Cyber Breach: Now What?
When a participant’s 401(k) account is compromised, the aftermath is rarely straightforward. It’s bad enough that breaches target retirement funds, but they also expose sensitive personally identifiable information (PII)—like Social Security numbers, dates of birth, and home addresses—opening the door to further cyber crime. From participants and plan advisors to recordkeepers and plan sponsors, every party plays a role in identifying, mitigating, and recovering from a cyber incident. What’s your plan?
Who’s Responsible for What?
When a breach occurs, confusion over roles can lead to catastrophic delays. Plan sponsors cannot simply assume their recordkeeper or third-party administrator (TPA) will leap into action or cover all losses. It is critical to work with vendors in advance to ensure specific incident-response protocols are codified in service agreements—establishing clear arrangements for who takes action, who notifies affected parties, and who carries financial responsibility for specific types of loss.
To assist fiduciaries in establishing this operational clarity, the U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) outlines specific Cybersecurity Program Best Practices that plan sponsors should focus on with all plan vendors. It’s imperative for plan sponsors to be clear on precise protocols for who does what in response to a cyber breach. Consider for example:
- Immediate Lockdown: Who freezes compromised accounts and blocks further unauthorized transactions?
- Law Enforcement & Insurer Notification: Who immediately reports the cyber incident to law enforcement and notifies the appropriate cyber liability insurance carriers?
- Participant Communication: Who informs affected participants in a timely manner, providing actionable guidance and necessary information to prevent or reduce further financial harm.
- Remediation & Root-Cause Analysis: Who conducts a formal investigation to identify how the breach occurred and fix the underlying vulnerabilities to prevent recurrence?
- Continuous Service Provider Oversight: What is the oversight for a third party administrator’s timely and thorough response to a breach?
When it comes to the cybersecurity of ERISA retirement plans, experts at Plan Sponsor underscore that “it takes a village.” Read up on their advice right here: Responding To A Cyber Breach.
Who’s Covered For What?
As a plan sponsor, it is unwise to assume that because vendors carry cyber insurance, the plan itself is fully protected, and participants will automatically be made whole when cyber crimes result in losses. Risk management experts at Eisner Amper note that given the “vendor heavy environment” most plans rely on, sponsors need to find out exactly how each vendor addresses cybersecurity. That includes knowing what insurance coverages vendors have in place, and the limits and exclusions on the kinds of losses covered. Remember too that carrying dedicated Cyber Liability Insurance ensures that the plan and the sponsor have immediate, first-party legal defense, forensics support, and loss mitigation—regardless of vendor disputes or policy limits. When reviewing coverage, keep these factors in mind:
- Vendor Policies Protect the Vendor: It’s likely that a recordkeeper’s insurance policy is primarily designed to defend their organization, not yours. If plan participants file a lawsuit naming you the plan sponsor or employer as defendants for imprudent vendor oversight, the recordkeeper’s policy may not cover your legal defense or settlement costs.
- Coverage Limits Can Be Exhausted: Third party service providers probably aggregate data for many, many plans. If a major breach affects multiple clients at once, the vendor’s policy limits may be drained before all claims are satisfied.
- Disputed Fault & Slow Payouts: Insurers can dispute liability, arguing the breach originated from stolen participant credentials or a breach at the employer level (e.g., compromised HR emails). While third-party insurers litigate who is at fault, you and your business may be left funding defense costs out-of-pocket.
- Direct Plan Exposure: Most plan sponsors hold sensitive employee data on internal servers, HR systems, and payroll software. If a cyberattack originates inside your own network, a recordkeeper’s insurance may not be helpful.
Closing The Gaps
Because plan sponsors from small businesses tend to face the biggest hurdles implementing cybersecurity protocols, Colonial Surety Company offers an efficient, affordable and clear solution. For a few dollars a day, plan sponsors can obtain protection for the company, the plan, and themselves, with a Cyber Liability+Fiduciary Liability Insurance package. In addition to providing defense costs and penalty limits up to $1,000,000 for the sponsor, this package addresses numerous DOL recommendations by explicitly covering the plan and the business with:
- Expert-led response services following a data breach.
- Protection from lawsuits and regulatory actions related to the breach
- Legal services.
- Computer forensic services.
- Public relations and crisis management expenses.
- Notification services.
- Call Center services.
- Credit and Identity monitoring
Protect your retirement plan, your business, and your personal assets in one smart move: bundle your ERISA Bond with Fiduciary and Cyber Liability Insurance at Colonial Surety Company.
👉 Get Your Instant Quote & Download Your Proof of Coverage in Minutes
Why Choose Colonial Surety Company?
- Trusted & Reliable: U.S. Treasury Listed, Rated “A” (Excellent) by A.M. Best Company, and in business since 1930.
- Direct & Digital: Skip the middleman. Quote, purchase, and download your full protection package entirely online in minutes.
- The Carrier, Not a Broker: No agent markups, no waiting for a callback, and no unnecessary fees.
- National Reach, Local Support: Licensed nationwide with a knowledgeable, US-based customer service team ready to assist you.
Helpful Resources
Frequently Asked Questions (FAQs)