CYB-25 · Cyber security
Almost all SA short-term insurance brokers depend on a single Policy Administration System. A ransomware attack on the PAS vendor — or a cloud outage — can render the broker operationally blind. The risk of this dependency must be explicitly assessed, with documented manual fallback procedures and SLA-backed recovery commitments from the vendor.
Trigger
PAS vendor dependency not documented in risk register; no manual fallback procedures for PAS outage; PAS vendor has not provided cyber security assurance or SLA for recovery from a cyber incident
Applicability gate
This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.
Citation
This control maps to the public instruments below. The mapping does not establish entity applicability.
Remediation
Document the PAS vendor as a critical single point of dependency. Obtain the vendor's Business Continuity and Disaster Recovery plan. Define manual fallback procedures (paper-based policy documentation) for 48-hour outage scenario. Review vendor's cyber insurance status.
Evidence required