Skip to content

Evidence request lists

Lloyd's Minimum Standards - Cyber Security

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Access + Privileged + MFA + Vulnerability + MS11.4-5

LLOYDS-MS11-Access-Control-Privileged-MFA-Vulnerability-Patch-Management-MS11-4-5-PRA-Senior-Managers-Regime
Lloyds MS11 Access Control + Privileged + MFA + Vulnerability + Patch + MS11.4-5

Lloyds MS11.4 Access Control and Privileged Access Management - identity and access management (IAM) per industry best practice (ISO 27001 A.9 + NIST SP 800-53 AC family) + role-based access control (RBAC) + least privilege + segregation of duties + identity lifecycle (joiner-mover-leaver) + privileged access management (PAM) with vault + session recording + just-in-time access + ephemeral credentials + multi-factor authentication (MFA) mandatory for: (a) all privileged accounts including domain admins + cloud admin consoles + database admins; (b) all remote access (VPN + RDP + SSH); (c) all Internet-facing administrative interfaces; (d) Lloyds-required: claims handling systems + underwriting platforms + financial accounts + customer data access; (e) FCA/PRA-recommended additional MFA for senior managers SMF1-SMF24 access. Customer authentication: Strong Customer Authentication (SCA) for

Artefacts an auditor will ask for
  • IAM + PAM deployment
  • MFA enforcement on privileged + remote + admin
  • Vulnerability scanning reports
  • Patch SLA evidence (Critical 7d + High 30d)
  • Coordinated Vulnerability Disclosure programme
  • CISA KEV alignment
Where this commonly fails
  • No MFA on privileged
  • Slow patching
  • No vulnerability disclosure
  • No CISA KEV monitoring

Awareness + Insider + Pen Test + Assurance + MS11.13-16

LLOYDS-MS11-Security-Awareness-Insider-Risk-Penetration-Testing-Independent-Assurance-MS11-13-16
Lloyds MS11 Security Awareness + Insider Risk + Pen Testing + Assurance + MS11.13-16

Lloyds MS11.13 Security Awareness and Insider Risk - mandatory annual cyber security awareness training for all personnel + Senior Manager Function holders + Board + role-based deep training for IT + security + claims handlers + underwriters + actuaries + finance + legal + DPO + privileged users + phishing simulation programme + Insurance-specific phishing scenarios + Lloyds market fraud awareness + insider threat programme combining technical controls (UEBA + DLP + privileged session monitoring + access review) + non-technical controls (background screening + conflict of interest + clear policies + ethical leadership + Whistleblower Policy + SM&CR conduct rules + Lloyds Code of Conduct + Insurance Distribution Directive (IDD) conduct requirements + UK Senior Managers and Certification Regime SM&CR Conduct Rules + Lloyds market governance) + Lloyds Cyber Security Code of Practice + Insur

Artefacts an auditor will ask for
  • Annual cyber training (all personnel)
  • Phishing simulation results
  • Insider threat programme
  • Annual penetration testing reports
  • CBEST/TLPT engagement (where applicable)
  • CREST-certified provider engagement
  • SOC 2 Type II / ISO 27001 audit reports
  • Independent assurance evidence
Where this commonly fails
  • No annual training
  • No insider threat programme
  • No annual pen test
  • No SOC 2/ISO 27001
  • No independent assurance

Configuration + Network + Perimeter + MS11.6-15

LLOYDS-MS11-Secure-Configuration-Change-Management-Network-Segmentation-Perimeter-Defence-MS11-6-15
Lloyds MS11 Secure Configuration + Change + Network Segmentation + Perimeter + MS11.6-15

Lloyds MS11.6 Secure Configuration and Change Management - configuration baselines aligned with industry benchmarks (CIS Critical Security Controls v8 + CIS Benchmarks for Windows + Linux + cloud + container + DISA STIGs where applicable) + Infrastructure-as-Code (IaC) per HashiCorp Terraform + AWS CloudFormation + Azure ARM + Google Cloud Deployment Manager + golden images + configuration drift detection + change management process aligned with ITIL v4 / ISO 20000 + Lloyds Realistic Disaster Scenarios change impact assessment + segregation of development + test + production environments + production access controls + emergency change process + rollback procedures. MS11.15 Network Segmentation and Perimeter Defence - defense in depth + perimeter security (next-generation firewall + Web Application Firewall + Distributed Denial of Service mitigation + secure remote access via VPN with MFA

