TCSPs Cybersecurity, Data Protection, and Resilience Thematic Review
Summary
The Gibraltar Financial Services Commission (GFSC) has published the findings of a thematic review on cybersecurity, data protection, and resilience within the Trust and Corporate Service Providers (TCSPs) sector. The publication outlines areas of strength and weakness, sets minimum standards, and provides clear expectations for TCSPs to enhance their frameworks.
What changed
The Gibraltar Financial Services Commission (GFSC) has released a publication detailing the outcomes of its thematic review concerning cybersecurity, data protection, and resilience among Trust and Corporate Service Providers (TCSPs). The review identifies specific areas where TCSPs are performing well and highlights critical areas requiring improvement, including governance oversight, risk identification and management, and resilience planning. The document aims to establish minimum standards and clear expectations to guide TCSPs in strengthening their operational frameworks, ensuring alignment with international best practices, and maintaining robust systems proportionate to their operational scale and complexity.
Compliance officers in the TCSP sector should review the GFSC's findings and expectations to assess their current cybersecurity, data protection, and resilience measures. The publication provides a roadmap for necessary enhancements, emphasizing the need for robust governance and risk management. While no specific compliance deadline is mentioned, firms are expected to align with the outlined standards to ensure continued regulatory compliance and operational integrity. Failure to address identified weaknesses could lead to future supervisory actions.
What to do next
- Review GFSC thematic review publication on TCSP cybersecurity, data protection, and resilience.
- Assess current governance oversight, risk identification and management, and resilience planning against findings and expectations.
- Implement necessary enhancements to strengthen cybersecurity, data protection, and resilience frameworks.
Source document (simplified)
News
TCSPs Thematic Review Publication
05 Mar 26
Today the Gibraltar Financial Services Commission (GFSC) has published the findings, observations and expectations from the thematic review on cybersecurity, data protection and resilience in the Trust and Corporate Service Providers (TCSPs) sector.
The review highlights areas where firms are performing well and where improvements are needed, including governance oversight, risk identification & management and resilience planning. It also sets out minimum standards and clear expectations to help TCSPs strengthen their frameworks, align with internationally recognised standards, and ensure they remain robust and proportionate to their size and operational complexity.
To read the full publication click here.
Named provisions
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Banking & Finance alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when Gibraltar FSC News publishes new changes.