Trinidad and Tobago: Technical Assistance Report-Strengthening Cybersecurity in Financial Institutions
IMF Staff Country Reports, May 8, 2023
Source details
- Canonical URL
- Trinidad and Tobago: Technical Assistance Report-Strengthening Cybersecurity in Financial Institutions
Other formats
Bibliographic details
- Published: May 8, 2023
- Series: IMF Staff Country Reports
- DOI: https://doi.org/10.5089/9798400240249.002
Executive summary and deliverables
- Technical note evaluating strengthening cybersecurity in financial institutions of Trinidad and Tobago.
- Deliverables included a capacity-building seminar on regulation of cyber risk.
- The Central Bank of Trinidad and Tobago intends to develop a draft guideline for consultation with its regulated institutions in the first quarter of 2023, covering:
- governance,
- risk management,
- incident reporting,
- cyber hygiene.
Key findings
- The Central Bank of Trinidad and Tobago identified the need for filling regulatory gaps related to cybersecurity.
- Supervisory arrangements for Information and Communication Technology/cyber risks need further improvements.
- Resource constraints within the Financial Institutions Supervision Department need to be addressed urgently.
- The Identity and Access Management project has been formally set up and is now in Phase 1, which is considered preparatory.
- The governance of the Identity and Access Management project, the high-level roadmap, and the deliverables for Phase 1 are generally in line with good practices.
Policy recommendations and governance actions
- Issue a focused guideline on cybersecurity covering governance, risk management, incident reporting, and cyber hygiene (draft to be developed for consultation in the first quarter of 2023).
- Address resource constraints within the Financial Institutions Supervision Department urgently to strengthen supervisory capacity for ICT/cyber risks.
- Improve supervisory arrangements for Information and Communication Technology/cyber risks.
- Establish regular cybersecurity meetings and a reporting regime at the Board level with the participation of the Head of IT Security.
- Continue capacity building (e.g., seminars) on regulation of cyber risk.
Implementation status and project governance
- Identity and Access Management project: formally established and in Phase 1 (preparatory).
- Phase 1 deliverables and high-level roadmap are generally aligned with good practices.
- Ongoing need for enhanced supervisory arrangements and resourcing to translate guidelines and project work into strengthened oversight.
Source: Trinidad and Tobago: Technical Assistance Report-Strengthening Cybersecurity in Financial Institutions, IMF Staff Country Reports, May 8, 2023.
Content in this bundle
- 1ttoea2023002