Artefacts an auditor will ask for
  • CIS Benchmark configuration evidence
  • IaC deployment + drift detection
  • Change management process (ITIL/ISO 20000)
  • Network segmentation diagram
  • ZTNA + SASE deployment
  • CSPM/CWPP for cloud
Where this commonly fails
  • No configuration baseline
  • No drift detection
  • Flat network
  • No ZTNA
  • No CSPM

Governance + Board + Risk + Asset + MS11.1-3

LLOYDS-MS11-Governance-Board-Oversight-Risk-Identification-Assessment-Asset-Inventory-MS11-1-2-3-Lloyds-PMD
Lloyds MS11 Governance + Board Oversight + Risk + Asset Inventory + MS11.1-3

Lloyds of London Minimum Standards 11 (MS11) - Cyber Security developed by Lloyds Performance Management Directorate (PMD) within Society of Lloyds + applicable to all Lloyds managing agents + syndicates + members agents + service companies + Lloyds Insurance Company SA Brussels (post-Brexit EU establishment). Minimum Standards are the prudential baseline expectations Lloyds requires of its market participants + part of broader Lloyds Minimum Standards suite (MS1-19 covering Governance + Risk Management + Underwriting + Reserving + Investment + Reinsurance + Operational Risk + Outsourcing + ICT + Conduct + Capital + etc) + MS11 specifically addresses Cyber Security adopted 2017 + revised 2021/2023. MS11.1 Cyber Security Governance and Board Oversight - Board-level cyber risk oversight + Chief Information Security Officer (CISO) or equivalent + cyber risk appetite + governance forum + cyb

Artefacts an auditor will ask for
  • Board cyber risk reporting cadence
  • CISO designation + SMF24 allocation
  • Cyber risk appetite statement
  • Lloyds Realistic Disaster Scenarios
  • Crown Jewels CMDB
  • PRA SS1/21 alignment evidence
Where this commonly fails
  • No Board oversight
  • No SMF allocation
  • No risk appetite
  • Incomplete CMDB
  • No RDS analysis

Incident Response + BC + Recovery + MS11.8-9

LLOYDS-MS11-Cyber-Incident-Response-Reporting-Business-Continuity-Cyber-Recovery-MS11-8-9-PRA-Operational-Resilience
Lloyds MS11 Incident Response + Reporting + Business Continuity + Recovery + MS11.8-9

Lloyds MS11.8 Cyber Incident Response and Reporting - documented Incident Response Plan + Computer Security Incident Response Team (CSIRT) + 24/7 incident hotline + Incident classification matrix (severity + impact + urgency) + Triage + Containment + Eradication + Recovery (NIST SP 800-61 Rev 2) + Lessons Learned post-incident review + tabletop exercises (quarterly for high-risk + annually minimum) + functional exercises + red team / purple team engagements + Lloyds-required mandatory incident reporting: significant cyber incidents must be notified to Lloyds Cyber Risk team within 24 hours of detection + parallel PRA notification under SS2/21 (significant operational disruption) within 24 hours + FCA notification under Principle 11 (open and cooperative) + NCSC (UK National Cyber Security Centre) reporting under voluntary CIRP scheme + Action Fraud reporting + ICO breach notification wit

Artefacts an auditor will ask for
  • IRP + CSIRT charter
  • 24-hour Lloyds Cyber Risk notification SOP
  • PRA SS2/21 24-hour notification SOP
  • FCA Principle 11 notification SOP
  • ICO 72-hour breach notification
  • Important Business Services + Impact Tolerance documentation
  • Immutable backup evidence
  • Quarterly tabletop exercises
Where this commonly fails
  • No 24-hour Lloyds notification
  • No PRA/FCA SOP
  • No IBS identification
  • No Impact Tolerance
  • No immutable backup
  • No tabletop exercises

Risk Quantification + Reporting + MS11.17-18

LLOYDS-MS11-Cyber-Risk-Quantification-Capital-Linkage-Regulatory-Lloyds-Reporting-MS11-17-18-CBEST-FFIEC
Lloyds MS11 Cyber Risk Quantification + Capital + Regulatory + Lloyds Reporting + MS11.17-18

