Jersey’s financial watchdog says it has overhauled its cybersecurity and data protection measures after two significant data breaches emerged last year that drew scrutiny and challenged its reputation.
The first of the breaches, revealed in March 2024, involved a flaw that left the confidential data of nearly 67,000 individuals publicly accessible via the Jersey Financial Services Commission (JFSC) for three years.
Another incident in July of the same year saw the “non-public information” of 261 individuals became publicly available for three days following an issue during system maintenance.
Published yesterday, the JFSC’s 2024 annual report outlined for the first time the full extent of the reforms the regulator had since undertaken.
The watchdog said it took “immediate and robust action” after the breaches, commissioning an independent forensic review to fully understand the root causes.
As part of its response, the JFSC has appointed a new dedicated Data Protection Officer, strengthened its governance framework, and enhanced staff training to “foster a culture of vigilance and compliance”.
It also invested heavily in its broader cybersecurity capability, according to the report, achieving both ISO 27001 and Cyber Essentials certifications – international standards which ordinarily serve as a market of robust information security systems.
Speaking of the two incidents, the watchdog said in the 2024 annual report said: “This fell short of the high standards we set for ourselves in relation to safeguarding sensitive information.”
The report continued: “We acknowledge the concern these incidents caused and want to assure our stakeholders that we took immediate and robust action to address these.”
The new measures, it said, “demonstrate our commitment to protecting sensitive information and maintaining the trust of our stakeholders”.
“We are confident that the steps we have taken will significantly reduce the risk of future breaches and ensure that our data protection practices meet the highest standards of integrity and security.”
The breaches came against a backdrop of growing international risks. The JFSC’s horizon scanning identifies cybersecurity threats, emerging technologies and geopolitical instability as key risks facing financial centres like Jersey in the coming years.
It states: “By keeping track of emerging technologies and their potential impacts, we continue to assess and adjust our risk appetite to support the ongoing competitiveness of Jersey.”
Alongside its internal reforms, the JFSC’s report also outlined how it had ramped up its technology strategy, including the launch of an AI-powered regulatory chatbot, a new data strategy to reduce industry burden, and an overhaul of its back-office systems.
Data included in the report also showed that full-time permanent staff at the JFSC grew by 7% in 2024.
Of the regulator’s £32.4 million total operating costs – up £2.3 million in 2023 – £22.6 million was spent on staff in 2024.
Employee turnover was at 19% in 2024, up from 14% in 2023, and the average employee spends just 4.5 years in their job.
Director General Jill Britton – who took home a total of £370,450 last year, £31,000 more than in 2023 – previously told Express that the regulator, like other businesses, had felt the effect of the ‘Bean Drain’ and had been motivated to put more focus on recruitment and retention.
She said the desire for the organisation was to grow its own staff, with the JFSC currently sponsoring two University College Jersey students annually, who work four days a week and study on the fifth. Internal upskilling is also a priority.
But she also recognised that part of the solution may lie beyond the island.
A green paper last year collected ideas for the future – including the suggestion that the requirement for some compliance resources to be employed and resident in Jersey could change to reduce pressure on the industry, Mrs Britton explained.
You can read the full report here.
