Cybersecurity ยท Bermuda
Cybersecurity law & regulation in Bermuda (2026)
Bermuda shaded by its cybersecurity status
Cybersecurity in Bermuda: sectoral rules.
FrameworkCybersecurity Act 2024 (assented 24 June 2024, commencement staged); Computer Misuse Act 2024; BMA Insurance Sector Operational Cyber Risk Management Code of Conduct (2020); Personal Information Protection Act 2016 (PIPA, in force 1 January 2025). Oversight split between the Minister of National Security / Cybersecurity Advisory Board (CNII), the Bermuda Monetary Authority (financial sector), and the Privacy Commissioner (PrivCom) for personal-data breaches.
Bermuda does not yet operate a single, cross-sector NIS2-style cybersecurity regime. The overarching Cybersecurity Act 2024 received Royal Assent on 24 June 2024 and creates a Critical National Information Infrastructure (CNII) framework with designated sector enforcement authorities, but it is being brought into force gradually and its main operational duties depend on Ministerial commencement and CNII designations. In practice, cyber obligations today are sectoral: the Bermuda Monetary Authority's binding Operational Cyber Risk Management Code for insurers, PIPA's breach-notification duties on all organisations handling personal information, and criminal offences under the Computer Misuse Act 2024.
Key points
Passed by Parliament on 31 May 2024 and given Royal Assent on 24 June 2024. It empowers the Minister of National Security, advised by a Cybersecurity Advisory Board, to designate Critical National Information Infrastructure and appoint sector 'enforcement authorities' (expected to include the Regulatory Authority for telecoms/electricity, the Bermuda Health Council, and the Bermuda Airport Authority). No general commencement date has been gazetted, so obligations bite as sectors are brought in.
The Bermuda Monetary Authority's Insurance Sector Operational Cyber Risk Management Code of Conduct came into force on 1 January 2021 and applies to all registered insurers, insurance managers, agents, brokers and marketplace providers. Boards must approve a cyber-risk policy annually, and 'significant cyber reporting events' must be notified to the BMA within 72 hours, with a detailed incident report within 14 days.
The Personal Information Protection Act 2016 came fully into force on 1 January 2025 and is enforced by the Office of the Privacy Commissioner (PrivCom). Organisations must notify PrivCom and affected individuals without undue delay of any personal-information breach likely to adversely affect an individual; PrivCom publishes quarterly breach statistics.
The Computer Misuse Act 2024 was passed by the House of Assembly on 17 May 2024, replacing the 1996 statute. Modelled on UK law and aligned to the Council of Europe (Budapest) Convention on Cybercrime, it recasts and enhances criminal offences for unauthorised access to, modification of, and interference with computer systems.
The 2024 cybersecurity legislative package was driven by lessons learned from the September 2023 ransomware-style attack on Government of Bermuda systems, which prompted the creation of the Cybersecurity Advisory Board and the acceleration of the CNII framework.
Once the Cybersecurity Act's CNII provisions are operational, the Regulatory Authority (telecoms and electricity), the Bermuda Health Council (healthcare), and the Bermuda Airport Authority (aviation) are expected to be the primary sector 'enforcement authorities' setting cyber standards and receiving incident reports for their respective CNII operators.
Timeline - major decisions & events
Bermuda's comprehensive data-protection law became fully operative, obliging all in-scope organisations to appoint privacy officers, implement security safeguards, and report personal-data breaches. Its security and breach-notification provisions form a core pillar of Bermuda's cybersecurity obligations alongside the BMA codes and the Cybersecurity Act.
Office of the Privacy Commissioner for Bermuda (PrivCom) โIssued by the BMA under the Digital Asset Business Act 2018, the Code required all licensed digital-asset businesses to be fully compliant by this date with a proportionate technology/cyber-risk programme and board-level cyber governance. It extended sector-specific cyber rules to crypto and DLT firms.
Bermuda Monetary Authority โPassed by the Legislature on 31 May 2024, the Act creates a national regime overseen by a single Minister to set cybersecurity standards for Critical National Information Infrastructure (CNII) across health, telecoms, emergency services and energy, and establishes a Cybersecurity Advisory Board. It marks Bermuda's first economy-wide critical-infrastructure cyber law beyond the financial sector.
Parliament of Bermuda โThe Government announced the firm date for PIPA to come fully into force, giving organisations an ~18-month preparation window to build data-security and breach-reporting compliance programmes. It ended years of uncertainty over when Bermuda's data-protection regime would actually bite.
Office of the Privacy Commissioner for Bermuda (PrivCom) โBanks, deposit companies, trust companies, investment businesses, fund administrators, money service businesses and corporate service providers had to be fully compliant with the BMA's operational cyber-risk code by this date. It brought most of Bermuda's BMA-regulated financial entities under formal cyber-governance and 72-hour incident-reporting duties.
Bermuda Monetary Authority โThe BMA extended its cyber-risk framework beyond insurance to corporate service providers, trust companies, money service businesses, investment businesses and fund administrators (and, via amendments to the Banks and Deposit Companies Act 1999, to banks). It standardised board oversight, a CISO function, and incident reporting across the wider financial sector.
Bermuda Monetary Authority โThe first BMA cyber code took effect, with insurers, insurance managers and intermediaries required to comply by 31 December 2021. It mandated board-approved cyber-risk policies, a CISO role, and notification to the BMA within 72 hours of a confirmed cyber event, the template for all later sector codes.
Bermuda Monetary Authority โBermuda's earliest digital-economy statute legally facilitated e-commerce and included EU-style data-protection principles (never fully activated), laying the conceptual groundwork for later information-security and privacy regulation. It remains the historical starting point for Bermuda's IT and data-handling law.
Appleby โBermuda - other topics
Cybersecurity in other countries
Last verified 8/12/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