Lloyds MS11.17 Cyber Risk Quantification and Capital Linkage - cyber risk quantification methodology aligned with PRA Solvency II + Operational Risk Internal Model (where applicable) + standard formula + cyber-specific stressors + scenario analysis (Lloyds Realistic Disaster Scenarios for cyber + cloud outage + ransomware + supply chain) + FAIR (Factor Analysis of Information Risk) methodology + Monte Carlo simulation + insurance industry loss data including Verisk + Aon + AdvisenLoss + IBM Cost of a Data Breach Report + capital adequacy assessment including Operational Risk Capital + Lloyds-required Member Capital requirements + reinsurance protection + cyber catastrophe reinsurance + parametric cyber consideration + Cyber Risk Aggregation (CRA) market-wide modeling + Lloyds Realistic Disaster Scenarios cyber (extreme scenarios with industry losses USD 100B+ + Lloyds market exposure qua

Artefacts an auditor will ask for
  • FAIR methodology + Monte Carlo simulation
  • Lloyds RDS Cyber scenarios
  • PRA Solvency II + Operational Risk Capital
  • Quarterly Lloyds Cyber Risk Returns
  • Annual Lloyds Cyber Security Attestation
  • SFCR cyber-risk disclosure
  • PRA Form CY01
  • Senior Managers Annual Statement
Where this commonly fails
  • No quantification methodology
  • No RDS Cyber
  • No quarterly returns
  • No annual attestation
  • No SFCR disclosure

Third Party + Cloud + Data + Classification + MS11.10-14-11

LLOYDS-MS11-Third-Party-Outsourcing-Cyber-Risk-Cloud-Security-Data-Protection-Classification-MS11-10-14-11
Lloyds MS11 Third Party + Cloud + Data Protection + Classification + MS11.10-14-11

Lloyds MS11.10 Third Party and Outsourcing Cyber Risk - comprehensive third-party risk management programme + PRA SS2/21 Outsourcing and Third Party Risk Management requirements + due diligence at onboarding + cyber security questionnaire (SIG + CAIQ + custom) + right-to-audit clauses + SOC 2 Type II + ISO 27001 + ISO 27701 + certifications + ongoing monitoring + concentration risk analysis (PRA-specific concern for cloud concentration with Amazon Web Services + Microsoft Azure + Google Cloud) + critical third-party identification + critical third party (CTP) designation under FSMA 2023 (UK Financial Services and Markets Act 2023 + PRA/FCA/Bank of England CTP designation regime) + supply chain compromise mitigation (SolarWinds + Kaseya + log4j precedents + 3CX + MOVEit) + Software Bill of Materials (SBOM) + service level agreements (SLA) for security + Subprocessor authorisation + termin

Artefacts an auditor will ask for
  • Vendor risk assessment library
  • PRA SS2/21 alignment evidence
  • Critical Third Party (CTP) designation tracking
  • Concentration risk analysis
  • Cloud Controls Matrix (CCM) alignment
  • 5-tier data classification
  • DLP deployment
  • UK GDPR + DPA 2018 compliance
Where this commonly fails
  • No PRA SS2/21 alignment
  • No CTP analysis
  • No concentration risk
  • No DLP
  • No data classification
  • UK GDPR gap

Threat Detection + Email + Phishing + MS11.7-12

LLOYDS-MS11-Threat-Detection-Security-Monitoring-Email-Phishing-Defences-MS11-7-12-SOC-EDR-XDR-SIEM
Lloyds MS11 Threat Detection + Security Monitoring + Email + Phishing + MS11.7-12

Lloyds MS11.7 Threat Detection and Security Monitoring - 24/7/365 Security Operations Centre (SOC) capability internal or via Managed Security Service Provider (MSSP) + Security Information and Event Management (SIEM) covering identity + network + endpoint + cloud + application + database + privileged access + cloud trail + container logs + Endpoint Detection and Response (EDR) on all endpoints + Extended Detection and Response (XDR) where deployed + Network Detection and Response (NDR) + Cloud Detection and Response (CDR) + Threat Intelligence integration including commercial feeds + open-source intelligence (OSINT) + Information Sharing and Analysis Centre Insurance (Insurance ISAC) + FS-ISAC for cross-financial-sector intelligence + MITRE ATT&CK and CK framework mapping + tactics + techniques + procedures (TTPs) library + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs) +

Artefacts an auditor will ask for
  • 24/7 SOC capability
  • SIEM with use cases
  • EDR on all endpoints
  • Threat intelligence subscription (Insurance ISAC + FS-ISAC)
  • MITRE ATT and CK mapping
  • DMARC + SPF + DKIM evidence
  • Phishing simulation results
Where this commonly fails
  • No 24/7 SOC
  • No EDR
  • No threat intel
  • No phishing simulation
  • No DMARC enforcement
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.