News
Print Article

JFSC Supervises Persons, OES and Cyber Security (Jersey) Law 2026 – Commencement Dates start on 21 July 2026

22/07/2026

Introduction

  • Only banks are legally designated as Operators of Essential Services – OES.
  • Every other JFSC-registered firm already carries a binding duty to manage cyber risk and report incidents under the Codes.
  • A single cyber incident involving personal data can (and frequently will) require notifications to:
  1. JFSC (Codes – already live),
  2. JOIC (Data Protection (Jersey) Law 2018 – already live),
  3. JCSC (only if the firm is an OES bank – from 1 Dec 2026).
  • Firms that treat “cyber” as a single silo will miss deadlines.
  • The new Law simply raises the political and supervisory temperature.
  • Firms that treat “we’re not an OES” as a free pass are exposing themselves to regulatory, client, and insurance risks that are already live and will only intensify after 1 September.

This briefing captures key issues for all financial services to consider

1. What has happened?

  • On Friday 17 July 2026, the Minister for Sustainable Economic Development made the Cyber Security (Jersey) Commencement Order 2026 (RO-086-2026).

Full original source:

The Order brings the Cyber Security (Jersey) Law 2026 (L-22-2026) into force in two stages:

Full Law (as enacted):

2. Who is legally caught? (Operators of Essential Services – OES)

Within the financial services sector, the Law is deliberately narrow. Schedule 3, Part 3 designates only the Banking subsector:

  • Entities carrying on deposit-taking business that require registration under Part 2 of the Banking Business (Jersey) Law 1991.
  • There is no size or materiality threshold.
  • Every JFSC-registered bank is automatically an OES.

All other JFSC-registered persons (TCBs, FSBs, investment businesses, fund services businesses, insurance intermediaries, money-service businesses, etc.) fall outside the statutory OES regime.

3. Core obligations that will apply to OES banks from 1 December 2026

  • Notify the Minister that they are an OES (and keep contact details current).
  • Take appropriate and proportionate technical and organisational measures to manage cyber risk to the systems that support the essential service (identify, protect, detect, respond, recover; confidentiality, integrity, availability, authenticity and non-repudiation).
  • Report any significant cyber incident to the Director of JCSC as soon as reasonably practicable and in any event within 24 hours of becoming aware.
  • Comply with any Ministerial direction to implement specific security measures or remedial steps after an incident.
  • Civil penalties of up to ~£10,000 (and potential criminal liability for false/misleading information).

Guidance is expected from the Director of JCSC before the December commencement.

4. Why every other JFSC-registered firm (i.e. those not legally caught) must still take notice

This is the critical point that many firms are currently missing.

a) The JFSC Codes of Practice already impose a full cyber-risk obligation on every registered person

  • Principle 3 (and the near-identical wording across all sector Codes) requires a registered person to:
  • understand and manage the risks to its business and customers, including cyber-security risks.
  • The JFSC’s long-standing guidance is explicit that this includes a documented, tested ability to identify, protect, detect, respond and recover. Source: https://www.jerseyfsc.org/industry/risk/cyber-security/understanding-your-regulatory-obligations/
  • Banks simply acquire an additional statutory layer. Everyone else already has the first, enforceable layer.

b) Incident reporting to the JFSC is already mandatory for all registered persons

The Codes require disclosure of any matter that:

  • Is relevant to the JFSC’s supervisory functions,
  • Might reasonably be expected to affect the person’s registration,
  • Or is in the interests of clients/investors to disclose.

As a minimum, the JFSC expects notification of any cyber incident that:

  • Risks unauthorised access to client information,
  • Risks misappropriation of client assets,
  • Involves significant/widespread compromise of systems,
  • May have a material detrimental impact on the firm or Jersey, or
  • Is likely to result in non-compliance with laws or Codes.
  • A serious cyber event will almost always trigger this duty – whether or not the firm is an OES.

c) Three parallel reporting clocks already exist

A single cyber incident involving personal data can (and frequently will) require notifications to:

  • JFSC (Codes – already live),
  • JOIC (Data Protection (Jersey) Law 2018 – already live),
  • JCSC (only if the firm is an OES bank – from 1 Dec 2026).
  • Firms that treat “cyber” as a single silo will miss deadlines.

d) Supervisory and enforcement reality

  • The new Law elevates cyber resilience as a systemic issue for Jersey. The JFSC will inevitably raise its expectations and scrutiny of the cyber risk management frameworks of all registered persons.
  • When examining firms, the JFSC already asks for cyber risk assessments, policies, testing evidence and board oversight. The existence of a new statutory regime for banks will make any gap in a non-bank firm’s arrangements look more stark.
  • Reputation and insurance markets are already moving. Insurers and counterparties increasingly expect NIST/ISO/Cyber Essentials-level maturity regardless of legal designation.

e) Future-proofing

  • The Minister has power (by Regulations) to expand the list of essential services.
  • The original consultation contemplated a wider financial-services net. While the enacted Law is narrow, the direction of travel is clear. Firms that wait until they are designated will be playing catch-up under time pressure.

5. Practical next steps for non-OES JFSC firms (recommended by 1 September 2026)

  1. Confirm board/senior management awareness of the new Law and the existing Codes obligation.
  2. Map current cyber risk framework against the five functions (Identify / Protect / Detect / Respond / Recover) and the JFSC’s published expectations.
  3. Test incident response plans specifically for the multi-regulator notification matrix (JFSC + JOIC ± JCSC).
  4. Ensure cyber risk sits inside the firm’s overall risk management and compliance monitoring frameworks (not a separate IT spreadsheet).
  5. Consider voluntary engagement with JCSC (pre-registration form is already live on jcsc.je) – free advice sessions and the Cyber Shield program remain open to all.

Key sources  

JERSEY YOUTUBE-IMAGE CYBER JFSC

The Team

Meet the team of industry experts behind Comsure

Find out more

Latest News

Keep up to date with the very latest news from Comsure

Find out more

Gallery

View our latest imagery from our news and work

Find out more

Contact

Think we can help you and your business? Chat to us today

Get In Touch

News Disclaimer

As well as owning and publishing Comsure's copyrighted works, Comsure wishes to use the copyright-protected works of others. To do so, Comsure is applying for exemptions in the UK copyright law. There are certain very specific situations where Comsure is permitted to do so without seeking permission from the owner. These exemptions are in the copyright sections of the Copyright, Designs and Patents Act 1988 (as amended)[www.gov.UK/government/publications/copyright-acts-and-related-laws]. Many situations allow for Comsure to apply for exemptions. These include 1] Non-commercial research and private study, 2] Criticism, review and reporting of current events, 3] the copying of works in any medium as long as the use is to illustrate a point. 4] no posting is for commercial purposes [payment]. (for a full list of exemptions, please read here www.gov.uk/guidance/exceptions-to-copyright]. Concerning the exceptions, Comsure will acknowledge the work of the source author by providing a link to the source material. Comsure claims no ownership of non-Comsure content. The non-Comsure articles posted on the Comsure website are deemed important, relevant, and newsworthy to a Comsure audience (e.g. regulated financial services and professional firms [DNFSBs]). Comsure does not wish to take any credit for the publication, and the publication can be read in full in its original form if you click the articles link that always accompanies the news item. Also, Comsure does not seek any payment for highlighting these important articles. If you want any article removed, Comsure will automatically do so on a reasonable request if you email info@comsuregroup.com.