2025-07-07 | 36239

Added · Updated

Mandatory Cybersecurity Incident Reporting

The Central Bank of Trinidad and Tobago mandates that regulated financial institutions report material cybersecurity incidents within 24 hours of awareness and submit a complete report within 72 hours. This requirement applies to entities licensed under the Financial Institutions Act, Insurance Act, Exchange Control Act, and E-Money Issuer Order, covering incidents that disrupt financial systems, compromise data, or reach high severity levels. Institutions must submit reports via email to the specified address and provide regular updates until resolution.

Central Bank of Trinidad and Tobago logo

Trinidad and Tobago

Central Bank of Trinidad and Tobago

Click to view thumbnail

Eric Williams Plaza, Independence Square, Port of Spain, Trinidad and Tobago Postal Address: P.O. Box 1250 Telephone: (868) 621-CBTT (2288), 235-CBTT (2288) Fax: (868) 612-6396 E-Mail Address: info@central-bank.org.tt Website: www.central-bank.org.tt

February 5, 2025 CIRCULAR LETTER TO ALL INSTITUTIONS: LICENSED OR ISSUED A FINANCIAL HOLDING COMPANY PERMIT UNDER THE FINANCIAL INSTITUTIONS ACT, 2008 REGISTERED UNDER THE INSURANCE ACT, 2018 LICENSED UNDER THE EXCHANGE CONTROL ACT CHAP 79:50 PAYMENTS SYSTEM OPERATORS OR PAYMENT SERVICES PROVIDERS PURSUANT TO THE FIA OR CBA E-MONEY ISSUERS REGISTERED UNDER THE E-MONEY ISSUER ORDER, 2020 REF: CB-OIFI-399/2025 MANDATORY CYBERSECURITY INCIDENT REPORTING Due to the increasing threats to cybersecurity and the critical importance of maintaining the integrity and trustworthiness of our financial systems, the Central Bank of regulated financial institutions of the requirement to report any cybersecurity incidents within twenty-four (24) hours of becoming aware of them. This requirement pertains to incidents that are deemed reportable under our regulatory framework, as noted As outlined in Appendix II Instructions for Completing the Cybersecurity Incident Form Instructions ), regulated financial institutions are required to report promptly any incidents to the Central Bank that may have one or more of the following characteristics of a material nature, as follows: -

  1. Impact has potential consequences for other companies or the domestic financial system;
  2. Impacts the company's systems affecting financial market settlement, confirmations or payments (e.g., Financial Market Infrastructure), or impact to payment services;
  3. Impacts operations, infrastructure, data and/or systems, including but not limited to the confidentiality, integrity or availability of customer information;
  4. Disrupts business systems and/or operations, including but not limited to utility or data centre outages or loss or degradation of connectivity;
  5. Causes the disaster recovery teams or plans to be activated or a disaster declaration has been made by a third-party vendor that impacts the company;

Circular Letter to All Institutions: Licensed or issued a Financial Holding Company Permit under the FIA, 2008 Registered under the IA, 2018; Licensed Under the Exchange Control Act Chap 79:50 Payments System Operators or Payment Services Providers pursuant to the FIA or CBA E-Money Issuers Registered under the E-Money Issuer Order, 2020 February 5, 2025 2 6. Impacts a number of external customers and/or negative reputational impact is imminent (e.g., public and/or media disclosure); 7. An incident assessed by the company to be of high or critical severity or ranked Priority/Severity/Tier 1 or 2 based on the company's internal assessment; and 8. Incidents that breach internal risk appetite or thresholds as per the cybersecurity strategy or policy. Examples of incidents that the Central Bank would typically expect financial institutions to report include, but are not limited to: a. Cyberattacks which disrupt the successful delivery of financial services such as:

  1. A large-scale distributed denial of service ( DDOS ) attack on a cloud service provider, or other critical third-party service provider; and
  2. Social engineering (via email, social media, phone call, text message, etc.) leading to unauthorised wire transfers or electronic card purchases, the theft of customer deposits, or the loss of sensitive corporate or customer data, compromising its confidentiality. b. Process failures and/or System Update failures which significantly disrupt the delivery of financial services, such as:
  3. Failed batch processing preventing mass salary or pension payments;
  4. Card payment processing delays affecting merchant transactions;
  5. Application or database upgrades that corrupt customer records or monthly statements; and
  6. Mobile app updates that cause user authentication issues or inadvertently expose customer data. c. Infrastructure problems, including extended power outages or infrastructure damage from extreme weather, such as:
  7. Flooding affecting backup power systems, leading to power failures at multiple locations; and
  8. Fibre optic cable damage adversely disrupting online services. For incidents that do not align with or contain the specific criteria or examples listed above, or when a company is uncertain, notification to the Central Bank is encouraged. Institutions should therefore institute adequate policies, procedures and processes to identify and report a material cybersecurity incident in a timely manner.

Circular Letter to All Institutions: Licensed or issued a Financial Holding Company Permit under the FIA, 2008 Registered under the IA, 2018; Licensed Under the Exchange Control Act Chap 79:50 Payments System Operators or Payment Services Providers pursuant to the FIA or CBA E-Money Issuers Registered under the E-Money Issuer Order, 2020 February 5, 2025 3 The Central Bank has established the following timelines to ensure the prompt and structured handling of cybersecurity incidents: Activity/Report Submission Timeframe Initial Notification Within 24 hours of becoming aware of a cyber-incident Complete Cyber Incident Reporting Within 72 hours of the incident Subsequent Reporting Regular updates (e.g., daily) as new information becomes available Ongoing situation updates until incident containment/resolution Post-incident review and lessons learned report following incident closure Note: Where specific details are unavailable at the time of the initial report, the institution must: Indicate "information not yet available"; Provide best estimates and all other available details; and Include expectations of when additional information will be available To ensure a streamlined reporting process, financial institutions should submit a Cybersecurity Incident Report Form to cyberincident@central-bank.org.tt, sending a copy to their designated Relationship Officer. The Guideline, the Cyber Incident Reporting Form, and the Instructions can be https://www.central-bank.org.tt/core￾functions/supervision/cybersecurity. Please be guided accordingly and kindly acknowledge receipt of this letter electronically. We look forward to your cooperation in ensuring the timely reporting of any material cybersecurity incidents. Yours sincerely Patrick Solomon INSPECTOR OF FINANCIAL INSTITUTIONS

More like this from CBTT

We email you every new CBTT publication the day it's published.

Topics
Share