Principles for Doing Business at Lloyd's
Principle 12: Operational Resilience – Principles for Doing Business at Lloyd's

Principles for Doing Business at Lloyd's P12.3: 12.3 Maintain appropriate cyber resilience

Cyber resilience is maintained across seven headings: information systems and reporting (at the baseline, integrity protection and reporting of significant cyber incidents and data breaches to Lloyd's and the LMA within 72 hours); data protection and governance (policies, training, DSARs and reporting of market-impacting data loss within statutory timescales); cyber governance, protection and identification (a documented strategy, protection of systems behind Important Business Services, hardening, awareness training, end of life management); third-party management (identified and assessed vital suppliers, contracts or data processing agreements, secure transfers); detection (endpoint and perimeter detection with file scanning and alert tuning); response and recovery (offline, tested incident and continuity plans; tested backup and restore); and information sharing (receiving Lloyd's market cyber information). Higher levels add asset registers, encryption, 24/7 monitoring, forensics, external red teaming and LMA CISO community participation.

Maintained by Gerard Blokdyk

Other controls in Principle 12: Operational Resilience – Principles for Doing Business at Lloyd's

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.