2023-09-23 | 24007Added · Updated
The Central Bank of Trinidad and Tobago requires authorized financial institutions to conduct annual self-assessments against cybersecurity guidelines and submit them by March 31st of the following year, accompanied by action plans for any material deficiencies. Institutions must establish governance, risk management, training, business continuity, testing, and incident management frameworks, with specific mandates such as deploying multi-factor authentication for customer access and conducting regular vulnerability and penetration testing. Material cybersecurity incidents must be reported to the Central Bank within 24 hours of awareness, with a detailed template submission required within 72 hours, followed by regular updates until resolution.