On 22 January 2024, the Bermuda Monetary Authority’s ( BMA ) 2024 Business Plan confirmed its continuing focus on cyber risk supervision, its interest in considering how AI will impact financial services, and its commitment to its IT Strategy: Vision 2025.

As well, the BMA has made clear the real connection that exists between IT and cyber operational risk, outsourcing transactions, business continuity planning and data protection across the critical infrastructure that the BMA regulates.

Recently, the Computer Misuse Act 2024 was introduced by the Bermuda Government to provide enhanced legal weapons to fight cybercrime. Heavily based on UK law for those matters, the new Act replaces Bermuda’s previous 1996 statute of the same name and is intended to reflect international best practices to address both computing innovations and to greatly enhance penalties.

However, our newest Computer Misuse Act 2024 may not be the final word on computer misuse criminal law reform given the many law reform recommendations that are advanced in UK’s Criminal Law Reform Network’s 2020 report titled “Reforming The Computer Misuse Act 1990”. There may be more to come on that front.

On 31 May, Bermuda’s new Cybersecurity Act 2024 was passed by the House to address the need for the regulatory oversight across numerous essential services and critical infrastructure in Bermuda that the Government will more specifically identify in the weeks ahead.

In passing the Cybersecurity Act, the Government has decided to create a new regulatory regime under Ministerial oversight rather than simply directing existing regulators, like the Bermuda Health Council and the Regulatory Authority, to implement their own models of proportional risk based IT and cybersecurity regulation, which would likely follow the BMA’s very successful formulation, implementation and management of such regulations in recent years.

The end result, however, is expected to be very similar across all essential services and their regulators, even if different proportional risk based security standards, practices and governance requirements are stipulated under that Act. That Act’s implementation process, including the introduction of all such regulatory standards in the weeks to come, is expected to include diligent industry consultation and the responsive consideration by Government toward improving that Act’s relevance and effectiveness.

Finally, as many have been following, Bermuda’s Personal Information Protection Act 2016 ( PIPA ) will come into full force at the end of this year. Indeed, PIPA also includes laws that require IT and cybersecurity safeguards and addresses third party services such as outsourcing, the transfer of personal information overseas, and related data protection duties and responsibilities.

There is no question that the legal landscape of IT and cybersecurity in Bermuda is undergoing transformational change in all of its facets, from the fundamental standards of diligent corporate governance to all of the commercial IT service and outsourcing agreements that every critical infrastructure participant enters into with their affiliates and commercial service providers.

Share
X.com LinkedIn Email Save as PDF
More Publications
Appleby-Website-Insurance-and-Reinsurance
24 Mar 2025

Bridging the $51 trillion gap: asset-intensive reinsurance in Bermuda

In this article we examine the rise and regulatory landscape of Asset-Intensive Reinsurance (AIR) in...

Appleby-Website-Privacy-and-Data-Protection
20 Mar 2025

PIPA Guidance on Financial Services (Bermuda)

This month, the Privacy Commissioner of Bermuda released his Financial Services Guidance Notes: Fin...

IWD Grid Capture
8 Mar 2025

International Women’s Day 2025 roundtable: Rights. Equality. Empowerment.

As we recognise International Women’s Day 2025, we are reminded that gender equality is not just a...

Corporate
28 Feb 2025

Bermuda Monetary Authority’s proposed resilience code

The Bermuda Monetary Authority, which well understands the operational risks associated with financi...

Dispute Resolution
25 Feb 2025

Bermuda: An Introduction to Dispute Resolution 2025

The stable, competitive regulatory and legal regime in Bermuda continues to ensure its place as a hu...

Appleby-Website-Banking-and-Financial-Services
19 Feb 2025

Recent Updates on BVI, Cayman and Bermuda laws

Entities incorporated or registered in the British Virgin Islands (BVI), Cayman Islands and Bermuda ...

Appleby-Website-Employment-and-Immigration
18 Feb 2025

Fostering Respect: the Importance of Bullying and Sexual Harassment Policies in Bermuda (Part 2)

Under the Employment Act 2000 (EA), it is a requirement for an employer to not only have a compliant...

Technology and Innovation
31 Jan 2025

Bermuda Monetary Authority’s 2025 Tech Commitment

A focus on the crucial and enabling role that technology plays across all financial service sectors ...

Fund Finance
29 Jan 2025

Fund Finance Laws and Regulations 2025 – Bermuda

The Bermuda fund industry sees investment predominantly from North America and Europe, and therefore...

Employment-and-Immigration
23 Jan 2025

Fostering Respect: the Importance of Bullying and Sexual Harassment Policies in Bermuda (Part 1)

Under the Employment Act 2000 (EA), it is a requirement for an employer to not only have a compliant...