2023-09-23 | 24008Added · Updated
Regulated financial institutions must alert the Central Bank of any cybersecurity incident within 24 hours of awareness and submit a completed reporting template within 72 hours. Reportable incidents are defined by material impacts on the financial system, critical infrastructure, data confidentiality, or high internal severity levels. Companies are required to provide regular updates until the incident is resolved and submit a post-incident review upon closure. Failure to comply with these notification timelines and requirements may result in enhanced supervisory oversight or compliance directions.
CBTT published 6 documents in the last 30 days — get each new one by email the day it lands.
These instructions are reproduced from Appendix II of the Cybersecurity Best Practices Guideline INSTRUCTIONS FOR COMPLETING THE CYBERSECURITY INCIDENT REPORTING FORM September 2023
Instructions for Completing the Cybersecurity Incident Reporting Form INSTRUCTIONS A. Purpose
Instructions for Completing the Cybersecurity Incident Reporting Form
C. Initial Notification Requirements
Read the rest free
Source: Central Bank of Trinidad and Tobago — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBTT
CBTT published 6 documents in the last 30 days. We email you each new one the day it's published.