Cyber resilience is maintained across seven headings: information systems and reporting (at the baseline, integrity protection and reporting of significant cyber incidents and data breaches to Lloyd's and the LMA within 72 hours); data protection and governance (policies, training, DSARs and reporting of market-impacting data loss within statutory timescales); cyber governance, protection and identification (a documented strategy, protection of systems behind Important Business Services, hardening, awareness training, end of life management); third-party management (identified and assessed vital suppliers, contracts or data processing agreements, secure transfers); detection (endpoint and perimeter detection with file scanning and alert tuning); response and recovery (offline, tested incident and continuity plans; tested backup and restore); and information sharing (receiving Lloyd's market cyber information). Higher levels add asset registers, encryption, 24/7 monitoring, forensics, external red teaming and LMA CISO community participation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.