Learning Objectives:

  • Understand the regulatory reporting requirements for cyber incidents.

  • Identify the timelines for reporting cyber incidents to regulators.

  • Recognise the triggers for mandatory cyber incident reporting.

  • Apply incident classification frameworks to determine reportability.

3.1 The Importance of Cyber Incident Reporting

Effective incident reporting is essential for timely detection, response, and recovery from cyber incidents. The Central Bank of Trinidad and Tobago’s mandatory cybersecurity incident reporting requires all regulated financial institutions to report cybersecurity incidents within twenty-four (24) hours of becoming aware of them . This requirement pertains to incidents that are deemed reportable under the regulatory framework .

3.2 Triggers for Mandatory Reporting

The Central Bank of Trinidad and Tobago’s Guideline specifies that regulated financial institutions are required to report promptly any incidents that may have characteristics of a material nature :

  1. Systemic Impact: Impact has potential consequences for other companies or the domestic financial system .

  2. Financial Market Impact: Impacts the company’s systems affecting financial market settlement, confirmations or payments (e.g., Financial Market Infrastructure), or impact to payment services .

  3. Data Impact: Impacts operations, infrastructure, data and/or systems, including but not limited to the confidentiality, integrity or availability of customer information .

  4. Business Disruption: Disrupts business systems and/or operations, including but not limited to utility or data centre outages or loss or degradation of connectivity .

  5. Disaster Declaration: Causes the disaster recovery teams or plans to be activated or a disaster declaration has been made by a third-party vendor that impacts the company .

  6. Reputational Impact: Impacts a number of external customers and/or negative reputational impact is imminent (e.g., public and/or media disclosure) .

  7. Severity: An incident assessed by the company to be of high or critical severity or ranked Priority/Severity/Tier 1 or 2 based on the company’s internal assessment .

  8. Risk Appetite Breach: Incidents that breach internal risk appetite or thresholds as per the cybersecurity strategy or policy .

3.3 Examples of Reportable Incidents

The Central Bank of Trinidad and Tobago provides examples of incidents that would typically be expected to be reported :

Cyberattacks:

  • A large-scale distributed denial of service (“DDOS”) attack on a cloud service provider, or other critical third-party service provider .

  • Social engineering (via email, social media, phone call, text message, etc.) leading to unauthorised wire transfers or electronic card purchases, the theft of customer deposits, or the loss of sensitive corporate or customer data .

Process and System Failures:

  • Failed batch processing preventing mass salary or pension payments .

  • Card payment processing delays affecting merchant transactions .

  • Application or database upgrades that corrupt customer records or monthly statements .

  • Mobile app updates that cause user authentication issues or inadvertently expose customer data .

Infrastructure Problems:

  • Flooding affecting backup power systems, leading to power failures at multiple locations .

  • Fibre optic cable damage adversely disrupting online services .

3.4 Reporting Timelines

The Central Bank of Trinidad and Tobago has established the following timelines for reporting cyber incidents :

  • Initial Notification: Within 24 hours of becoming aware of a cyber-incident .

  • Complete Cyber Incident Reporting: Within 72 hours of the incident .

  • Subsequent Reporting: Regular updates (e.g., daily) as new information becomes available; ongoing situation updates until incident containment/resolution; post-incident review and lessons learned report following incident closure .

Best Practices for Incomplete Information:
Where specific details are unavailable at the time of the initial report, the institution must:

  • Indicate “information not yet available” .

  • Provide best estimates and all other available details .

  • Include expectations of when additional information will be available .