The Department of Labor (DOL) issued three guidelines related to cybersecurity — tips a plan sponsor should look for in a provider, processes plan providers should have in place and online security tips for participants and beneficiaries.
According to the DOL, plan providers should have best practices and processes in place to protect plan assets, including but not limited to the following:
- Have a formal, well-documented cybersecurity program
- Conduct annual risk assessments
- Use third parties to audit the program
- Have strong access controls
- Conduct periodic cybersecurity training
- Encrypt sensitive data
- Have strong technical controls that meet security best practices
- Appropriately respond to any cybersecurity breaches
Plan fiduciaries also have responsibilities in this regard. The DOL requires plan fiduciaries to prudently select and monitor their providers, the intent of which is to safeguard plan assets. As a cybersecurity breach could affect participant accounts, plan fiduciaries should consider the following:
- Ask the provider about their cybersecurity practices, procedures, policies and audit results, and compare them to what others in the industry are doing
- Ask the provider how they evaluate their procedures and what level of security standards they meet
- Evaluate the provider’s cybersecurity track record based on public records
- Ask the provider about any prior breaches, what happened and what was done to resolve the issue
- Ask the provider about any insurance coverage they have that would cover any losses due to cybersecurity breaches
- Ensure any contract with a provider requires ongoing compliance with security standards
- Beware of any language in a service contract that limits the provider’s responsibility for any IT security breaches
The DOL believes plan participants and their beneficiaries also have a responsibility to help keep their accounts secure. The DOL suggests participants/beneficiaries:
- Register their account and monitor it regularly
- Use strong and unique passwords
- Use multi-factor authentication (MFA)
- Keep contact information current
- Close/delete any unused accounts
- Consider not using ‘free’ Wi-Fi
- Don’t share passwords, accounts or other sensitive information with an unknown person, even those posing as a known person; it could be a phishing attack trying to obtain this information to gain access to accounts
- Use anti-virus software and keep it and all apps current
- Know how to report identity theft and cybersecurity attacks
Need more help?
Retirement plans are a key benefit to your organization, but managing them can be complex and time-consuming. At CBIZ, we’re passionate about helping people achieve their retirement savings goals while also helping their employers navigate the fiduciary responsibilities that come with sponsoring a retirement plan. Depending on the area, our team of professionals can help guide you to make the decisions that best support your organization. Learn more at www.cbiz.com/retirement or connect with a CBIZ Retirement & Investment Solutions consultant today.
Investment advisory services provided through CBIZ Investment Advisory Services, LLC, a registered investment adviser and a wholly owned subsidiary of CBIZ, Inc.