Skip to content

Tech & Cyber Compliance

Duncan has written numerous articles on this compliance topic in Bermuda’s national newspaper over the last 4 years. Bermuda is experiencing a regulatory explosion related to cybersecurity operational risk management and corporate governance.

As the National Chair of both the “Information Technology Law Group” and the “Defence & National Security Law Practice” at his former law firm in Canada, Duncan has over 20 years of direct experience advising CISOs, CIOs, Chief Risk Officers and in-house counsel less experienced in the specialized field of regulatory compliance issues associated with tech security and cybersecurity compliance obligations, duties and best practices.

Duncan was consulted by the Ministry of National Security on the development of the development of the Cybersecurity Act 2024’s ( Cyber Act ) regulatory compliance prescriptions across the critical infrastructure and essential services that the Cyber Act addresses. At the same time, he has provided advice to many local and multinational financial service enterprises on their compliance with the Bermuda Monetary Authority’s directives, guidance and regulatory requirements related to the operational risk management of information technology, data protection, cybersecurity and the developing regulatory framework of AI and intelligent systems. Duncan has also provided extensive advice to a broad range of clients in the developing field of Digital Assets Service Providers. Now that Duncan has left his legal practice behind, he can now focus on an organization’s day to day operational, administrative, management, governance and compliance strategies that BMA registrants must adopt to fully comply with the business’ license obligations and requirements in Bermuda.

  • Cybersecurity incident or event reporting requirements and administrative compliance requirements
  • Working closely with in-house and external legal counsel as a subject matter expert in cybersecurity compliance
  • How the demands of the Cyber Act, the BMA’s regulations and PIPA overlap and intersect for compliance purposes
  • Assistance with the organization’s operational response to ( and management of ) the Cyber Act’s compliance demands
  • PIPA’s IT security requirements and standards, and governance best practices for organization to ensure they are compliant
  • Personnel and professional training and seminars related to cybersecurity compliance under each of the Cyber Act, the BMA’s regulations and PIPA
  • CIO, CISO and Privacy Office advisory services and support related to the operational requirements of Cybersecurity compliance
  • Presentations to Boards of Directors on all aspects of cybersecurity corporate governance and related best practices.