Are Your Plan(s) Cybersecure?

Last week the DOL’s Employee Benefit Security Administration unveiled a set of “best practices” on cybersecurity practices – and, perhaps more intriguingly - on cybersecurity considerations in hiring providers. 

The publication comes within a month of a report from the Government Accountability Office (GAO) calling for some definitive DOL guidance on the issue – specifically noting that “The Department of Labor hasn't clarified whether plan administrators are responsible for mitigating cybersecurity risks and hasn’t set minimum expectations for protecting personal information.”

It wasn’t exactly guidance – but it IS an issue of increasing importance to plan sponsors – and the DOL. 

So, this week we’d like to know which, if any, of the best practices you’ve advocated with your plan sponsor clients – and which of the standards in hiring considerations you have already embraced, or are thinking about.

Question Title

* 1. Will/have cybersecurity be an issue for your plan committee meetings this quarter?

Question Title

* 2. Generally speaking, which of the following cybersecurity measures do the plans you work with have in place (check all that apply)?

Question Title

* 3. What will be the focus of those discussions (check all that apply?

Question Title

* 4. Generally speaking, among the providers you recommend, what is the status of the following cybersecurity best practices for recordkeepers identified by EBSA?

  Have in place Not yet, but planning to have in place. Don't have in place. Don't know.
Have a formal, well documented cybersecurity program.
Conduct prudent annual risk assessments.
Have a reliable annual third party audit of security controls.
Clearly define and assign information security roles and responsibilities.
Have strong access control procedures.
Ensure that any assets or data stored in a cloud or managed by a third party service provider are subject to appropriate security reviews and independent security assessments.
Conduct periodic cybersecurity awareness training.
Implement and manage a secure system development life cycle (SDLC) program.
Have an effective business resiliency program addressing business continuity, disaster recovery, and incident response.
Encrypt sensitive data, stored and in transit.
Implement strong technical controls in accordance with best security practices.
Appropriately respond to any past cybersecurity incidents.

Question Title

* 5. Other comments about cybersecurity, cybersecurity concerns, lack of cybersecurity concerns, criteria for evaluating cybersecurity concerns, concerns about cybersecurity concerns, or life in general?

Question Title

* 6. What is your role working with retirement plans?

Question Title

* 7. What size plans do you work with PRIMARILY?

Question Title

* 8. Suggestions for future survey questions?  Seriously - what would you like to know about/from your fellow NAPA-Net readers?  Or what would you like to be asked?

Question Title

* 9. All responses are confidential, of course - but just in case you would like a response - or want me to know you responded - or just want to say hi - here's your chance to do so (don't forget your email)!

T