Lloyd's Minimum Standards - Cyber Security
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access + Privileged + MFA + Vulnerability + MS11.4-5
Lloyds MS11.4 Access Control and Privileged Access Management - identity and access management (IAM) per industry best practice (ISO 27001 A.9 + NIST SP 800-53 AC family) + role-based access control (RBAC) + least privilege + segregation of duties + identity lifecycle (joiner-mover-leaver) + privileged access management (PAM) with vault + session recording + just-in-time access + ephemeral credentials + multi-factor authentication (MFA) mandatory for: (a) all privileged accounts including domain admins + cloud admin consoles + database admins; (b) all remote access (VPN + RDP + SSH); (c) all Internet-facing administrative interfaces; (d) Lloyds-required: claims handling systems + underwriting platforms + financial accounts + customer data access; (e) FCA/PRA-recommended additional MFA for senior managers SMF1-SMF24 access. Customer authentication: Strong Customer Authentication (SCA) for
- IAM + PAM deployment
- MFA enforcement on privileged + remote + admin
- Vulnerability scanning reports
- Patch SLA evidence (Critical 7d + High 30d)
- Coordinated Vulnerability Disclosure programme
- CISA KEV alignment
- No MFA on privileged
- Slow patching
- No vulnerability disclosure
- No CISA KEV monitoring
Awareness + Insider + Pen Test + Assurance + MS11.13-16
Lloyds MS11.13 Security Awareness and Insider Risk - mandatory annual cyber security awareness training for all personnel + Senior Manager Function holders + Board + role-based deep training for IT + security + claims handlers + underwriters + actuaries + finance + legal + DPO + privileged users + phishing simulation programme + Insurance-specific phishing scenarios + Lloyds market fraud awareness + insider threat programme combining technical controls (UEBA + DLP + privileged session monitoring + access review) + non-technical controls (background screening + conflict of interest + clear policies + ethical leadership + Whistleblower Policy + SM&CR conduct rules + Lloyds Code of Conduct + Insurance Distribution Directive (IDD) conduct requirements + UK Senior Managers and Certification Regime SM&CR Conduct Rules + Lloyds market governance) + Lloyds Cyber Security Code of Practice + Insur
- Annual cyber training (all personnel)
- Phishing simulation results
- Insider threat programme
- Annual penetration testing reports
- CBEST/TLPT engagement (where applicable)
- CREST-certified provider engagement
- SOC 2 Type II / ISO 27001 audit reports
- Independent assurance evidence
- No annual training
- No insider threat programme
- No annual pen test
- No SOC 2/ISO 27001
- No independent assurance
Configuration + Network + Perimeter + MS11.6-15
Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-Code (IaC) per HashiCorp Terraform + AWS CloudFormation + Azure ARM + Google Cloud Deployment Manager + golden images + configuration drift detection + change management process aligned with ITIL v4 / ISO 20000 + Lloyds Realistic Disaster Scenarios change impact assessment + segregation of development + test + production environments + production access controls + emergency change process + rollback procedures. MS11.15 Network Segmentation and Perimeter Defence - defense in depth + perimeter security (next-generation firewall + Web Application Firewall + Distributed Denial of Service mitigation + secure remote access via VPN with MFA
- CIS Benchmark configuration evidence
- IaC deployment + drift detection
- Change management process (ITIL/ISO 20000)
- Network segmentation diagram
- ZTNA + SASE deployment
- CSPM/CWPP for cloud
- No configuration baseline
- No drift detection
- Flat network
- No ZTNA
- No CSPM
Governance + Board + Risk + Asset + MS11.1-3
Lloyds of London Minimum Standards 11 (MS11) - Cyber Security developed by Lloyds Performance Management Directorate (PMD) within Society of Lloyds + applicable to all Lloyds managing agents + syndicates + members agents + service companies + Lloyds Insurance Company SA Brussels (post-Brexit EU establishment). Minimum Standards are the prudential baseline expectations Lloyds requires of its market participants + part of broader Lloyds Minimum Standards suite (MS1-19 covering Governance + Risk Management + Underwriting + Reserving + Investment + Reinsurance + Operational Risk + Outsourcing + ICT + Conduct + Capital + etc) + MS11 specifically addresses Cyber Security adopted 2017 + revised 2021/2023. MS11.1 Cyber Security Governance and Board Oversight - Board-level cyber risk oversight + Chief Information Security Officer (CISO) or equivalent + cyber risk appetite + governance forum + cyb
- Board cyber risk reporting cadence
- CISO designation + SMF24 allocation
- Cyber risk appetite statement
- Lloyds Realistic Disaster Scenarios
- Crown Jewels CMDB
- PRA SS1/21 alignment evidence
- No Board oversight
- No SMF allocation
- No risk appetite
- Incomplete CMDB
- No RDS analysis
Incident Response + BC + Recovery + MS11.8-9
