Th e European Insurance and Occupational Pensions Authority (EIOPA) issued a consultation paper on the 13th March 2020, proposing guidelines on information and communication technology (ICT) security and governance, which will apply from 1st July 2021. In this paper, we aim to determine the perceived eff ectiveness, (i.e. effi ciency, relevance, coherence and benefi t) of the proposed guidelines, by carrying out a survey and discussions with targeted users (Practitioners / Controllers / Regulators in the area of Insurance) and bringing to light their various concerns and recommendations. Th ese guidelines are very superfi cial and generic and they do not reach the purpose for what they were set. Moreover, although they require that specifi c identifi ed risks are addressed they are not specifi c in addressing the how and when and leave it up to the organisations to determine this. Measurability of results is another issue, which makes it very diffi cult for compliance and enforcement to determine when and how to act, even in terms of proportionality. Th erefore, although the guidelines are clear in what they want to achieve, their eff ectiveness of the approach leaves much to be desired and is considered by respondents as creating more confusion than good and can turn out to be just another scope for duplication of eff orts and data collection overspill with no added value.