2025-07-07 | 36239

Added · Updated

Mandatory Cybersecurity Incident Reporting

The Central Bank of Trinidad and Tobago mandates that regulated financial institutions report material cybersecurity incidents within 24 hours of awareness and submit a complete report within 72 hours. This requirement applies to entities licensed under the Financial Institutions Act, Insurance Act, Exchange Control Act, and E-Money Issuer Order, covering incidents that disrupt financial systems, compromise data, or reach high severity levels. Institutions must submit reports via email to the specified address and provide regular updates until resolution.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Click to view full text

More like this from CBTT

We email you every new CBTT publication the day it's published.

Topics
Share