On 22 January 2024, the Bermuda Monetary Authority’s ( BMA ) 2024 Business Plan confirmed its continuing focus on cyber risk supervision, its interest in considering how AI will impact financial services, and its commitment to its IT Strategy: Vision 2025.

As well, the BMA has made clear the real connection that exists between IT and cyber operational risk, outsourcing transactions, business continuity planning and data protection across the critical infrastructure that the BMA regulates.

Recently, the Computer Misuse Act 2024 was introduced by the Bermuda Government to provide enhanced legal weapons to fight cybercrime. Heavily based on UK law for those matters, the new Act replaces Bermuda’s previous 1996 statute of the same name and is intended to reflect international best practices to address both computing innovations and to greatly enhance penalties.

However, our newest Computer Misuse Act 2024 may not be the final word on computer misuse criminal law reform given the many law reform recommendations that are advanced in UK’s Criminal Law Reform Network’s 2020 report titled “Reforming The Computer Misuse Act 1990”. There may be more to come on that front.

On 31 May, Bermuda’s new Cybersecurity Act 2024 was passed by the House to address the need for the regulatory oversight across numerous essential services and critical infrastructure in Bermuda that the Government will more specifically identify in the weeks ahead.

In passing the Cybersecurity Act, the Government has decided to create a new regulatory regime under Ministerial oversight rather than simply directing existing regulators, like the Bermuda Health Council and the Regulatory Authority, to implement their own models of proportional risk based IT and cybersecurity regulation, which would likely follow the BMA’s very successful formulation, implementation and management of such regulations in recent years.

The end result, however, is expected to be very similar across all essential services and their regulators, even if different proportional risk based security standards, practices and governance requirements are stipulated under that Act. That Act’s implementation process, including the introduction of all such regulatory standards in the weeks to come, is expected to include diligent industry consultation and the responsive consideration by Government toward improving that Act’s relevance and effectiveness.

Finally, as many have been following, Bermuda’s Personal Information Protection Act 2016 ( PIPA ) will come into full force at the end of this year. Indeed, PIPA also includes laws that require IT and cybersecurity safeguards and addresses third party services such as outsourcing, the transfer of personal information overseas, and related data protection duties and responsibilities.

There is no question that the legal landscape of IT and cybersecurity in Bermuda is undergoing transformational change in all of its facets, from the fundamental standards of diligent corporate governance to all of the commercial IT service and outsourcing agreements that every critical infrastructure participant enters into with their affiliates and commercial service providers.

Share
X.com LinkedIn Email Save as PDF
More Publications
Appleby-Website-Privacy-and-Data-Protection
14 Apr 2025

M&A transactions under PIPA (Bermuda)

Mergers and business acquisitions are among the many different types of business transactions that r...

Appleby-Website-Insurance-and-Reinsurance
1 Apr 2025

Bermuda: With everything growing, all of the ILS world will rise together

It’s been an exceptionally busy and record start to the year for the catastrophe bond sector, and ...

Appleby-Website-Employment-and-Immigration
27 Mar 2025

Entering and Exiting Bermuda for Visa-Controlled Nationals

As it stands, with direct commercial flights to and from Bermuda only going from the United Kingdom,...

Appleby-Website-Corporate-Practice
27 Mar 2025

How foreign companies become Bermuda companies

Bermuda, renowned as a global business hub, offers a robust legal and regulatory framework that attr...

Appleby-Website-Insurance-and-Reinsurance
24 Mar 2025

Bridging the USD51 trillion gap: asset-intensive reinsurance in Bermuda

In this article we examine the rise and regulatory landscape of Asset-Intensive Reinsurance (AIR) in...

Appleby-Website-Privacy-and-Data-Protection
20 Mar 2025

PIPA Guidance on Financial Services (Bermuda)

This month, the Privacy Commissioner of Bermuda released his Financial Services Guidance Notes: Fin...

IWD Grid Capture
8 Mar 2025

International Women’s Day 2025 roundtable: Rights. Equality. Empowerment.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a...

Corporate
28 Feb 2025

Bermuda Monetary Authority’s proposed resilience code

The Bermuda Monetary Authority, which well understands the operational risks associated with financi...

Dispute Resolution
25 Feb 2025

Bermuda: An Introduction to Dispute Resolution 2025

The stable, competitive regulatory and legal regime in Bermuda continues to ensure its place as a hu...

Appleby-Website-Banking-and-Financial-Services
19 Feb 2025

Recent Updates on BVI, Cayman and Bermuda laws

Entities incorporated or registered in the British Virgin Islands (BVI), Cayman Islands and Bermuda ...