese cases, the Authority does not expect regulated entities to\nduplicate functions that are already carried out by the parent. However,\nregulated entities should assess and document that, an appropriate\ncybersecurity framework is in place on a  group-wide basis and at the\nlegal entity\u2019s level.\n6.2.2 The cybersecurity framework should be implemented on a consolidated\nbasis and must at a minimum cover the requirements noted in this Rule.\n\n6.3\nManaged Entities\n6.3.1 The Authority recognises that certain regulated entities are fully\nmanaged by a licensed service provider. Furthermore, these entities\nmight not develop their own cybersecurity framework but rather rely on\nthe framework of their service provider. Such regulated entities that are\nmanaged by entities licensed by the Authority must make appropriate\nenquiries, through their governing body, to satisfy themselves with the\nlevel of cybersecurity applied by that service provider.\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 8 of 11\n\n6.3.2 Regulated entities, as referred to in 6.3.1:\na)\nare ultimately responsible for their cybersecurity and for\nassessing the service provider(s)\u2019 compliance with this Rule and\nthe related SOG on Cybersecurity for Regulated Entities; and\nb)\nmust satisfy themselves that the cybersecurity framework that\nwill be applied in respect of the services provided to them is\nappropriate for the cybersecurity risks posed to them as a result\nof the use of technology and emerging cybersecurity threats.\n6.3.3 The governing body of a regulated entity referred to in 6.3.1 must\nrequire the service provider to report any cybersecurity related breaches\nthat pertain to the regulated entity. A mechanism must be in place to\nensure that the regulated entities are aware through the governing body\nwhat services are being provided to them by their insurance managers.\n\n6.4\nCybersecurity Awareness, Training and Resources\n\n6.4.1 Regulated entities must establish a comprehensive training and awareness\nprogramme3 relating to cybersecurity and cyber-resilience that is endorsed\nby its governing body and\/or senior management. It should be reviewed\nand updated to ensure that the contents of the programme remain current\nand relevant by taking into consideration the evolving nature of technology\nas well as emerging risks, including risk areas for the regulated entity.\n\n6.4.2 Regulated entities must ensure that they have sufficient and suitable\npersonnel to maintain their cybersecurity framework, commensurate with\nthe size, complexity, structure, nature of business and risk profile of its\noperations.\n\n6.5\nManagement of Outsourcing Risks\n\n6.5.1 Regulated entities that outsource IT functions either externally to third\nparties or internally to affiliated entities:\na)\nremain ultimately responsible for outsourced IT functions and\ntheir cybersecurity;\nb)\nmust ensure that they assess the service provider(s)\u2019 compliance\nwith this Rule and related SOG on Cybersecurity for Regulated\nEntities and the SOG - Outsourcing: Regulated Entities; and\nc)\nmust have oversight and clear accountability for all outsourced\nfunctions as if these functions were performed by the regulated\nentities themselves and subject to the normal standards of their\n\n3 Training seeks to teach skills, which allow a person to perform a specific function, while awareness seeks to focus\nan individual\u2019s attention on an issue or set of issues. (Source: NIST Special Publication 800-16)\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 9 of 11\n\ncybersecurity and IT security framework.\n\n6.5.2 Regulated entities should also make considerations for outsourcing\narrangements that go beyond IT-related functions that may also present a\ncybersecurity risk.\n\n7. Data Protection\n\n7.1\nRegulated entities must demonstrate that data protection is part of their\nstrategy and cybersecurity framework taking into consideration the provisions\nof the Data Protection Act and the guidance issued by the Cayman Islands\nOmbudsman on data protection.\n\n8. Notification Requirements\n\n8.1\nRegulated entities must immediately notify the Authority in writing of an\nincident when it is deemed to have a material impact or has the potential to\nbecome a material incident, and no later than 72 hours following the discovery\nof said incident.