Cybersecurity Breach: Ask “Why?”
Not paying attention to why a cyber breach occurred paves the path for the next cyber breach. That’s why it’s essential for retirement plan sponsors to follow up with service providers after even a minor incident. Examining the cause is the first step in preventing a subsequent breach. In fact, putting clear post-incident response protocols in place with all third parties contracted for the plan is work sponsors need to take very seriously, given their fiduciary obligations for selecting and monitoring service providers.
Cybersecurity Is A Fiduciary Responsibility
The assets and data associated with retirement plans are obvious targets for cyber crime, and as accounting professionals at Eisner Amper remind us, the “vendor heavy environment” most plans rely on, complicates protection strategies. Regardless of the inherent challenges, plan sponsors are obligated to mitigate the threats by diligently following federal protocols: Cybersecurity | U.S. Department of Labor.
Specifically, to properly select and oversee all of the recordkeepers, payroll systems and custodians involved with the retirement plan, sponsors must follow the DOL’s Tips for Hiring A Service Provider With Strong Security Practices, which include these instructions related to Notification of Cybersecurity Breaches: “The contract should identify how quickly you would be notified of any cyber incident or data breach. In addition, the contract should ensure the service provider’s cooperation to investigate and reasonably address the cause of the breach.”
When working with a service provider in the aftermath of a breach (no matter the size or extent of the damage), it is imperative for plan sponsors to ask why the breach happened. As Julie Tracy, CISSP Manager, Cyber and Information Security Services, at Withium emphasized at the American society of Pension Professionals & Actuaries (ASPPA): 73% of the organizations that experience a breach of security experience a second one “because they didn’t identify the cause and didn’t fix it.”
While it is critical to examine the cause of a breach, and take steps to “make a system resistant to the vulnerability that was exploited,” it is also essential to act
quickly in the face of cyber theft. Time is very much of the essence, as Kelsey Mayo, Chief of Retirement Policy & Regulatory Affairs at the American Retirement Association, underscores: “if a theft is reported within roughly 36 hours, law enforcement (particularly the FBI’s Internet Crime Complaint Center at IC3) has a very high success rate in freezing and recovering the funds before they disappear.After that window, the odds drop dramatically.”
Unfortunately, it is typical after cyber breaches, for vendors, advisors, trustees and sponsors to assume “the others” are on top of the situation and miss important action steps, which is why Mayo emphasizes: “Every plan sponsor and service provider should have a written escalation protocol that clearly identifies who is responsible for reporting a theft and ensures the process is understood—and tested—before it’s ever needed.”
A Must Have: Solid Response Plan
The time to develop a solid response plan for cybersecurity incidents is now–not after a vendor notifies you that a breach has occurred. In fact, an incident response plan is a specific expectation of the Department of Labor for plan sponsors. Additional pointers for plan sponsors from cybersecurity professionals at ASPPA include:
- Have a policy in place to manage third-party vendors — and remember that all the vendors that provide services must have cybersecurity programs in place.
- Assign roles for incident response and make sure those who fill those roles are well-trained.
- Remember that print shops that handle information for the plan also must follow a cybersecurity program, like other service providers.
- All plans should participate in cybersecurity training at least once a year.
- Notification also is a key responsibility. “Any time anyone touches information that they shouldn’t, that requires notification…”.
For plan sponsors, even a relatively minor cybersecurity incident can spiral into bigger problems quickly, as Forvis Mazars reminds us: “fiduciary responsibility for oversight remains with the plan sponsor and named fiduciaries.”
Indeed, the consequences for plan sponsors can be steep in the aftermath of a cyber breach, since an oversight like failure to implement a proper response plan can result in allegations of a fiduciary breach. Without protection in the form of liability insurance, costs associated with defense and penalties are personal, out of pocket expenses for sponsors and they add up quickly.
Only fiduciary liability insurance (FLI) provides sponsors with personal coverage for legal defense costs and penalties in the event of errors, oversights and allegations—and only Colonial Surety Company puts three essential coverages into one seamless, affordable bundle for retirement plan sponsors:
- ERISA Fidelity Bond: Fulfills your federal mandate to protect plan funds from dishonesty. (Colonial Surety is a direct, Treasury-Listed bond writer).
- Fiduciary Liability Insurance (FLI): Shields your personal assets, covering up to $1,000,000 in legal defense costs and penalties for administrative errors or oversight omissions.
- Complimentary Cyber Liability Insurance: Provides $50k of vital protection for the plan and company against regulatory actions following a data breach and directly addresses the DOL’s response plan recommendations.
Protect your retirement plan, your business, and your personal assets in one smart move: 👉 Get Your Instant Quote & Download Your Proof of Coverage in Minutes
Why Choose Colonial Surety Company?
- Trusted & Reliable: U.S. Treasury Listed, Rated “A” (Excellent) by A.M. Best Company, and in business since 1930.
- Direct & Digital: Skip the middleman. Quote, purchase, and download your full protection package entirely online in minutes.
- The Carrier, Not a Broker: No agent markups, no waiting for a callback, and no unnecessary fees.
- National Reach, Local Support: Licensed nationwide with a knowledgeable, US-based customer service team ready to assist you.
Helpful Resources
Frequently Asked Questions (FAQs)