11.4 Cyber Hygiene and Technology Risk

Key Takeaways

  • MAS Notice FSM-N04 on Cyber Hygiene, effective 10 May 2024, applies to licensed insurers and to insurance agents other than individuals.

  • The six cyber hygiene requirements cover administrative accounts, security patches, written security standards, network perimeter defence, malware protection and multi-factor authentication.

  • Multi-factor authentication is required for administrative accounts on critical systems and for all accounts on systems used to access customer information through the internet.

  • Under MAS's Notice on Technology Risk Management, an insurer must notify MAS within 1 hour of discovering a relevant incident and submit a root-cause report within 14 days.

  • Individual practitioners support cyber hygiene through strong authentication, prompt updates, caution with links and attachments, and reporting incidents quickly.

Last updated: October 2026

11.4 Cyber Hygiene and Technology Risk

Quick Summary: Cyber hygiene means the basic security practices that keep systems and data safe. MAS Notice FSM-N04 makes six of them legally binding for licensed insurers and corporate insurance agents. MAS's Notice on Technology Risk Management requires insurers to notify MAS within 1 hour of discovering a serious IT incident. Individual practitioners must also follow good habits, because many attacks start with one careless click.

Why Cyber Hygiene Matters in Insurance

Insurers and intermediaries hold large amounts of sensitive data, such as NRIC numbers, bank details, medical reports and claims histories, and they depend on online systems for quotations, payments and claims. A breach can expose customers to identity theft and scams, disrupt service, and lead to regulatory action under both MAS rules and the PDPA. Scammers also impersonate insurers and training bodies, and SCI's own website warns candidates about fraudulent course and examination registrations.

MAS Notice FSM-N04: Notice on Cyber Hygiene

ItemDetail
Legal basisSection 29(1) of the Financial Services and Markets Act 2022
Issued / effectiveIssued 9 May 2024; effective 10 May 2024
Applies toLicensed insurers, and insurance agents other than individuals and certain persons exempted under the Financial Advisers Act
Practical scopeIndividual agents work within their principals' and agencies' security controls

MAS has issued parallel Cyber Hygiene Notices for other types of financial institutions.

The Six Cyber Hygiene Practices

  1. Administrative accounts: every administrative account on any operating system, database, application, security appliance or network device must be secured to prevent unauthorised access or use. These are accounts with full privileges and unrestricted access.
  2. Security patches: security patches must be applied to address vulnerabilities in every system, within a timeframe commensurate with the risk posed by each vulnerability. Where no patch is available, controls must be put in place to reduce the risk.
  3. Security standards: there must be a written set of security standards for every system, and every system must conform to them. Where a system cannot conform, compensating controls are required.
  4. Network perimeter defence: controls must be implemented at the network perimeter to restrict all unauthorised network traffic, for example through firewalls.
  5. Malware protection: one or more malware protection measures must be implemented on every system where such measures are available and can be implemented.
  6. Multi-factor authentication (MFA): required for all administrative accounts on critical systems and for all accounts on any system used to access customer information through the internet.

Key definitions:

  • A critical system is one whose failure would significantly disrupt operations or materially affect service to customers, such as systems that process time-critical transactions or provide essential services.
  • Multi-factor authentication uses two or more factors: something you know (a password or PIN), something you have (a token or device) or something you are (biometrics or behaviour).
  • An entity need not comply with a requirement to the extent it cannot exercise direct or indirect control over a system, and it is not reasonable to switch to a provider over whom it could.

Technology Risk Management: Incidents and Recovery

MAS's Notice on Technology Risk Management for insurers adds incident and resilience requirements:

  • Recovery time objective: a recovery time objective of not more than 4 hours for each critical system, validated at least once every 12 months.
  • Incident notification: MAS must be notified as soon as possible, and not later than 1 hour, after the discovery of a relevant incident. A relevant incident is a system malfunction or IT security incident with a severe and widespread impact on operations, or a material impact on service to customers.
  • Root cause report: a root cause and impact analysis report must be submitted within 14 days of discovery, unless MAS allows longer. It sets out the cause, the impact and the remedial measures.
  • Customer information: IT controls must protect customer information from unauthorised access or disclosure.

The MAS FAQs give a timing example. If an incident occurs at time T but is discovered at T+1, MAS must be notified by T+2, while the recovery clock for the 4-hour objective still runs from T.

Good Cyber Habits for Intermediaries

HabitWhy it matters
Use strong, unique passwords and turn on MFAStolen passwords are a leading cause of account takeovers
Install updates promptly on phones and laptopsPatches close known vulnerabilities
Lock and encrypt devices, and never leave them unattendedLost devices are a common source of breaches
Be suspicious of unexpected links, attachments and urgent payment requestsPhishing and impersonation scams target intermediaries and customers
Verify websites and contact details through official channelsFake websites and numbers imitate insurers and regulators
Share customer data only through approved, secure channelsPersonal email and chat apps bypass corporate controls
Avoid unsecured public Wi-Fi for client workTraffic on open networks can be intercepted
Report suspected incidents immediatelyEarly reporting lets the firm contain damage and meet notification deadlines

Important

A cyber incident involving personal data may also be a PDPA data breach. If it is notifiable, the PDPC must be told within 3 calendar days (Section 11.3), separately from any notification to MAS.

Test Your Knowledge

Which of the following is one of the six requirements in MAS Notice FSM-N04 on Cyber Hygiene?

A

Reporting every incident to the PDPC within 1 hour

B

Maintaining a written set of security standards for every system

C

Appointing a Data Protection Officer

D

Validating a 4-hour recovery time objective for every system

Test Your Knowledge

Under MAS's Notice on Technology Risk Management, how quickly must an insurer notify MAS after discovering a relevant IT incident?

A

Within 14 days

B

Within 3 calendar days

C

As soon as possible and not later than 1 hour

D

At the next annual regulatory return submitted to MAS

Test Your Knowledge

For which accounts does Notice FSM-N04 require multi-factor authentication?

A

Admin accounts on critical systems, and accounts used to reach customer data online

B

Only customer accounts on the insurer's website

C

Only accounts used by individual agents

D

Every user account on every system the insurer uses, including internal test systems

Sections you finish are checked off in the contents.

Congratulations!

You've completed this section

Continue exploring other exams