Benefits Think How cybersecurity threats are affecting retirement plans

Published Updated 7 Min Read

  • Consider a framework on which to base the strategy. Possibilities include the NIST framework, SAFETY Act, and industry-based initiatives, including SPARK Institute and the AICPA. In most cases, retirement plan cybersecurity risk management ideally is integrated with the cybersecurity strategy of the entity’s core business.
  • Own the strategy. Identify and document who has what responsibilities for strategy implementation and updating within the organization.
  • Understand the data. What is it, what is it used for, where is it stored? How is data accessed? Is access properly controlled and limited to those personnel who need access? When and how is data encrypted? Is the data collected limited to only what is minimally required? What data needs to be retained and when should it be destroyed?
  • Consider whether an external certification, such as an AICPA Service Organization Control 2 (SOC2) report, is an appropriate measure to enhance security compliance and streamline testing procedures. Determine the frequency and type of systems testing, which might include threat detection, penetration testing, testing of backup and recovery plans, and systems resiliency testing. Establish how often and to whom the testing results should be provided, and how reports will be memorialized in the plan’s official records.
  • Require screening and background checks of new personnel with direct or indirect access to benefit plan data, and provide ongoing cybersecurity training.
  • Identify all service providers and their vendors with access to plan data, and request and evaluate their cybersecurity programs and controls, including encryption and transmission protocols. Determine whether the service provider uses any external review of controls, such as SOC2 reports or industry certifications. Consider the frequency and manner for monitoring service providers’ cybersecurity systems, and whether testing is appropriate to assess service provider risk and compliance.
  • Review, and amend as necessary, service provider agreements to ensure there are appropriate contractual obligations for data protection and a fair allocation of liability risk. Consider the extent to which the agreement should address compliance with applicable data privacy laws, relevant industry standards or certifications, requirements regarding data encryption and destruction of data, obligations of the parties in the event of a cybersecurity breach, and the extent of service provider’s liability for cybersecurity breaches.
  • Determine the level and type of insurance coverage the service provider maintains, including the extent of coverage provided for cybersecurity breaches, and whether and to what extent third-party loses are covered.
Eugene S. Griggs
Partner

Eugene S. Griggs is partner at Poyner Spruill, LLP. He has practiced in the employee benefits and executive compensation area for more than 20 years advising public, private, nonprofit and … Read full bio


For reprint and licensing requests for this article, click here.


More From Employee Benefit News

Sign Up Form

Login Modal Form