← SA-Specific Risk Factors

CYB-32 · Cyber security

Cyber insurance alignment — cyber insurance in place; declared controls verified to match actual implementation

Cyber-insurance applications may ask the applicant to declare whether controls such as MFA, backups and incident response are implemented. Those declarations should be checked against current evidence before submission. A Provantis readiness assessment can organise that evidence but does not determine coverage or guarantee claim acceptance.

High priority

Trigger

When this rule fires

No cyber insurance in place; cyber insurance application declarations not verified against actual controls; significant gap between declared and actual MFA, backup, or IRP status

Applicability gate

Confirm the entity's role before treating this as a duty

This is a readiness rule mapped to JS2 themes. Its presence in the library does not establish that JS2 applies directly to the firm.

  • Insurance Broker: Most independent non-life Category I brokers are not directly in JS2's defined scope. A broker may be directly in scope if it separately meets a listed category, and may face contract or oversight requirements from an in-scope institution. Third-party provisions impose duties on the in-scope financial institution. They do not themselves make every supplier or intermediary directly subject to JS2.
  • Uma Binder Holder: UMA or binder-holder status is not itself listed in JS2's definition. Direct scope depends on another listed capacity; insurer contracts and oversight may create evidence requirements. JS2 paragraph 3.3 concerns juristic persons structured under an insurer or designated insurance group; it is not a blanket rule for every independent UMA or intermediary.
  • Insurer: An insurer as defined in the Insurance Act is directly in scope of JS2 from 1 June 2025. Apply proportionality and distinguish the insurer's own duty from requirements it places on third parties.

Citation

Mapped source

This control maps to the public instruments below. The mapping does not establish entity applicability.

Section
Joint Standard 2 of 2024 / FAIS Act risk management / Cyber insurance best practice
Legislation
  • Joint Standard 2 of 2024
  • FAIS Act

Remediation

How to close the gap

Obtain cyber insurance if not in place. Before renewal, conduct an Provantis cyber audit to verify all declared controls match actual implementation. Address any gaps before submission. Retain the Provantis audit report as evidence of controls at the time of declaration.

Evidence required

Evidence to prepare if this control applies

  • Current cyber insurance policy schedule
  • Insurance application/renewal declaration
  • Provantis cyber audit report confirming controls alignment
  • Gap analysis between declared and actual controls