Benefits Think Negotiating cybersecurity contractual protections for retirement plans

Published Updated 4 Min Read

  • Compliance with TPA Policies – The TPA should commit to comply with its own cybersecurity policies and agree not to materially degrade the level of security reflected in those policies during the term of the contract. Plan sponsors and/or plan administrators should request copies (or at least summaries) of the TPA’s policies and have their internal IT security personnel review them from a due diligence perspective.
  • Compliance with Applicable Law – The TPA should commit to comply with all U.S. and foreign data security and privacy laws applicable to the TPA’s services.
  • Compliance with Industry Standards – The TPA should commit to meet industry standards relating to data security. For example, the International Organization for Standardization (ISO), which is an international standard-setting body, publishes information security standards codified in ISO 27001 / 27002. It would be reasonable to require that the TPA agree to comply with these standards and maintain ISO 27001 certification.
  • Security Audits – The TPA should commit to have a nationally recognized independent third party conduct annual (or more frequent) audits or reviews of the TPA’s cybersecurity practices at facilities used to deliver the services and provide a copy (or at least a summary) of the audit report to the plan sponsor. One of the more common types of audit reports furnished by service providers is a SOC 2, Type II report under Attestation Standards Section 101 published by the American Institute of Certified Public Accountants. The SOC 2, Type II audit addresses the operating effectiveness of the TPA’s controls relating to security, availability, processing integrity, confidentiality and privacy.
Jeffrey Hutchings
Partner

Hutchings is a partner in Pillsbury's Global Sourcing group, represents clients in complex sourcing transactions.

Jennifer Lutrin
Associate

Lutrin is an associate in Pillsbury's Executive Compensation & Benefits practice and is located in the New York office.

Susan Serota
Partner

Serota leads Pillsbury's Executive Compensation & Benefits practice and is located the New York and Washington, DC offices.


For reprint and licensing requests for this article, click here.


More From Employee Benefit News

Sign Up Form

Login Modal Form