Media

Cybersecurity & ERISA Compliance: Protecting Your Plan

02/06/2026

Cybersecurity has become a necessary consideration in many aspects of life, and your retirement plan is no exception. For plan sponsors, understanding your responsibilities—as well as those of the third party administrators (TPAs) and recordkeepers that you work with—is a fundamental part of ERISA (Employee Retirement Income Security Act) compliance and the fulfillment of your fiduciary responsibilities. Retirement plans hold significant financial assets and large volumes of highly sensitive participant data, making them an attractive target for cybercriminals. As a result, the protection of this data and access to it has become inseparable from the obligation to act prudently and in the best interests of participants.

Why Cybersecurity Matters

Under ERISA, fiduciaries are required to act with care, prudence and diligence when administering a plan and safeguarding its assets. In today’s environment, plan assets include not only the money held in trust, but also the systems, data and processes that control access to those assets. Cyber incidents such as account takeovers, fraudulent distributions and data breaches can directly harm participants and may be viewed as a failure of fiduciary prudence. The DOL (Department of Labor) has reinforced that managing cybersecurity risk is now an expected part of plan governance—not an optional enhancement. A failure to consider known and growing cyber risk can expose plan sponsors to regulatory scrutiny, participant claims and reputational damage.

Your Role in Cybersecurity

For plan sponsors, cybersecurity is closely tied to the duty to prudently select and monitor service providers. Sponsors are expected to understand how TPAs and recordkeepers protect participant data, prevent fraud and respond to incidents; evaluating these practices has become just as important as reviewing fees, services and operational capabilities. Let’s look at what role each has in protecting your plan:

  • TPAs play a critical role in the administration of your plan and routinely handle sensitive participant information and transactional data. As such, we are expected to maintain strong internal controls, secure workflows and documented policies designed to protect plan operations from cyber threats.
  • Recordkeepers are often the primary point of interaction for participants and therefore sit in the front line of cybersecurity risk. For them, secure participant access, identity verification, transaction monitoring and distribution controls are essential to protecting retirement savings.

Bottom Line

The Department of Labor’s cybersecurity guidance underscores the expectation that plans and their service providers will maintain formal security programs, protect data through appropriate controls, prepare for incidents and clearly communicate with participants. To see the DOL’s Cybersecurity Program Best Practices, please visit the URL provided at the end of this article. Following these principles help demonstrate procedural prudence and supports compliance with ERISA’s fiduciary standards.

Ultimately, effective cybersecurity protects participants, strengthens trust in the plan, and reduces fiduciary and operational risk. In the current regulatory and litigation environment, sound cybersecurity practices are a clear reflection of prudent plan management. As your TPA, we take digital security seriously, and we are fully committed to protecting your plan and participants and giving you one less thing worry about.

Source: Department of Labor | Cybersecurity Program Best Practices: https://www.dol.gov/agencies/ebsa/key-topics/retirement-benefits/cybersecurity/best-practices

This newsletter is intended to provide general information on matters of interest in the area of qualified retirement plans and is distributed with the understanding that the publisher and distributor are not rendering legal, tax or other professional advice. Readers should not act or rely on any information in this newsletter without first seeking the advice of an independent tax advisor such as an attorney or CPA.

Categories

Articles

News

Advisor Connect

Benefits of Sponsoring a Retirement Plan

Benefits of Sponsoring a Retirement Plan

The benefits of being a retirement plan participant are well-documented, but the perks available to the sponsoring employer are often overlooked. In offering a retirement plan, plan sponsors can enjoy the advantages of tax deductions and credits, flexible design...

read more
Features of a 401(k) Plan

Features of a 401(k) Plan

401(k) plans are a popular way to save for retirement. Although many people participate in these plans, the flexibility allowed by plan provisions ensures each can be unique. Understanding the features and options available for a 401(k) plan will help you design your...

read more
Upcoming Compliance Deadlines for Calendar-Year Plans

Upcoming Compliance Deadlines for Calendar-Year Plans

September 15 Deadline for required contribution to defined benefit plans, money purchase pension plans and target benefit pension plans. Deadline for deducting 2025 employer contributions for sponsors who filed an extension on Partnership or S-Corporation tax returns,...

read more
Spring Cleaning

Spring Cleaning

Spring will arrive soon, promising new growth and a fresh beginning. It could also be the perfect time to do some spring cleaning for your plan. Let’s look at some areas that you might consider reviewing to ensure your retirement plan is operating efficiently....

read more
The Plan Document: Why Understanding it Matters

The Plan Document: Why Understanding it Matters

An employer-sponsored retirement plan is an extremely valuable benefit a company can offer its employees. At the heart of this benefit is the plan document—the official rulebook that explains exactly how the plan works. For plan sponsors, understanding this document...

read more