There was a time when retirement plan fiduciary discussions focused mostly on investments and fees. While those topics still matter, there is another issue squarely on the list.

Cybersecurity

Retirement plans hold sensitive personal and financial information, and participant accounts are attractive targets for fraud and cybercrime. Therefore, cybersecurity is no longer just an IT matter. It has become part of prudent plan oversight.

Plan sponsors do not need to become cybersecurity experts, and no one expects the retirement committee to become fluent in computer jargon. However, fiduciaries do need to understand that protecting plan data and monitoring service provider controls are part of a responsible governance process. This may include asking questions such as:

  • Do you have a cybersecurity policy?
  • What cybersecurity measures do your service providers have in place?
  • How are participant accounts protected against unauthorized access?
  • What authentication and fraud-prevention tools are you using?
  • How is sensitive data stored and transmitted?
  • How often are security controls reviewed or tested?
  • Do you conduct periodic cybersecurity awareness training?
  • Do you have an incident response process?

Cybersecurity oversight also includes internal practices. Weak internal controls, poor password habits, lax access management, or unclear procedures around distributions and account changes can all create risk. The core fiduciary concept here is the same as in the other areas – prudence.

A prudent process means understanding the risk, evaluating relevant protections, choosing qualified providers, and documenting oversight. It does not require perfection. It does require careful attention.

Because when retirement plan assets and participant data are involved, “we assumed the vendor had that covered” is not the response anyone wants to hear after a breach.

Cybersecurity may not get your heart racing in a good way, but it is essential.

If cybersecurity has not yet become part of your plan governance discussions, it is time to add it to the agenda. To help you with that discussion, here is a link to the Department of Labor’s Cybersecurity Program Best Practices.

Categories: Fiduciary

Allison Hennessy

Allison Hennessy is co-owner of TNJ Retirement Partners LLC and a credentialed retirement plan professional with extensive experience in the qualified retirement plan space. She holds the ERPA, QPA, and QKA credentials and helps employers, advisors, and CPA partners understand complex retirement plan rules and make informed, practical decisions.