- Encrypt all sensitive information subject to auto-portability using Advanced Encryption Standard 256-bit encryption, an industry standard developed by the National Institute of Standards and Technology. There is no known type of cyberattack that can read AES-encrypted data without having the cryptographic key.
- Never combine a Social Security number with other personally identifiable information in any single file transfer. The objective should be to ensure there is never enough personal data in any single transmission for a hacker to use to steal an identity. In addition, any file with personal information should never include the identity of either the plan’s sponsor or the record keeper. That further thwarts a hacker from accessing an individual participant’s retirement account.