רשות שוק ההון — Capital Market Cyber Risk Circular
Who needs it
Insurance companies, pension funds and provident funds (and their management companies) regulated by the Capital Market, Insurance and Savings Authority, plus licensed financial service providers brought into scope by later amendments.
Key requirements
A board-approved cyber risk management program, a designated cyber defense officer with real authority, asset-level risk assessment across information, processes and systems, and ongoing governance-based monitoring.
Cyber implications
Risk assessment has to be specific to your actual assets and processes, not a generic template, and the cyber defense officer needs a real reporting line to the board, not just a title.
Assessment methodology
Governance review of the cyber risk program, review of the cyber defense officer's mandate and access, an asset and risk register review, and a controls gap analysis against the circular's requirements.
Implementation phases
Assess
Review governance structure, cyber defense officer mandate, and asset-level risk coverage.
Remediate
Close governance and control gaps; formalize the risk management program for board approval.
Evidence
Document board approvals, risk registers and control implementation in an audit-ready form.
Evidence & documentation requirements
Board approval records for the cyber risk management program, the cyber defense officer's appointment and reporting lines, asset and risk registers, and evidence that controls were actually implemented, not just documented.
Common mistakes
Appointing a cyber defense officer without real board access or authority; scoping the risk assessment as IT-only instead of covering business processes and third parties; and losing track of the circular's later amendments (2022-10-9, 2024-10-3), which extended its scope beyond the original institutional entities.
Related standards
Expert review
FAQ
Request a Gap Assessment
See exactly where your cyber risk program stands against the Authority's requirements before an examination.
Request a Gap Assessment →