
Recent DOL guidance establishes cybersecurity as a core fiduciary duty for retirement plan sponsors. This means implementing reasonable security measures, conducting regular assessments, and maintaining proper oversight of service providers.
We help plan sponsors meet their cybersecurity obligations through practical, implementable security measures that protect participant data and demonstrate reasonable fiduciary care.
DOL cybersecurity guidance, ERISA fiduciary standards, participant notification requirements
Common questions about ERISA cybersecurity requirements.
The Department of Labor recognizes that retirement plan data is valuable to cybercriminals and has established cybersecurity as a fiduciary responsibility. Plan sponsors must implement reasonable cybersecurity measures to protect participant information and plan assets.
The DOL guidance calls for annual cybersecurity audits, strong access controls, vendor cybersecurity oversight, incident response procedures, and staff cybersecurity training. The key word is "reasonable" , measures should be appropriate for the plan's size and complexity.
ERISA fiduciary liability can extend to personal assets in cases of breach of fiduciary duty. Implementing reasonable cybersecurity measures and following proper procedures helps protect against this liability exposure.