Lloyd's Minimum Standards - Cyber Security
Threat Detection + Email + Phishing + MS11.7-12

Lloyd's Minimum Standards - Cyber Security LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM: Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + cloud + application + database + privileged access + cloud trail + container logs + Endpoint Detection and Response (EDR) on all endpoints + Extended Detection and Response (XDR) where deployed + Network Detection and Response (NDR) + Cloud Detection and Response (CDR) + Threat Intelligence integration including commercial feeds + open-source intelligence (OSINT) + Information Sharing and Analysis Centre Insurance (Insurance ISAC) + FS-ISAC for cross-financial-sector intelligence + MITRE ATT&CK and CK framework mapping + tactics + techniques + procedures (TTPs) library + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs) + UEBA (User and Entity Behavior Analytics) + Insider threat detection + log retention minimum 1 year (longer for FCA/PRA regulated activities + claims investigation) + tamper-evident storage + correlation rules + use cases + SOAR (Security Orchestration Automation and Response) automation. MS11.12 Email and Phishing Defences - secure email gateway with sandboxing + DMARC + SPF + DKIM authentication + URL rewriting + impersonation detection + Business Email Compromise (BEC) defences + phishing simulation programme (quarterly minimum) + Lloyds market-specific phishing scenarios (claims fraud + invoice fraud + executive impersonation) + reporting mechanism for suspicious emails + DPO + DSAR phishing variants.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.