Compliance · Israel
Circular 2016-9-14 Cyber Risk Management in Institutional Entities

רשות שוק ההון — Capital Market Cyber Risk Circular

Plain-English definition

Issued by Israel's Capital Market, Insurance and Savings Authority, Circular 2016-9-14 requires insurance companies, pension funds and provident funds to run a board-approved cyber risk management program under a named cyber defense officer. Circular 2022-10-9 (amended 2024-10-3) later extended broadly similar obligations to licensed financial service providers, such as credit, payment and financial-asset providers.

Follows a broadly similar risk-based, governance-driven approach to the Bank of Israel's נב"ת directive, but the two are separate regimes with no formal cross-reference between them.

Who needs it

Insurance companies, pension funds and provident funds (and their management companies) regulated by the Capital Market, Insurance and Savings Authority, plus licensed financial service providers brought into scope by later amendments.

Key requirements

A board-approved cyber risk management program, a designated cyber defense officer with real authority, asset-level risk assessment across information, processes and systems, and ongoing governance-based monitoring.

Cyber implications

Risk assessment has to be specific to your actual assets and processes, not a generic template, and the cyber defense officer needs a real reporting line to the board, not just a title.

Assessment methodology

Governance review of the cyber risk program, review of the cyber defense officer's mandate and access, an asset and risk register review, and a controls gap analysis against the circular's requirements.

Implementation phases

01
Assess

Review governance structure, cyber defense officer mandate, and asset-level risk coverage.

02
Remediate

Close governance and control gaps; formalize the risk management program for board approval.

03
Evidence

Document board approvals, risk registers and control implementation in an audit-ready form.

Evidence & documentation requirements

Board approval records for the cyber risk management program, the cyber defense officer's appointment and reporting lines, asset and risk registers, and evidence that controls were actually implemented, not just documented.

Common mistakes

Appointing a cyber defense officer without real board access or authority; scoping the risk assessment as IT-only instead of covering business processes and third parties; and losing track of the circular's later amendments (2022-10-9, 2024-10-3), which extended its scope beyond the original institutional entities.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

Does this apply to my payment or fintech company?
The core circular (2016-9-14) covers insurance companies, pension funds and provident funds. Circular 2022-10-9, amended by 2024-10-3, extended broadly similar cyber risk-management obligations to licensed financial service providers such as credit, payment and financial-asset providers.
How does this relate to the Bank of Israel's cyber directive?
Both follow a similar risk-based, governance-driven approach and were developed around the same period, but they are separate regulatory regimes with no formal cross-reference between them, so compliance with one does not automatically satisfy the other.

Request a Gap Assessment

See exactly where your cyber risk program stands against the Authority's requirements before an examination.

Request a Gap Assessment →