A Practical Guide to GL20 Compliance Using Picus
| April 08, 2026
Executive Summary
The Insurance Authority's (IA) Guideline on Cybersecurity GL20 sets the minimum cybersecurity standard for authorized insurers operating in Hong Kong. It requires insurers to put resilient cybersecurity measures in place to protect business data, policyholder information, and operational continuity.
GL20 is backed by the Cyber Resilience Assessment Framework CRAF, a structured assessment that measures both inherent cyber risk and the maturity of an insurer's cybersecurity controls. CRAF assessments must be submitted to the IA, and the results carry real consequences. They determine the level of controls an insurer is expected to meet, and gaps must be remediated within defined timelines.
The challenge is that CRAF does not just ask whether controls exist. It asks whether they work. Across domains covering governance, identification, protection, detection, response, and recovery, situational awareness, and third-party risk management, insurers must demonstrate that their cybersecurity controls are implemented and effective against real threats.
This is where Picus changes the GL20 compliance experience. Picus validates the security controls that CRAF evaluates and converts technical control performance into objective, auditable evidence that supports GL20 requirements.
Showing GL20 Compliance with Evidence
GL20 and CRAF define what authorized insurers are accountable for, but demonstrating that controls actually work in practice is where most compliance programs struggle. Controls are documented, tools are deployed, and periodic assessments are performed. Between assessment cycles, assumptions are made that controls continue to behave as expected.
The problem is that insurer environments do not stand still. Detection rules degrade, network segmentation weakens after changes, access controls drift, and new attack techniques emerge without being tested against existing defenses. When control effectiveness is assumed rather than proven, GL20 compliance becomes fragile. Assessment results rely on incomplete visibility, and remediation plans lack operational proof.
GL20 was designed to prevent this gap. Picus helps operationalize its intent by validating the security controls that CRAF evaluates and testing whether they block, detect, or contain real attack techniques that could compromise insurer systems, policyholder data, or business operations. This shifts GL20 compliance from documentation to evidence.
GL20 - Section 4: Overview of CRAF
"CRAF is a structured assessment framework under which authorized insurers can evaluate their inherent risks and maturity levels of their cyber resilience using a set of risk indicators, control principles, and calculation methodologies." (CRAF, Chapter 1.1.1)
CRAF is a structured assessment framework that helps authorized insurers evaluate their inherent cyber risk and the maturity of their cybersecurity controls against prescribed control principles. By adopting CRAF, insurers assess their risk exposure, measure their actual cybersecurity maturity, and identify gaps that require remediation.
CRAF comprises three main elements: an inherent risk assessment that determines the insurer's risk exposure; a cybersecurity maturity assessment that evaluates actual controls against the level expected for that risk rating; and a submission protocol for reporting results and remediation plans to the IA.
How Picus supports this requirement
CRAF requires insurers to evaluate whether their cybersecurity controls meet the maturity level expected for their risk profile, not just whether controls are documented. Picus supports CRAF by validating the effectiveness of the security controls that underpin each maturity domain. Instead of relying on configuration reviews or policy documentation alone, Picus tests whether controls actually prevent, detect, and respond to attack techniques relevant to the insurer's environment. This produces the kind of operational evidence that strengthens CRAF assessment results and gives assessors and validators objective data to work with.
CRAF Appendix - Chapter 3: Cybersecurity Maturity Assessment
"Authorized insurers should apply the prescribed set of control principles stated in the Cybersecurity Maturity Assessment Matrix in Annex B to evaluate their actual cybersecurity controls maturity level against the prescribed control principles applicable to them." (CRAF, Chapter 3.1)
The cybersecurity maturity assessment evaluates an insurer's actual controls against the control principles prescribed across seven domains, including Governance, Identification, Protection, Detection, Response and Recovery, Situational Awareness, and Third Party Risk Management. Each insurer's inherent risk rating determines the grade of control principles it must achieve. Low risk insurers are expected to meet Baseline controls, medium risk insurers must meet both Baseline and Intermediate controls, and high risk insurers are required to meet Baseline, Intermediate, and Advanced controls. The insurer must achieve 100 percent of the applicable control principles to meet its expected maturity level.
How Picus supports this requirement
The maturity assessment requires insurers to demonstrate that each applicable control principle is fulfilled, not merely planned. Picus validates the security controls mapped to these control principles by testing them against real attack techniques. For each domain, from access control and data protection to detection and incident response, Picus produces evidence showing whether the control operates as intended. Where controls fall short, Picus identifies the specific gap and provides vendor-specific guidance on what to fix. This turns the maturity assessment from a documentation exercise into a defensible, evidence-backed evaluation.
