Featured Product

    IA of Hong Kong Publishes Cyber-Security Guideline for Insurers

    June 28, 2019

    IA of Hong Kong published the guideline GL20 on cyber-security for authorized insurers. The guideline sets the minimum standard for cyber-security that authorized insurers are expected to have in place and the general guiding principles which the IA uses in assessing the effectiveness of the cyber-security framework of an insurer. The guideline applies to all authorized insurers, except for captive insurers and marine mutual insurers, in relation to the insurance business they conduct in, or from, Hong Kong. GL20 shall take effect on January 01, 2020.

    Cyber risk is one of the most significant operational risks that insurers face, particularly with regard to the business operations they conduct digitally and online. Cyber-security incidents can result in financial loss, business disruption, damage to reputation, and other adverse consequences to an insurer. Accordingly, this guideline requires authorized insurers to put in place resilient cyber-security frameworks to protect their business data and the personal data of their existing or potential policyholders and to ensure continuity of their business operations. The guideline stipulates that authorized insurers should establish and maintain a cyber-security strategy and framework tailored to mitigate relevant cyber risks that are commensurate with the nature, size, and complexity of their business. The cyber-security strategy and framework should be endorsed by the Board of the insurer. Insurers should also develop a cyber-security incident response plan, which covers scenarios of cyber-security incidents and corresponding contingency strategies to maintain and restore critical functions and essential activities in such scenarios.

     

    Related Links

    Keywords: Asia Pacific, Hong Kong, Insurance, Cyber Risk, Guideline, Cyber Guidance, IA

    Related Articles
    News

    EU Agencies Update LCR Rule and Macro-Prudential Policy Recommendation

    The European Commission (EC) published the Delegated Regulation 2022/786 with regard to the liquidity coverage requirements for credit institutions under the Capital Requirements Regulation (CRR).

    May 23, 2022 WebPage Regulatory News
    News

    EBA Publishes Regulatory Standards to Identify Shadow Banking Entities

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying the criteria to identify shadow banking entities for the purposes of reporting large exposures.

    May 23, 2022 WebPage Regulatory News
    News

    EIOPA Examines Physical Climate Risk Exposure, SII Non-Compliance

    The European Insurance and Occupational Pensions Authority (EIOPA) published a report assessing insurers' exposure to physical climate change risks

    May 20, 2022 WebPage Regulatory News
    News

    NGFS Report Explores Quantification of Climate Risk Differentials

    The Network for Greening the Financial System (NGFS) published two reports to aid central banks and regulators in their oversight of the financial sector and in their central bank operations

    May 19, 2022 WebPage Regulatory News
    News

    EC Publishes Results on Review of Web Accessibility Directive

    The European Commission (EC) published the results of a public consultation, held in October 2021, on the review of the Web Accessibility Directive.

    May 19, 2022 WebPage Regulatory News
    News

    MAS Consults on Adjustment Spreads for Conversion of SOR Contracts

    The Monetary Authority of Singapore (MAS) and the SC-STS are jointly consulting, until June 10, 2022, on setting adjustment spreads for the conversion of legacy SOR contracts to SORA reference rate.

    May 18, 2022 WebPage Regulatory News
    News

    OSFI Discusses Benchmark Rate Transition, Sets Out Work Priorities

    The Office of the Superintendent of Financial Institutions (OSFI) published the strategic plan for 2022-2025 and the departmental plan for 2022-23.

    May 17, 2022 WebPage Regulatory News
    News

    EBA Proposes Standards to Support Secondary NPL Markets

    The European Banking Authority (EBA) is consulting, until August 31, 2022, on the draft implementing technical standards specifying requirements for the information that sellers of non-performing loans (NPLs) shall provide to prospective buyers.

    May 17, 2022 WebPage Regulatory News
    News

    EU Confirms Agreement on Rules on Cybersecurity and Banking Resolution

    The European Council and the Parliament reached an agreement on the revised Directive on security of network and information systems (NIS2 Directive).

    May 13, 2022 WebPage Regulatory News
    News

    EBA Issues Standards for Crowdfunding Service Providers Under ECSPR

    The European Banking Authority (EBA) published the final draft regulatory technical standards specifying information that crowdfunding service providers shall provide to investors on the calculation of credit scores and prices of crowdfunding offers.

    May 13, 2022 WebPage Regulatory News
    RESULTS 1 - 10 OF 8206