Skip to content
World Watch/Cayman Islands/Cybersecurity

Cybersecurity · Cayman Islands

Cybersecurity law & regulation in Cayman Islands (2026)

Sectoral rulesCountry index 80 · B+

Cayman Islands shaded by its cybersecurity status

Cybersecurity in Cayman Islands: sectoral rules.

FrameworkCIMA Rule & Statement of Guidance – Cybersecurity for Regulated Entities (financial sector); Data Protection Act (2021 Revision) enforced by the Ombudsman; Computer Misuse Act (2015 Revision) for cybercrime. No horizontal NIS-style law.

The Cayman Islands has no single comprehensive cybersecurity statute; obligations are set sector-by-sector, principally by the Cayman Islands Monetary Authority (CIMA) for regulated financial entities, together with the Data Protection Act for personal data and the Computer Misuse Act for cybercrime. A National Cyber Security Incident Response Team (CSIRT) was launched in 2022 and a dedicated Cybersecurity Agency is being scoped under the World Bank–supported Digital Transformation Project (2024).

Key points

CIMA Cybersecurity Rule (financial sector)

CIMA's binding Rule and Statement of Guidance on Cybersecurity for Regulated Entities came into force on 27 November 2020 and applies to all CIMA-licensed/registered entities (banks, insurers, funds, investment managers, VASPs). Entities must maintain a documented cybersecurity framework to identify, monitor and mitigate cyber risks, with breach potentially triggering fines or regulatory action.

72-hour CIMA incident notification

Regulated entities must notify CIMA in writing no later than 72 hours after discovering a cyber incident deemed to have — or potentially become — material impact (e.g. significant operational disruption, customer impact, or compromise/loss of sensitive information).

Data Protection Act breach notification

Under the Data Protection Act (in force 30 September 2019), data controllers must notify the Ombudsman and affected individuals of a personal data breach without undue delay and no later than 5 days after they should have become aware. Failure is an offence; fines up to KYD 250,000 and/or imprisonment are available for specified contraventions.

Cybercrime — Computer Misuse Act

The Computer Misuse Act (2015 Revision), modelled on the UK's Computer Misuse Act 1990, criminalises unauthorised access, unauthorised modification, unauthorised interception and denial-of-service style acts. Provisions are extraterritorial where Cayman computer systems are affected.

National CSIRT and Cyber Safe Campaign

A national Computer Security Incident Response Team (CSIRT.KY) was launched in 2022 within the Ministry responsible for e-government to coordinate incident response for government, business and citizens, complemented by the government's Cyber Safe Cayman awareness campaign.

2026 outlook — VASP and tokenised fund cyber rules

CIMA's updated regime (February 2026) tightens cybersecurity, risk-assessment and internal-control obligations for Virtual Asset Custodians and Virtual Asset Trading Platforms; tokenised fund offering documents must now disclose cybersecurity and transferability risks and mitigations. Further rulemaking on cyber-risk management, technology governance and senior-management accountability is anticipated.

Timeline - major decisions & events

Nov 1, 2025guidanceofficial
CIMA publishes Desk-Based Review of registered VASPs flagging cyber gaps

CIMA's thematic review of 11 virtual asset service providers (assessed Sept 2024-Feb 2025) found that 82% lacked cybersecurity insurance, 27% had not appointed a qualified CISO/CIO, and many had inadequate custody, wallet and private-key controls. It signals heightened cyber-supervisory scrutiny of the crypto sector.

CIMA
Jun 5, 2025enforcement
CIMA cancels VASP registration of AC Holding Limited

CIMA revoked AC Holding Limited's virtual asset registration for failures including non-provision of documents, deficient AML systems and breaches of CIMA's Corporate Governance and Internal Controls Rules. It illustrates the regulator's growing willingness to take enforcement action against governance and control failings.

Loeb Smith
Jun 1, 2023guidanceofficial
CIMA issues Thematic Cybersecurity Review Report

CIMA reviewed 12 banking, insurance and securities entities and concluded the 2020 cybersecurity guidance had largely been adopted, while flagging weaknesses in risk assessment and oversight of outsourced providers (notably Microsoft 365/Azure dependencies). The report sets supervisory expectations for the sector.

CIMA
Apr 14, 2023law
CIMA updates Cybersecurity Rule and Statement of Guidance

Updated binding Rule and SOG on Cybersecurity for Regulated Entities took effect, expressly extending obligations to virtual asset service providers and SIBA-registered persons while extending the cybersecurity/outsourcing exemption from mutual funds to private funds. It broadened the perimeter of regulated entities subject to mandatory cyber-risk management.

Ogier
May 1, 2020lawofficial
CIMA issues binding Rule and SOG on Cybersecurity for Regulated Entities

CIMA introduced its first dedicated, binding cybersecurity framework requiring regulated entities to adopt a board-approved cyber risk strategy, security policies and controls, and to notify CIMA of material cyber incidents within 72 hours. This established the financial sector's core cybersecurity obligations.

CIMA
Sep 30, 2019lawofficial
Data Protection Act comes into force; Ombudsman becomes supervisory authority

The DPA took effect, making the Office of the Ombudsman the data-protection supervisor and requiring controllers to notify the Ombudsman and affected individuals of a personal data breach without undue delay and within five days. It created the islands' core data-security and breach-notification obligations, backed by penalties up to CI$250,000.

Cayman Islands Ombudsman
Jan 1, 2015lawofficial
Computer Misuse Law (2015 Revision) consolidates core cybercrime offences

The consolidated Computer Misuse Law, modelled on the UK Computer Misuse Act, criminalises unauthorised access, modification, interception, obstruction and disclosure of access codes, with extra-territorial reach. It is the foundational anti-hacking statute underpinning the islands' cybersecurity legal framework.

OfReg (Cayman Islands)

Cayman Islands - other topics

Cybersecurity in other countries

Last verified 8/24/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map →