Skip to content

Cybersecurity: Are You Managing The New Risks?

Sep 18, 2026
Share

For retirement plan sponsors, cybersecurity continues to climb the list of concerns. The trillions of savings invested in retirement accounts is obviously a target for cybercriminals, and the growing use of AI in plan administration creates new vulnerabilities. Examine the risks and focus on practical steps, with these insights from attorneys. 

Now’s The Time: Tune In

If cybersecurity has somehow eluded your attention as a retirement plan sponsor (as it has for many of us), now more than ever, it is time to ratchet up your attention: your role as a fiduciary actually requires you to do so, as attorneys Kelsey A. O’Gorman and Iris Grossman of Foley & Lardner remind us: 

  • In April 2021, the DOL’s Employee Benefits Security Administration (EBSA) issued its first-ever guidance on cybersecurity…In September 2024, EBSA updated the guidance to clarify that all employee benefit plans (both retirement and health and welfare plans) are covered by its cybersecurity requirements. The guidance makes clear that the DOL views cybersecurity as an ERISA fiduciary responsibility. Plan fiduciaries must ensure proper mitigation of cybersecurity risks as part of their duty of prudence, including prudently selecting and monitoring service providers who handle participant data and plan assets….
  • Fiduciaries cannot simply rely on service providers to manage these risks — their active and ongoing oversight is required. 
  • Cybersecurity remains a top DOL priority. Earlier this year, EBSA released its 2026 enforcement priorities, with cybersecurity topping the list. EBSA has also incorporated cybersecurity questions into its standard plan audit protocols, with investigators now requesting documentation regarding cybersecurity policies, service provider agreements, and incident response procedures.

In addition to compliance with federal expectations on cybersecurity, retirement plan sponsors now need to be concerned with the AI tools that “are increasingly used in benefits administration, from chatbots answering participant questions to algorithms processing claims and generating investment recommendations.” As O’Gorman and Grossman point out: “While these tools can improve efficiency, they also introduce new cybersecurity risks that fiduciaries must evaluate.” Three specific examples of the cybersecurity challenges AI brings to retirement plans are: 

  • AI systems often require access to vast amounts of sensitive data to function effectively. This concentration of data creates attractive targets for cyberattacks. A breach of an AI system may expose not only current participant information, but also historical data used to train the models.
  • AI tools may be vulnerable to “adversarial attacks” — cyberattacks specifically designed to manipulate AI outputs. Bad actors could potentially manipulate AI systems to approve fraudulent transactions, provide incorrect benefit information, or bypass security controls. The complexity of some AI systems can make such attacks difficult to detect.
  • The integration of AI with other plan systems could create additional security vulnerabilities. AI tools often connect to multiple databases, communication platforms, and third-party services. Each integration point represents a potential vulnerability. 

In the face of these new threats AI opens up related to keeping retirement plans secure, and in line with the guidance from the Department of Labor (DOL), attorneys at Foley & Lardner are counseling plan fiduciaries to step up vendor due diligence and contractual protections:

  • Vendor Due Diligence. When selecting service providers, evaluate their cybersecurity practices as part of the prudent selection process. Request and review their written cybersecurity policies, inquire about security certifications and cybersecurity insurance, and ask about incident history … .Specifically ask whether AI is being used and for what purposes, what data these AI tools can access, and how that data is stored and protected. And, because fiduciary responsibility does not end after vendor selection, implement ongoing monitoring procedures, including requiring periodic cybersecurity reports….
  • Contractual Protections. Service agreements should include robust cybersecurity provisions. Key terms to review include: whether there is a clear allocation of responsibility for data security and breach liability; requirements for the service provider to maintain specified security controls; notification obligations for security incidents; annual cybersecurity reports or certifications; audit rights permitting the plan to verify security compliance; restrictions on subcontracting with requirements for subcontractor oversight; and provisions addressing AI-specific risks….

Personal Protection for Plan Sponsors Is Essential Too…

Retirement plan sponsors can be held personally liable for errors or alleged oversights  in how the plan is run, and that liability cannot be handed off to a third party, even when you use a pension professional or TPA. For example, for a plan sponsor, an oversight like failure to implement a proper response plan in the aftermath of even a minor cybersecurity breach can result in allegations of a fiduciary breach, with the sponsor personally liable for the costs associated with defense and penalties. 

Only fiduciary liability insurance (FLI) provides sponsors with personal coverage for  legal defense costs and penalties in the event of errors, oversights and allegations—and only Colonial Surety Company puts three essential coverages into one seamless, affordable bundle for retirement plan sponsors:

  1. ERISA Fidelity Bond: Fulfills your federal mandate to protect plan funds from dishonesty. (Colonial Surety is a direct, Treasury-Listed bond writer).
  2. Fiduciary Liability Insurance (FLI): Shields your personal assets, covering up to $1,000,000 in legal defense costs and penalties for administrative errors or oversight omissions.
  3. Complimentary Cyber Liability Insurance: Provides $50k of vital protection for the plan and company against regulatory actions following a data breach and directly addresses the DOL’s response plan recommendations.

Protect your retirement plan, your business, and your personal assets in one smart move: bundle your ERISA Bond with Fiduciary and Cyber Liability Insurance at Colonial Surety Company, in minutes, now:

👉 Fiduciary and Cyber Liability Insurance For Retirement Plan Sponsors

Why Choose Colonial Surety Company?

 

  • Trusted & Reliable: U.S. Treasury Listed, Rated “A” (Excellent) by A.M. Best Company, and in business since 1930.
  • Direct & Digital: Skip the middleman. Quote, purchase, and download your full protection package entirely online in minutes.
  • The Carrier, Not a Broker: No agent markups, no waiting for a callback, and no unnecessary fees.
  • National Reach, Local Support: Licensed nationwide with a knowledgeable, US-based customer service team ready to assist you.

Frequently Asked Questions (FAQs)