Lloyds MS11.8 Cyber Incident Response and Reporting - documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification matrix (severity + impact + urgency) + Triage + Containment + Eradication + Recovery (NIST SP 800-61 Rev 2) + Lessons Learned post-incident review + tabletop exercises (quarterly for high-risk + annually minimum) + functional exercises + red team / purple team engagements + Lloyds-required mandatory incident reporting: significant cyber incidents must be notified to Lloyds Cyber Risk team within 24 hours of detection + parallel PRA notification under SS2/21 (significant operational disruption) within 24 hours + FCA notification under Principle 11 (open and cooperative) + NCSC (UK National Cyber Security Centre) reporting under voluntary CIRP scheme + Action Fraud reporting + ICO breach notification wit
- IRP + CSIRT charter
- 24-hour Lloyds Cyber Risk notification SOP
- PRA SS2/21 24-hour notification SOP
- FCA Principle 11 notification SOP
- ICO 72-hour breach notification
- Important Business Services + Impact Tolerance documentation
- Immutable backup evidence
- Quarterly tabletop exercises
- No 24-hour Lloyds notification
- No PRA/FCA SOP
- No IBS identification
- No Impact Tolerance
- No immutable backup
- No tabletop exercises
Risk Quantification + Reporting + MS11.17-18
Lloyds MS11.17 Cyber Risk Quantification and Capital Linkage - cyber risk quantification methodology aligned with PRA Solvency II + Operational Risk Internal Model (where applicable) + standard formula + cyber-specific stressors + scenario analysis (Lloyds Realistic Disaster Scenarios for cyber + cloud outage + ransomware + supply chain) + FAIR (Factor Analysis of Information Risk) methodology + Monte Carlo simulation + insurance industry loss data including Verisk + Aon + AdvisenLoss + IBM Cost of a Data Breach Report + capital adequacy assessment including Operational Risk Capital + Lloyds-required Member Capital requirements + reinsurance protection + cyber catastrophe reinsurance + parametric cyber consideration + Cyber Risk Aggregation (CRA) market-wide modeling + Lloyds Realistic Disaster Scenarios cyber (extreme scenarios with industry losses USD 100B+ + Lloyds market exposure qua
- FAIR methodology + Monte Carlo simulation
- Lloyds RDS Cyber scenarios
- PRA Solvency II + Operational Risk Capital
- Quarterly Lloyds Cyber Risk Returns
- Annual Lloyds Cyber Security Attestation
- SFCR cyber-risk disclosure
- PRA Form CY01
- Senior Managers Annual Statement
- No quantification methodology
- No RDS Cyber
- No quarterly returns
- No annual attestation
- No SFCR disclosure
Third Party + Cloud + Data + Classification + MS11.10-14-11
Lloyds MS11.10 Third Party and Outsourcing Cyber Risk - comprehensive third-party risk management programme + PRA SS2/21 Outsourcing and Third Party Risk Management requirements + due diligence at onboarding + cyber security questionnaire (SIG + CAIQ + custom) + right-to-audit clauses + SOC 2 Type II + ISO 27001 + ISO 27701 + certifications + ongoing monitoring + concentration risk analysis (PRA-specific concern for cloud concentration with Amazon Web Services + Microsoft Azure + Google Cloud) + critical third-party identification + critical third party (CTP) designation under FSMA 2023 (UK Financial Services and Markets Act 2023 + PRA/FCA/Bank of England CTP designation regime) + supply chain compromise mitigation (SolarWinds + Kaseya + log4j precedents + 3CX + MOVEit) + Software Bill of Materials (SBOM) + service level agreements (SLA) for security + Subprocessor authorisation + termin
- Vendor risk assessment library
- PRA SS2/21 alignment evidence
- Critical Third Party (CTP) designation tracking
- Concentration risk analysis
- Cloud Controls Matrix (CCM) alignment
- 5-tier data classification
- DLP deployment
- UK GDPR + DPA 2018 compliance
- No PRA SS2/21 alignment
- No CTP analysis
- No concentration risk
- No DLP
- No data classification
- UK GDPR gap
Threat Detection + Email + Phishing + MS11.7-12
Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + cloud + application + database + privileged access + cloud trail + container logs + Endpoint Detection and Response (EDR) on all endpoints + Extended Detection and Response (XDR) where deployed + Network Detection and Response (NDR) + Cloud Detection and Response (CDR) + Threat Intelligence integration including commercial feeds + open-source intelligence (OSINT) + Information Sharing and Analysis Centre Insurance (Insurance ISAC) + FS-ISAC for cross-financial-sector intelligence + MITRE ATT&CK and CK framework mapping + tactics + techniques + procedures (TTPs) library + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs) +
- 24/7 SOC capability
- SIEM with use cases
- EDR on all endpoints
- Threat intelligence subscription (Insurance ISAC + FS-ISAC)
- MITRE ATT and CK mapping
- DMARC + SPF + DKIM evidence
- Phishing simulation results
- No 24/7 SOC
- No EDR
- No threat intel
- No phishing simulation
- No DMARC enforcement
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.