Lloyd's Minimum Standards - Cyber Security
Lloyd's of London Minimum Standards establish baseline requirements that all managing agents in the Lloyd's market must meet. The Cyber Security minimum standards, part of the broader Operational Risk framework, require managing agents to implement appropriate cybersecurity controls, conduct risk assessments, and report incidents. Lloyd's also sets standards for underwriting, claims, reserving, and other operational areas. Enforced through Lloyd's supervisory framework.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (17)
Access Control
| Code | Title |
|---|---|
| LMS-CYB-MS11.4 | Access Control and Privileged Access |
Asset Management
| Code | Title |
|---|---|
| LMS-CYB-MS11.3 | Information Asset Inventory |
Assurance
| Code | Title |
|---|---|
| LMS-CYB-MS11.16 | Penetration Testing and Independent Assurance |
Cloud
| Code | Title |
|---|---|
| LMS-CYB-MS11.14 | Cloud Security |
Cyber Security Requirements
ONR cyber security expectations
Data Protection
| Code | Title |
|---|---|
| LMS-CYB-MS11.11 | Data Protection and Information Classification |
Detection
| Code | Title |
|---|---|
| LMS-CYB-MS11.7 | Threat Detection and Security Monitoring |
Governance
| Code | Title |
|---|---|
| LMS-CYB-MS11.1 | Cyber Security Governance and Board Oversight |
Incident Response
| Code | Title |
|---|---|
| LMS-CYB-MS11.8 | Cyber Incident Response and Reporting |
Incident Response and Reporting
Incident management and Lloyd's reporting
| Code | Title |
|---|---|
| FTC-314.4g | Program Evaluation and Adjustment |
| FTC-314.4h | Written Incident Response Plan |
| FTC-314.4i | Board / Senior Officer Reporting |
| FTC-314.4j | FTC Breach Notification |
| FTC-314.5 | Exemption for Small Institutions |
| LLOYDS-IR-01 | Incident Response Plan |
| LLOYDS-IR-02 | Lloyd's Incident Reporting |
| LLOYDS-IR-03 | Resilience and Recovery |
| NGC-5.260(g) | Cyber Attack Investigation |
| NGC-5.260(h) | Board Notification |
| NGC-5.260(i) | Patron and Employee Data Protection |
| Sec. 314.4(h) | Incident response plan |
| Sec. 314.4(i) | Board reporting by Qualified Individual |
| Sec. 314.4(j) | FTC notification requirement |
| Sec. 314.5 | Effective date and compliance |
| Sec. 314.6 | Exceptions for small institutions |
Network
| Code | Title |
|---|---|
| LMS-CYB-MS11.15 | Network Segmentation and Perimeter Defence |
People
| Code | Title |
|---|---|
| LMS-CYB-MS11.13 | Security Awareness and Insider Risk |
Reporting
| Code | Title |
|---|---|
| LMS-CYB-MS11.18 | Regulatory and Lloyd's Reporting Obligations |
Resilience
| Code | Title |
|---|---|
| LMS-CYB-MS11.9 | Business Continuity and Cyber Recovery |
Risk Management
| Code | Title |
|---|---|
| LMS-CYB-MS11.17 | Cyber Risk Quantification and Capital Linkage |
| LMS-CYB-MS11.2 | Cyber Risk Identification and Assessment |
Technical Controls
| Code | Title |
|---|---|
| LMS-CYB-MS11.12 | Email and Phishing Defences |
| LMS-CYB-MS11.5 | Vulnerability and Patch Management |
| LMS-CYB-MS11.6 | Secure Configuration and Change Management |
Third Party
| Code | Title |
|---|---|
| LMS-CYB-MS11.10 | Third Party and Outsourcing Cyber Risk |
Your Compliance Coverage
If you comply with Lloyd's Minimum Standards - Cyber Security, you already cover:
Singapore Government Instruction Manual on ICT&SS Management (IM8)
29%
10 controls mapped
Compare →CAIQ (CSA)
29%
10 controls mapped
Compare →UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
29%
10 controls mapped
Compare →+ 600 more: Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (29%), Defence Security Principles Framework (DSPF) (29%)
See all 603 mapped frameworks ↓Maps to 603 other frameworks
Frequently Asked Questions
What is Lloyd's Minimum Standards - Cyber Security?
Lloyd's Minimum Standards - Cyber Security is a compliance framework from United Kingdom (Lloyd's) with 17 domains and 34 controls. Lloyd's of London Minimum Standards establish baseline requirements that all managing agents in the Lloyd's market must meet. The Cyber Security minimum standards, part of the broader Operational Risk framework, require managing agents to implement appropriate cybersecurity controls, conduct risk assessments, and report incidents. Lloyd's also sets standards for underwriting, claims, reserving, and other operational areas. Enforced through Lloyd's supervisory framework. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Lloyd's Minimum Standards - Cyber Security have?
Lloyd's Minimum Standards - Cyber Security has 34 controls organised across 17 domains. The largest domains are Incident Response and Reporting (16 controls), Technical Controls (3 controls), Risk Management (2 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Lloyd's Minimum Standards - Cyber Security map to?
Lloyd's Minimum Standards - Cyber Security maps to 603 other compliance frameworks. The top mapping partners are Singapore Government Instruction Manual on ICT&SS Management (IM8) (29% coverage), CAIQ (CSA) (29% coverage), UK Defence Standard 05-138 - Cyber Security for Defence Suppliers (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Lloyd's Minimum Standards - Cyber Security compliance?
Start your Lloyd's Minimum Standards - Cyber Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Lloyd's Minimum Standards - Cyber Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required