Cybersecurity

Preparing for CIMA’s Proposed Cybersecurity and Governance Requirements: How CompCay Can Help

October 08, 2026•5 min read

As Cayman’s financial services industry continues to evolve, cybersecurity, operational resilience and strong governance are becoming increasingly important areas of regulatory focus.

The Cayman Islands Monetary Authority (CIMA) is seeking industry feedback on three proposed regulatory measures covering cybersecurity and incident reporting for regulated entities, cybersecurity requirements for Virtual Asset Service Providers (VASPs), and tokenised funds.

While the proposed requirements introduce additional obligations for regulated entities, they also provide an opportunity for organisations to strengthen their cybersecurity frameworks, governance structures and overall operational resilience.

For Cayman-based businesses, the key question is not simply “Are we compliant?” but rather:

“Do we have the right governance, controls, processes and expertise in place to demonstrate that we are managing these risks effectively?”

This is where CompCay can help.

Strengthening Cybersecurity Governance

The proposed cybersecurity framework places greater emphasis on governance, accountability and the management of emerging technology and third-party cybersecurity risks.

For regulated entities, cybersecurity can no longer be viewed solely as an IT responsibility. Boards, senior management and business leaders all have an important role to play in understanding cyber risks and ensuring that appropriate controls are implemented and regularly reviewed.

CompCay can assist organisations in developing and strengthening their cybersecurity governance framework, including:

  • Cybersecurity policies and procedures

  • Cyber risk assessments

  • Governance and accountability frameworks

  • Risk registers and remediation plans

  • Third-party and vendor risk management

  • Security awareness and training

  • Vulnerability and risk management

  • Incident response planning

  • Business continuity and disaster recovery

  • Cybersecurity assessments and control reviews

Our goal is to help organisations move beyond simply having policies on paper and establish practical controls that are understood, implemented and regularly tested.

Preparing for Cybersecurity Incident Reporting

The proposed framework also provides clearer expectations around cybersecurity incident reporting, including requirements aligned with the Financial Stability Board’s FIRE framework while retaining the existing 72-hour maximum notification period.

When a cybersecurity incident occurs, having a documented response plan is critical. Organisations need to know:

  • Who is responsible for declaring and managing an incident?

  • Who needs to be notified internally?

  • When does an incident become reportable?

  • What information needs to be collected?

  • How quickly can the organisation respond?

  • How will the incident be communicated to management, the Board and regulators?

  • How will lessons learned be incorporated into future controls?

CompCay can help organisations review and strengthen their incident response and escalation processes, ensuring that responsibilities are clearly defined and that the organisation is better prepared to respond when an incident occurs.

Cybersecurity for VASPs

The proposed VASP-specific requirements recognise that virtual asset businesses face unique cybersecurity risks.

Areas such as wallet security, private key management, smart contracts, custody arrangements, vulnerability management and third-party dependencies require specialised consideration.

For VASPs, cybersecurity needs to address not only traditional IT infrastructure but also the technologies and processes that directly protect customer assets.

CompCay can support VASPs with cybersecurity and governance assessments covering areas such as:

  • Cybersecurity risk assessments

  • Wallet and custody security

  • Access control and privileged access

  • Private key management processes

  • Vulnerability management

  • Third-party risk

  • Incident response and recovery

  • Business continuity and disaster recovery

  • Security policies and procedures

  • Cybersecurity governance

  • Audit and compliance readiness

The proposed requirement for independent cybersecurity audits at least annually and following material changes also highlights the importance of maintaining an ongoing cybersecurity programme rather than treating security as a one-time compliance exercise.

Governance Around Third-Party Technology

Modern financial services organisations increasingly depend on cloud providers, software platforms, managed service providers and other technology partners.

This creates another important area of risk.

A company may have strong internal security controls, but a weakness within a critical third-party provider can still create significant operational and cybersecurity exposure.

Effective third-party risk management should therefore form part of an organisation's broader cybersecurity governance programme.

CompCay can assist with establishing practical processes for identifying critical technology providers, assessing their risks, documenting security requirements and monitoring third-party relationships.

Supporting Operational Resilience

Cybersecurity is closely connected to business continuity and operational resilience.

A cybersecurity incident can affect an organisation's ability to provide services, access systems, process transactions or protect sensitive information. For financial services organisations, the consequences can extend well beyond the IT department.

That is why organisations should regularly test whether they can continue operating and recover effectively following a significant technology or cybersecurity disruption.

CompCay can assist with:

  • Business continuity planning

  • Disaster recovery planning

  • IT recovery assessments

  • Recovery testing

  • Incident response exercises

  • Tabletop exercises

  • Identification of critical systems and dependencies

  • Recovery objectives and procedures

The objective is simple: know what needs to happen before an incident occurs, rather than trying to develop a response during the incident.

Governance for Tokenised Funds

The proposed framework for tokenised funds also highlights the importance of strong governance and control over technology-enabled financial products.

Tokenisation introduces additional considerations around legal rights, valuation, transfers, redemptions, custody and technology arrangements.

Fund operators will need to maintain appropriate oversight of their tokenisation arrangements, including outsourced functions, while implementing controls designed to prevent issues such as over-issuance and discrepancies in valuation or ownership records.

While technology may enable new ways of managing and transferring fund interests, strong governance remains essential.

CompCay can help organisations assess the cybersecurity, technology governance and operational controls supporting these arrangements, including third-party dependencies and technology risks.

Turning Regulatory Expectations into Practical Controls

Regulatory requirements can sometimes appear complex when viewed as a collection of rules, policies and documentation.

The real challenge is translating those requirements into practical, sustainable controls that work within the organisation's day-to-day operations.

This is where an experienced cybersecurity and governance partner can add significant value.

At CompCay, we can work with organisations to assess their current cybersecurity and governance maturity, identify gaps and develop a practical roadmap for addressing those gaps.

Our approach can include:

Assess → Identify → Remediate → Test → Improve

This helps organisations establish a continuous cybersecurity and governance programme rather than approaching regulatory compliance as a one-time project.

Is Your Organisation Ready?

CIMA's proposed measures reinforce an important message for Cayman’s financial services sector:

Cybersecurity and governance are business responsibilities, not simply IT responsibilities.

Whether you are a regulated entity reviewing your cybersecurity framework, a VASP preparing for enhanced requirements, or an organisation evaluating technology and operational risks associated with tokenisation, now is a good time to assess your current position.

CompCay can assist with cybersecurity assessments, governance, risk management, incident response, third-party risk, business continuity and regulatory readiness.

If your organisation is unsure where it currently stands, a cybersecurity and governance gap assessment can be a practical first step toward understanding what needs to be strengthened.

CompCay — helping Cayman businesses strengthen cybersecurity, governance and operational resilience.

Back to Blog