\n\n8.2\nRegulated entities should define incident criticality in their incident\nmanagement framework. When in doubt about the level of seriousness of an\nevent, regulated entities should consult the Authority. Incidents should be\nreported to the Authority if they fall under one or more of the following:\n\na)\nMaterial impact to the regulated entity\u2019s internal operations.\nb)\nThe event results in the unauthorised dissemination of any personal data\neither internally or externally.\nc)\nSignificant operational impact to internal users that is material to\ncustomers or business operations.\nd)\nExtended disruptions to critical business systems or internal operations.\ne)\nNumber of external customers impacted is significant or growing.\nf)\nIf determined that there is potential reputational impact, either to the\nregulated entity or the Cayman Islands as a whole, notification to the\nAuthority must occur immediately if there is any risk of premature public\ndisclosure.\ng)\nAny loss of any card payment information, beneficial owner details, or\nany personally identifiable information.\nh)\nLoss or exposure of any data in violation of any applicable data\nprotection Acts and other regulatory requirements both foreign and\ndomestic.\n\n8.3\nFor regulated entities that have risk ratings in respect of their cyber risks, the\nAuthority expects that the required notification includes ratings that correspond\nto a material incident.\n\n8.4\nRegulated entities must notify affected persons if a cyber attack results in the\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 10 of 11\n\nbreach of non-public information or disrupts a service that is utilised including\ninformation on the action taken to contain (as necessary), remedy and recover\nfrom the breach.\n\n9. Enforcement\n\n9.1\nWhenever a breach of these Rules occurs, the Authority\u2019s policies and\nprocedures, as contained in its Enforcement Manual, will apply, in addition to\nany other powers provided in the regulatory Acts and the MAA.\n\nRule \u2013 Cybersecurity for Regulated Entities\n_____________________________________________________________________________________________\n\n                         Page 11 of 11","akn_extracted_at":"2026-07-18 12:34:15.704057+00","cms_id":"2020-0095","law_type":"subordinate","year":"2020","number":"95","title":"Rule \u2013 Cybersecurity for Regulated Entities","status":"in_force"},"provenance":{"files":[{"file_id":"5171","expr_id":"276","kind":"akn_xml","filename":"2020-0095_SL 38 of 2023.akn.xml","source_url":null,"storage_path":"\/Users\/q\/kyleg-data\/working\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.akn.xml","content_md5":"ea3b4c26fee5a41f20c45e637c9c0517","byte_size":"21571","http_last_modified":null,"fetched_at":"2026-07-18 12:34:15.769759+00"},{"file_id":"551","expr_id":"276","kind":"pristine_pdf","filename":"2020-0095_SL 38 of 2023.pdf","source_url":"\/cms\/images\/LEGISLATION\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.pdf","storage_path":"\/Users\/q\/kyleg-data\/pristine\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.pdf","content_md5":"881464b6181868a3f843f85c7214d28f","byte_size":"454750","http_last_modified":null,"fetched_at":"2026-06-21 23:09:36.098187+00"},{"file_id":"552","expr_id":"276","kind":"working_pdf","filename":"2020-0095_SL 38 of 2023.pdf","source_url":"\/cms\/images\/LEGISLATION\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.pdf","storage_path":"\/Users\/q\/kyleg-data\/working\/SUBORDINATE\/2020\/2020-0095\/2020-0095_SL 38 of 2023.pdf","content_md5":"881464b6181868a3f843f85c7214d28f","byte_size":"454750","http_last_modified":null,"fetched_at":"2026-06-21 23:09:36.098187+00"}],"paragraph_count":10,"latest_history":{"history_id":"270410","change_type":"UPDATE","changed_at":"2026-07-18 00:00:00+00","change_source":"MIGRATION_027","change_reason":"CMS-id-collision audit 2026-07-18: title corrected from the document's own PDF and\/or the (law_type, cms_id)-keyed official legislation.gov.ky listing."}},"quality":{"expr_id":"276","doc_id":"276","quality_state":"known_issue","quality_score":"71","needs_human_review":"t","deterministic_categories":"{page_header_footer_noise,title_mismatch}","llm_categories":"{truncated_text,other}","repair_actions":"{manual_review,reextract_full_text,strip_page_furniture,verify_title_metadata}","finding_severity_counts":"{\"low\": 1, \"medium\": 1}","finding_summary":"Sample appears truncated; full document review needed to confirm completeness of legal content.","assessed_at":"2026-06-22 15:29:46.143858+00","updated_at":"2026-06-22 15:29:46.143858+00"}}