There was a time when cybersecurity was viewed as the responsibility of the IT department. If the network was protected and the antivirus software was up to date, management considered the job done. Those days are over—especially when it comes to retirement plans.
Today’s retirement plans hold sensitive participant information, account balances, Social Security numbers, banking details, and beneficiary data. A cybersecurity breach doesn’t just create technical problems; it creates fiduciary, financial, and reputational risks.
The Department of Labor has made it clear that cybersecurity is part of prudent plan administration. While the guidance isn’t a formal regulation, it sends a strong message that plan sponsors are expected to understand how participant data is protected and to ask meaningful questions of their service providers.
That doesn’t mean fiduciaries need to become cybersecurity experts. It does mean they should know who has access to participant information, how that information is protected, whether service providers maintain cybersecurity insurance, how incidents are reported, and what procedures are in place if a breach occurs.
Cybersecurity should also become a regular agenda item during retirement committee meetings. Ask your recordkeeper about multi-factor authentication, encryption, employee training, independent security audits, and disaster recovery planning. Document those discussions. Good fiduciary governance isn’t about having every answer—it’s about asking the right questions and maintaining a prudent process.
Unfortunately, many organizations still assume that because they hired reputable providers, cybersecurity is someone else’s responsibility. It isn’t. While service providers perform many important functions, the responsibility for selecting and monitoring them remains with the plan sponsor.
The greatest cybersecurity risk isn’t necessarily sophisticated hackers. It’s complacency. Assuming everything is fine because nothing has happened yet is rarely a winning strategy.
Protecting retirement plan assets today means protecting participant data as well. Cybersecurity is no longer simply an IT concern. It has become an essential part of fiduciary responsibility, and every plan sponsor should treat it that way.