CRAF Appendix - Chapter 1: Assessment Approach
"Assessors are required to perform both design effectiveness review and operating effectiveness testing of an authorized insurer's cybersecurity controls." (CRAF, Chapter 1.2.5)
CRAF applies to all authorized insurers carrying on insurance business in or from Hong Kong, with specified exceptions. Assessments must be conducted at least every three years, with results submitted within 12 months (high risk) or 18 months (low/medium risk) of the effective date, and every three years thereafter. For insurers with medium or high inherent risk ratings, assessors must hold prescribed qualifications, and independent validation may be required. Assessors must perform both design effectiveness review and operating effectiveness testing, with sample-based testing covering at least the preceding 6 months for first-time assessments and 12 months for subsequent ones.
How Picus supports this requirement
CRAF's assessment approach demands operating effectiveness testing, meaning evidence that controls work in practice and not just on paper. Picus supports this by providing validated, time-stamped evidence of control performance that assessors can reference when evaluating whether controls meet design and operating effectiveness requirements. Because Picus validates controls on an ongoing basis, insurers can maintain assessment-ready evidence throughout the three-year cycle rather than scrambling to produce it when an assessment is due. This also supports ad hoc assessments requested by the IA, where current evidence of control effectiveness may be needed on short notice.
CRAF Appendix - Chapter 2: Inherent Risk Rating Assessment
"The Inherent Risk Assessment Matrix in Annex A is used to evaluate an authorized insurer's inherent risk profile, which represents the insurer's cyber risk exposure based on its nature of business, company size, transaction volumes, and cyber attack history." (CRAF, Chapter 2.1)
The inherent risk assessment evaluates an insurer's cyber risk exposure across five categories: technologies and connection types, delivery channels, products and technology services, organizational characteristics, and external threats. Each indicator is rated High, Medium, or Low based on prescribed criteria, and the overall rating is determined by counting and comparing the distribution of indicator ratings.
How Picus supports this requirement
While the inherent risk assessment is primarily a self-evaluation of business and operational characteristics, several indicators directly relate to the effectiveness of the insurer's security posture, particularly the external threats category, which considers the history and types of cyber attacks. Picus helps insurers understand their actual attack surface by validating whether controls protect against the specific attack types referenced in the risk matrix, including malware, ransomware, SQL injection, and cross-site scripting. This gives insurers a grounded view of their exposure and helps ensure the risk assessment reflects operational reality rather than assumptions.
CRAF Appendix - Domain 5.5: Threat Intelligence Based Attack Simulation (TIBAS)
"Insurers should use threat intelligence analysis to formulate end-to-end cyber attack testing scenarios tailored to them and the insurance sector generally … to simulate real-life attacks conducted by competent adversaries. A minimum of three end-to-end cyber attack scenarios shall be covered in the simulation." (CRAF, Annex B, Domain 5.5)
Insurers with medium or high inherent risk ratings must conduct threat intelligence based attack simulations. TIBAS requires insurers to use threat intelligence analysis to formulate end-to-end cyber attack testing scenarios tailored to their organization and the insurance sector, simulating real-life attacks conducted by competent adversaries. A minimum of three end-to-end attack scenarios must be covered, testing must be conducted in a production environment where feasible, and it must assess human, process, and technology elements together. TIBAS must be performed at least every three years or after significant changes that could materially increase security risk.
How Picus supports this requirement
TIBAS is one of the most operationally demanding requirements in CRAF. It calls for intelligence-led, end-to-end attack simulation rather than isolated vulnerability scanning or penetration testing of a single system. Picus supports TIBAS by enabling insurers to validate their defenses against realistic, multi-stage attack scenarios mapped to current threat intelligence. Picus tests whether controls detect and prevent the tactics, techniques, and procedures that real adversaries would use against insurer environments. This provides the evidence TIBAS demands, validated outcomes showing how the insurer's defenses perform against tailored attack scenarios, with clear identification of gaps in detection and response.
