2025-07-07 | 36239Added · Updated
The Central Bank of Trinidad and Tobago mandates that regulated financial institutions report material cybersecurity incidents within 24 hours of awareness and submit a complete report within 72 hours. This requirement applies to entities licensed under the Financial Institutions Act, Insurance Act, Exchange Control Act, and E-Money Issuer Order, covering incidents that disrupt financial systems, compromise data, or reach high severity levels. Institutions must submit reports via email to the specified address and provide regular updates until resolution.
Eric Williams Plaza, Independence Square, Port of Spain, Trinidad and Tobago Postal Address: P.O. Box 1250 Telephone: (868) 621-CBTT (2288), 235-CBTT (2288) Fax: (868) 612-6396 E-Mail Address: info@central-bank.org.tt Website: www.central-bank.org.tt
February 5, 2025 CIRCULAR LETTER TO ALL INSTITUTIONS: LICENSED OR ISSUED A FINANCIAL HOLDING COMPANY PERMIT UNDER THE FINANCIAL INSTITUTIONS ACT, 2008 REGISTERED UNDER THE INSURANCE ACT, 2018 LICENSED UNDER THE EXCHANGE CONTROL ACT CHAP 79:50 PAYMENTS SYSTEM OPERATORS OR PAYMENT SERVICES PROVIDERS PURSUANT TO THE FIA OR CBA E-MONEY ISSUERS REGISTERED UNDER THE E-MONEY ISSUER ORDER, 2020 REF: CB-OIFI-399/2025 MANDATORY CYBERSECURITY INCIDENT REPORTING Due to the increasing threats to cybersecurity and the critical importance of maintaining the integrity and trustworthiness of our financial systems, the Central Bank of regulated financial institutions of the requirement to report any cybersecurity incidents within twenty-four (24) hours of becoming aware of them. This requirement pertains to incidents that are deemed reportable under our regulatory framework, as noted As outlined in Appendix II Instructions for Completing the Cybersecurity Incident Form Instructions ), regulated financial institutions are required to report promptly any incidents to the Central Bank that may have one or more of the following characteristics of a material nature, as follows: -
Circular Letter to All Institutions: Licensed or issued a Financial Holding Company Permit under the FIA, 2008 Registered under the IA, 2018; Licensed Under the Exchange Control Act Chap 79:50 Payments System Operators or Payment Services Providers pursuant to the FIA or CBA E-Money Issuers Registered under the E-Money Issuer Order, 2020 February 5, 2025 2 6. Impacts a number of external customers and/or negative reputational impact is imminent (e.g., public and/or media disclosure); 7. An incident assessed by the company to be of high or critical severity or ranked Priority/Severity/Tier 1 or 2 based on the company's internal assessment; and 8. Incidents that breach internal risk appetite or thresholds as per the cybersecurity strategy or policy. Examples of incidents that the Central Bank would typically expect financial institutions to report include, but are not limited to: a. Cyberattacks which disrupt the successful delivery of financial services such as:
Circular Letter to All Institutions: Licensed or issued a Financial Holding Company Permit under the FIA, 2008 Registered under the IA, 2018; Licensed Under the Exchange Control Act Chap 79:50 Payments System Operators or Payment Services Providers pursuant to the FIA or CBA E-Money Issuers Registered under the E-Money Issuer Order, 2020 February 5, 2025 3 The Central Bank has established the following timelines to ensure the prompt and structured handling of cybersecurity incidents: Activity/Report Submission Timeframe Initial Notification Within 24 hours of becoming aware of a cyber-incident Complete Cyber Incident Reporting Within 72 hours of the incident Subsequent Reporting Regular updates (e.g., daily) as new information becomes available Ongoing situation updates until incident containment/resolution Post-incident review and lessons learned report following incident closure Note: Where specific details are unavailable at the time of the initial report, the institution must: Indicate "information not yet available"; Provide best estimates and all other available details; and Include expectations of when additional information will be available To ensure a streamlined reporting process, financial institutions should submit a Cybersecurity Incident Report Form to cyberincident@central-bank.org.tt, sending a copy to their designated Relationship Officer. The Guideline, the Cyber Incident Reporting Form, and the Instructions can be https://www.central-bank.org.tt/corefunctions/supervision/cybersecurity. Please be guided accordingly and kindly acknowledge receipt of this letter electronically. We look forward to your cooperation in ensuring the timely reporting of any material cybersecurity incidents. Yours sincerely Patrick Solomon INSPECTOR OF FINANCIAL INSTITUTIONS
More like this from CBTT
We email you every new CBTT publication the day it's published.