Skip to content

Who Has Access? Cybersecurity and Retirement Plans

Aug 4, 2026
Share

Fulfilling fiduciary obligations around cybersecurity requires plan sponsors to oversee a complex network of recordkeepers, payroll systems, and custodians. With so many partners involved, answering “who can access what data” is rarely straightforward. Toward improved oversight, ERISA experts suggest three key actions: define a vendor responsibility matrix, formalize post-incident protocols, and back up your strategy with liability insurance to mitigate financial risk.

Cybersecurity Is A Fiduciary Responsibility

At the American Society of Pension Professionals and Actuaries, Kelsey Mayo crystallizes the cybersecurity oversight obligations of plan sponsors this way:

Under ERISA, fiduciary prudence and loyalty don’t stop at selecting investments. The Department of Labor has made it clear that cybersecurity is part of prudent plan administration. Protecting plan assets includes safeguarding the systems and processes that hold them.In other words, this isn’t just an IT issue. It’s not just the recordkeeper’s responsibility. It’s a fiduciary governance issue….Fiduciaries should be asking some fundamental questions:

  • Where are the plan’s highest risks for attack?
  • What is being done about those risks? Are our people trained? Do we understand our vendors’ cybersecurity practices?
  • Do we have an incident response protocol if something goes wrong? Do we know what to do? Who to call?
  • And importantly, do we have the protections we think we have? What do the contracts say? What would insurance actually cover?

Given what accounting professionals at Eisner Amper refer to as the “vendor heavy environment” most plans rely on, sponsors need to be especially diligent with efforts to understand and document how each third party involved with the plan addresses cybersecurity. Start with the Department of Labors’ specific Tips for Hiring A Service Provider With Strong Security Practices, which include guidance for ongoing monitoring. 

At Forvis Mazars, audit and assurance professionals underscore the importance of applying all of the cybersecurity guidance from the Department of Labor “based on the benefit plan’s specific risk profile and operating environment….” Retirement plan sponsors who have not yet done so should review all of the protocols: Cybersecurity | U.S. Department of Labor

As Forvis Mazars further emphasizes, while retirement plans may rely heavily on third parties,fiduciary responsibility for oversight remains with the plan sponsor and named fiduciaries.” Specifically, toward effective cybersecurity oversight, Forvis Mazars encourages plan sponsors to implement a responsibility matrix to document: 

  • Which cybersecurity controls are owned and operated by the plan sponsor
  • Which controls are operated by service providers
  • How fiduciaries obtain assurance over third-party controls
  • Where oversight gaps or dependencies may exist

Good To Know: Response Ready?

Having an expert response plan for cyber breaches at the ready is a specific expectation of the Department of Labor for retirement plans–with good reason. Absent expert and timely response, even a relatively minor cybersecurity incident can spiral into bigger problems quickly. 

For example, Mayo, has observed that after cyber breaches, sponsors, vendors, advisors and trustees tend to look to each other for what went wrong, and what to do, rather than move into organized action, and advices: “Every plan sponsor and service provider should have a written escalation protocol that clearly identifies who is responsible for reporting a theft and ensures the process is understood—and tested—before it’s ever needed.” 

According to Mayo, it is particularly important to act quickly in the face of theft, because “if a theft is reported within roughly 36 hours, law enforcement (particularly the FBI’s Internet Crime Complaint Center at IC3) has a very high success rate in freezing and recovering the funds before they disappear.After that window, the odds drop dramatically.”

What If…?

As we all know, even with great diligence, we cannot completely rule out the possibility of cyber breaches impacting the data and funds in retirement plans. The consequences for plan sponsors can be steep, since an oversight like failure to implement a proper response plan can also result in allegations of a fiduciary breach. Without protection in the form of liability insurance, costs associated with defense and penalties are out of pocket expenses for sponsors and add up quickly.

Only fiduciary liability insurance (FLI) provides sponsors with personal coverage for  legal defense costs and penalties in the event of errors, oversights and allegations—and only Colonial Surety Company puts three essential coverages into one seamless, affordable bundle for retirement plan sponsors:

  1. ERISA Fidelity Bond: Fulfills your federal mandate to protect plan funds from dishonesty. (Colonial Surety is a direct, Treasury-Listed bond writer).
  2. Fiduciary Liability Insurance (FLI): Shields your personal assets, covering up to $1,000,000 in legal defense costs and penalties for administrative errors or oversight omissions.
  3. Complimentary Cyber Liability Insurance: Provides $50k of vital protection for the plan and company against regulatory actions following a data breach and directly addresses the DOL’s response plan recommendations.

Protect your retirement plan, your business, and your personal assets in one smart move: bundle your ERISA Bond with Fiduciary and Cyber Liability Insurance at Colonial Surety Company. 

👉 Get Your Instant Quote & Download Your Proof of Coverage in Minutes

Why Choose Colonial Surety Company?

  • Trusted & Reliable: U.S. Treasury Listed, Rated “A” (Excellent) by A.M. Best Company, and in business since 1930.
  • Direct & Digital: Skip the middleman. Quote, purchase, and download your full protection package entirely online in minutes.
  • The Carrier, Not a Broker: No agent markups, no waiting for a callback, and no unnecessary fees.
  • National Reach, Local Support: Licensed nationwide with a knowledgeable, US-based customer service team ready to assist you.

Frequently Asked Questions (FAQs)