Cybersecurity can seem overwhelming for plan sponsors. Data breaches, phishing attacks, ransomware, account takeovers—the list of threats keeps growing. It’s easy to assume protecting a retirement plan requires expensive software, outside consultants, and a six-figure technology budget.
It doesn’t.
One of the simplest and least expensive cybersecurity decisions you can make is requiring multi-factor authentication (MFA).
Think about what’s sitting in your retirement plan. Social Security numbers, dates of birth, payroll information, beneficiary designations, and participant account balances. To a cybercriminal, that’s a treasure chest.
For years, a username and password were considered enough. They aren’t anymore. Passwords are stolen every day through phishing emails, data breaches, and reused credentials from other websites. Once someone has your password, they’re halfway through the front door.
MFA adds another lock.
Whether it’s a text message, an authentication app, or a biometric scan, that second step makes it dramatically harder for someone to gain unauthorized access. Is it foolproof? No. But it is one of the most effective ways to reduce the risk of account compromise.
The Department of Labor has repeatedly emphasized cybersecurity as part of a fiduciary’s responsibility. While ERISA doesn’t specifically require multi-factor authentication, ignoring readily available security measures becomes increasingly difficult to justify as industry standards evolve.
The good news is that most recordkeepers already offer MFA for plan sponsors and participants. The challenge isn’t availability—it’s making sure everyone actually uses it.
If you’re a plan sponsor, ask your recordkeeper whether MFA is available, whether it’s mandatory, and what percentage of participants have enabled it. If the answer is “I don’t know,” that’s a conversation worth having.
Sometimes fiduciary decisions involve complicated legal analysis or difficult business judgment.
This isn’t one of them.
Turning on multi-factor authentication may take only a few minutes, cost little or nothing, and significantly reduce the risk of a cybersecurity incident.
For a fiduciary, that’s about as easy a decision as you’ll ever make.