Lloyd's Minimum Standards - Cyber Security
Lloyd's of London Minimum Standards establish baseline requirements that all managing agents in the Lloyd's market must meet. The Cyber Security minimum standards, part of the broader Operational Risk framework, require managing agents to implement appropriate cybersecurity controls, conduct risk assessments, and report incidents. Lloyd's also sets standards for underwriting, claims, reserving, and other operational areas. Enforced through Lloyd's supervisory framework.
Lloyd's Minimum Standards - Cyber Security is a compliance framework from United Kingdom (Lloyd's) with 8 domains and 8 controls. The largest domains are Access + Privileged + MFA + Vulnerability + MS11.4-5 (1 controls), Awareness + Insider + Pen Test + Assurance + MS11.13-16 (1 controls), Configuration + Network + Perimeter + MS11.6-15 (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Access + Privileged + MFA + Vulnerability + MS11.4-5
| Code | Title |
|---|---|
| LLOYDS-MS11-Access-Control-Privileged-MFA-Vulnerability-Patch-Management-MS11-4-5-PRA-Senior-Managers-Regime | Lloyds MS11 Access Control + Privileged + MFA + Vulnerability + Patch + MS11.4-5 |
Awareness + Insider + Pen Test + Assurance + MS11.13-16
| Code | Title |
|---|---|
| LLOYDS-MS11-Security-Awareness-Insider-Risk-Penetration-Testing-Independent-Assurance-MS11-13-16 | Lloyds MS11 Security Awareness + Insider Risk + Pen Testing + Assurance + MS11.13-16 |
Configuration + Network + Perimeter + MS11.6-15
| Code | Title |
|---|---|
| LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15 | Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15 |
Governance + Board + Risk + Asset + MS11.1-3
| Code | Title |
|---|---|
| LLOYDS-MS11-Governance-Board-Oversight-Risk-Identification-Assessment-Asset-Inventory-MS11-1-2-3-Lloyds-PMD | Lloyds MS11 Governance + Board Oversight + Risk + Asset Inventory + MS11.1-3 |
Incident Response + BC + Recovery + MS11.8-9
| Code | Title |
|---|---|
| LLOYDS-MS11-Cyber-Incident-Response-Reporting-Business-Continuity-Cyber-Recovery-MS11-8-9-PRA-Operational-Resilience | Lloyds MS11 Incident Response + Reporting + Business Continuity + Recovery + MS11.8-9 |
Risk Quantification + Reporting + MS11.17-18
| Code | Title |
|---|---|
| LLOYDS-MS11-Cyber-Risk-Quantification-Capital-Linkage-Regulatory-Lloyds-Reporting-MS11-17-18-CBEST-FFIEC | Lloyds MS11 Cyber Risk Quantification + Capital + Regulatory + Lloyds Reporting + MS11.17-18 |
Third Party + Cloud + Data + Classification + MS11.10-14-11
| Code | Title |
|---|---|
| LLOYDS-MS11-Third-Party-Outsourcing-Cyber-Risk-Cloud-Security-Data-Protection-Classification-MS11-10-14-11 | Lloyds MS11 Third Party + Cloud + Data Protection + Classification + MS11.10-14-11 |
Threat Detection + Email + Phishing + MS11.7-12
| Code | Title |
|---|---|
| LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM | Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12 |
What is Lloyd's Minimum Standards - Cyber Security and who does it apply to?
Lloyd's Minimum Standards - Cyber Security is a compliance framework from United Kingdom (Lloyd's) with 8 domains and 8 controls. Lloyd's of London Minimum Standards establish baseline requirements that all managing agents in the Lloyd's market must meet. The Cyber Security minimum standards, part of the broader Operational Risk framework, require managing agents to implement appropriate cybersecurity controls, conduct risk assessments, and report incidents. Lloyd's also sets standards for underwriting, claims, reserving, and other operational areas. Enforced through Lloyd's supervisory framework. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Lloyd's Minimum Standards - Cyber Security actually require?
Lloyd's Minimum Standards - Cyber Security has 8 controls organised across 8 domains. The largest domains are Access + Privileged + MFA + Vulnerability + MS11.4-5 (1 controls), Awareness + Insider + Pen Test + Assurance + MS11.13-16 (1 controls), Configuration + Network + Perimeter + MS11.6-15 (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Lloyd's Minimum Standards - Cyber Security do I already cover?
Lloyd's Minimum Standards - Cyber Security does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I implement Lloyd's Minimum Standards - Cyber Security?
Start your Lloyd's Minimum Standards - Cyber Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Lloyd's Minimum Standards - Cyber Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 8 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required