GL20 - Section 8: Continuous Monitoring
"Insurers should establish systematic monitoring processes for early detection of cybersecurity incidents; regularly evaluate the effectiveness of internal control procedures; and update the risk appetite and tolerance limit as appropriate." (GL20, Section 8.1)
GL20 requires insurers to establish systematic monitoring processes for early detection of cybersecurity incidents, regularly evaluate the effectiveness of internal control procedures, and update their risk appetite as appropriate. Monitoring measures should include network monitoring, testing, internal audit, and external audit. Insurers should test all elements of their cybersecurity framework at least annually using methodologies such as vulnerability assessment, scenario-based testing, and penetration testing.
How Picus supports this requirement
Continuous monitoring means more than deploying monitoring tools; it means regularly validating that those tools actually detect what they should. Picus supports this requirement by testing whether detection controls, network monitoring, and security tools identify and respond to real attack behaviors. Rather than waiting for an annual test to discover that a detection rule has silently failed or that a monitoring gap has opened, Picus validates detection and prevention controls on an ongoing basis. This gives insurers confidence that their monitoring processes work as intended and surfaces issues before they become audit findings.
CRAF Appendix - Domain 4: Detection
"A process is in place to detect anomalous activities through monitoring across the environment." (CRAF, Annex B, Domain 4.2.2 - Baseline)
CRAF's Detection domain covers vulnerability detection, anomaly activity detection, cyber incident detection, and threat monitoring and analysis. Control principles range from maintaining updated antivirus tools and conducting penetration testing at Baseline, to behavioral analysis, EDR solutions, and correlated log analysis at Intermediate and Advanced grades. Insurers must demonstrate that they can detect anomalous activities, monitor customer transactions, and identify emerging threats.
How Picus supports this requirement
Detection is where the gap between deployed and effective is most visible. Picus validates whether detection controls such as EDR, SIEM, and log monitoring tools actually trigger when they should. By simulating the attack techniques that these controls are supposed to catch, Picus identifies silent failures, misconfigured rules, and detection blind spots. This produces direct evidence of detection effectiveness for each applicable control principle, and where detection fails, Picus provides vendor-specific guidance on what to tune or fix to close the gap.
CRAF Appendix - Domain 3: Protection
"Identification and authentication are required to manage the access to systems, applications, and devices." (CRAF, Annex B, Domain 3.1.1 - Baseline)
CRAF's Protection domain covers access control, infrastructure protection, data protection, secure development, patch and change management, and remediation management. Control principles span from basic access controls and network perimeter defenses at Baseline, through privileged account management and data loss prevention at Intermediate, to defense-in-depth network segmentation and cryptographic governance at Advanced.
How Picus supports this requirement
Protection controls are only as good as their ability to stop real attacks. Picus validates whether access controls, network segmentation, endpoint protections, and data security mechanisms actually prevent unauthorized access, lateral movement, and data exfiltration. By testing these controls against realistic attack techniques, Picus shows where protection holds and where it breaks down, giving insurers evidence that their protective controls meet the applicable control principles and clear direction on what to remediate where they fall short.
GL20 - Section 7: Risk Identification, Assessment and Control
"Insurers should identify cyber risks and conduct assessment on the effectiveness of the mitigating measures to protect against and manage cyber risks within the risk appetite and tolerance limit set by the Board or its designated management team." (GL20, Section 7.1)
GL20 requires insurers to identify cyber risks and assess the effectiveness of mitigating measures within the risk appetite set by the Board. This includes identifying business functions and maintaining a current inventory of information assets and system configurations, evaluating inherent cyber risks, and conducting business impact analysis covering threat identification, vulnerability assessment, likelihood, and impact.
How Picus supports this requirement
Risk identification is only as useful as the evidence behind it. Picus supports this requirement by validating whether the controls that mitigate identified cyber risks actually work in practice. Instead of relying on theoretical risk scores or configuration reviews, insurers can test whether their defenses prevent the specific threats and vulnerabilities identified in their risk assessments. This produces evidence that strengthens the link between risk identification and control effectiveness, showing the Board and the IA that the insurer's risk management is grounded in validated outcomes, not assumptions.
Making GL20 Compliance Resilient with Validation
GL20 and CRAF were not designed as documentation exercises. Their purpose is to ensure that the cybersecurity controls protecting insurers, policyholders, and the Hong Kong insurance market operate effectively in practice.
Picus helps insurers move from periodic, assumption-based compliance to evidence-based assurance. By validating control effectiveness against real attack behavior, Picus turns GL20 compliance from a three-year obligation into a defensible, continuously maintained control posture.
Get your demo and support GL20 compliance with audit-ready evidence.
