Lloyd's Minimum Standards - Cyber Security
Risk Quantification + Reporting + MS11.17-18

Lloyd's Minimum Standards - Cyber Security LLOYDS-MS11-Cyber-Risk-Quantification-Capital-Linkage-Regulatory-Lloyds-Reporting-MS11-17-18-CBEST-FFIEC: Lloyds MS11 Cyber Risk Quantification + Capital + Regulatory + Lloyds Reporting + MS11.17-18

Lloyds MS11.17 Cyber Risk Quantification and Capital Linkage - cyber risk quantification methodology aligned with PRA Solvency II + Operational Risk Internal Model (where applicable) + standard formula + cyber-specific stressors + scenario analysis (Lloyds Realistic Disaster Scenarios for cyber + cloud outage + ransomware + supply chain) + FAIR (Factor Analysis of Information Risk) methodology + Monte Carlo simulation + insurance industry loss data including Verisk + Aon + AdvisenLoss + IBM Cost of a Data Breach Report + capital adequacy assessment including Operational Risk Capital + Lloyds-required Member Capital requirements + reinsurance protection + cyber catastrophe reinsurance + parametric cyber consideration + Cyber Risk Aggregation (CRA) market-wide modeling + Lloyds Realistic Disaster Scenarios cyber (extreme scenarios with industry losses USD 100B+ + Lloyds market exposure quantification) + Investor and Member disclosure. MS11.18 Regulatory and Lloyds Reporting Obligations - quarterly Lloyds Cyber Risk and Resilience Returns + annual Lloyds Cyber Security Attestation + Annual Solvency and Financial Condition Report (SFCR) cyber-risk disclosure + PRA Form CY01 cyber + FCA Form RMA-R Regulatory Returns + Operational Resilience Annual Self-Assessment to PRA + Bank of England + FCA + UK NCSC voluntary reporting + ICO notifications + NIS Regulations 2018 (NIS1) compliance + NIS2 Directive (where applicable to UK or EU establishments) + Lloyds Cyber Resilience reporting + Insurance Distribution Directive (IDD) conduct risk reporting + Senior Managers Annual Cyber Resilience Statement + Lloyds Insurance Company SA (LIC) Brussels EU reporting via NBB (National Bank of Belgium) + EU DORA Digital Operational Resilience Act for EU establishment.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.