Lloyds MS11.8 Cyber Incident Response and Reporting - documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification matrix (severity + impact + urgency) + Triage + Containment + Eradication + Recovery (NIST SP 800-61 Rev 2) + Lessons Learned post-incident review + tabletop exercises (quarterly for high-risk + annually minimum) + functional exercises + red team / purple team engagements + Lloyds-required mandatory incident reporting: significant cyber incidents must be notified to Lloyds Cyber Risk team within 24 hours of detection + parallel PRA notification under SS2/21 (significant operational disruption) within 24 hours + FCA notification under Principle 11 (open and cooperative) + NCSC (UK National Cyber Security Centre) reporting under voluntary CIRP scheme + Action Fraud reporting + ICO breach notification within 72 hours where personal data involved (UK GDPR + DPA 2018) + customer notification under Insurance Conduct of Business Sourcebook (ICOBS) where claims handling disrupted + reinsurance notification where reinsured. MS11.9 Business Continuity and Cyber Resilience - Business Impact Analysis (BIA) covering Important Business Services per PRA SS1/21 + FCA PS21/3 Operational Resilience + Important Business Services identification + Impact Tolerance setting (maximum tolerable period of disruption + maximum tolerable financial loss + maximum tolerable customer harm) + Bank of England + PRA + FCA self-assessment requirement (initial by March 2022 + mapping + scenario testing + remediation by March 2025) + recovery objectives (RTO + RPO + MTD) + immutable + air-gapped + ransomware-resistant backups + tested restore procedures + alternate processing sites + crisis communications + executive crisis management team + customer + regulator + media communications + ISO 22301 BCMS alignment + parametric cyber business continuity insurance consideration + insurance market mutual aid arrangements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.