11.4 Cyber Hygiene and Technology Risk
Key Takeaways
MAS Notice FSM-N04 on Cyber Hygiene, effective 10 May 2024, applies to licensed insurers and to insurance agents other than individuals.
The six cyber hygiene requirements cover administrative accounts, security patches, written security standards, network perimeter defence, malware protection and multi-factor authentication.
Multi-factor authentication is required for administrative accounts on critical systems and for all accounts on systems used to access customer information through the internet.
Under MAS's Notice on Technology Risk Management, an insurer must notify MAS within 1 hour of discovering a relevant incident and submit a root-cause report within 14 days.
Individual practitioners support cyber hygiene through strong authentication, prompt updates, caution with links and attachments, and reporting incidents quickly.
11.4 Cyber Hygiene and Technology Risk
Quick Summary: Cyber hygiene means the basic security practices that keep systems and data safe. MAS Notice FSM-N04 makes six of them legally binding for licensed insurers and corporate insurance agents. MAS's Notice on Technology Risk Management requires insurers to notify MAS within 1 hour of discovering a serious IT incident. Individual practitioners must also follow good habits, because many attacks start with one careless click.
Why Cyber Hygiene Matters in Insurance
Insurers and intermediaries hold large amounts of sensitive data, such as NRIC numbers, bank details, medical reports and claims histories, and they depend on online systems for quotations, payments and claims. A breach can expose customers to identity theft and scams, disrupt service, and lead to regulatory action under both MAS rules and the PDPA. Scammers also impersonate insurers and training bodies, and SCI's own website warns candidates about fraudulent course and examination registrations.
MAS Notice FSM-N04: Notice on Cyber Hygiene
| Item | Detail |
|---|---|
| Legal basis | Section 29(1) of the Financial Services and Markets Act 2022 |
| Issued / effective | Issued 9 May 2024; effective 10 May 2024 |
| Applies to | Licensed insurers, and insurance agents other than individuals and certain persons exempted under the Financial Advisers Act |
| Practical scope | Individual agents work within their principals' and agencies' security controls |
MAS has issued parallel Cyber Hygiene Notices for other types of financial institutions.
The Six Cyber Hygiene Practices
- Administrative accounts: every administrative account on any operating system, database, application, security appliance or network device must be secured to prevent unauthorised access or use. These are accounts with full privileges and unrestricted access.
- Security patches: security patches must be applied to address vulnerabilities in every system, within a timeframe commensurate with the risk posed by each vulnerability. Where no patch is available, controls must be put in place to reduce the risk.
- Security standards: there must be a written set of security standards for every system, and every system must conform to them. Where a system cannot conform, compensating controls are required.
- Network perimeter defence: controls must be implemented at the network perimeter to restrict all unauthorised network traffic, for example through firewalls.
- Malware protection: one or more malware protection measures must be implemented on every system where such measures are available and can be implemented.
- Multi-factor authentication (MFA): required for all administrative accounts on critical systems and for all accounts on any system used to access customer information through the internet.
Key definitions:
- A critical system is one whose failure would significantly disrupt operations or materially affect service to customers, such as systems that process time-critical transactions or provide essential services.
- Multi-factor authentication uses two or more factors: something you know (a password or PIN), something you have (a token or device) or something you are (biometrics or behaviour).
- An entity need not comply with a requirement to the extent it cannot exercise direct or indirect control over a system, and it is not reasonable to switch to a provider over whom it could.
Technology Risk Management: Incidents and Recovery
MAS's Notice on Technology Risk Management for insurers adds incident and resilience requirements:
- Recovery time objective: a recovery time objective of not more than 4 hours for each critical system, validated at least once every 12 months.
- Incident notification: MAS must be notified as soon as possible, and not later than 1 hour, after the discovery of a relevant incident. A relevant incident is a system malfunction or IT security incident with a severe and widespread impact on operations, or a material impact on service to customers.
- Root cause report: a root cause and impact analysis report must be submitted within 14 days of discovery, unless MAS allows longer. It sets out the cause, the impact and the remedial measures.
- Customer information: IT controls must protect customer information from unauthorised access or disclosure.
The MAS FAQs give a timing example. If an incident occurs at time T but is discovered at T+1, MAS must be notified by T+2, while the recovery clock for the 4-hour objective still runs from T.
Good Cyber Habits for Intermediaries
| Habit | Why it matters |
|---|---|
| Use strong, unique passwords and turn on MFA | Stolen passwords are a leading cause of account takeovers |
| Install updates promptly on phones and laptops | Patches close known vulnerabilities |
| Lock and encrypt devices, and never leave them unattended | Lost devices are a common source of breaches |
| Be suspicious of unexpected links, attachments and urgent payment requests | Phishing and impersonation scams target intermediaries and customers |
| Verify websites and contact details through official channels | Fake websites and numbers imitate insurers and regulators |
| Share customer data only through approved, secure channels | Personal email and chat apps bypass corporate controls |
| Avoid unsecured public Wi-Fi for client work | Traffic on open networks can be intercepted |
| Report suspected incidents immediately | Early reporting lets the firm contain damage and meet notification deadlines |
Important
A cyber incident involving personal data may also be a PDPA data breach. If it is notifiable, the PDPC must be told within 3 calendar days (Section 11.3), separately from any notification to MAS.
Which of the following is one of the six requirements in MAS Notice FSM-N04 on Cyber Hygiene?
Reporting every incident to the PDPC within 1 hour
Maintaining a written set of security standards for every system
Appointing a Data Protection Officer
Validating a 4-hour recovery time objective for every system
Under MAS's Notice on Technology Risk Management, how quickly must an insurer notify MAS after discovering a relevant IT incident?
Within 14 days
Within 3 calendar days
As soon as possible and not later than 1 hour
At the next annual regulatory return submitted to MAS
For which accounts does Notice FSM-N04 require multi-factor authentication?
Admin accounts on critical systems, and accounts used to reach customer data online
Only customer accounts on the insurer's website
Only accounts used by individual agents
Every user account on every system the insurer uses, including internal test systems
Sections you finish are checked off in the contents.
You've completed this section
Continue exploring other exams