Skip to content

Cybersecurity: Inquiry Letter?

Jul 27, 2026
Share

Pointing out that the Department of Labor’s cybersecurity inquiries to employee benefit plans are “active and intensifying,” accounting professionals remind sponsors that inquiry letters are not love letters. How prepared are you with documented evidence of the steps you’ve taken to protect your retirement plan? Read on for practical advice. 

Where’s Your Proof of Actions Taken?

“If you received a DOL cybersecurity inquiry today regarding your employee benefit plan, could you produce consistent answers and supporting evidence across internal teams and service providers—within 10 business days?” That’s the question posed by Diane Wasser and Evan Wilson at Eisner Amper, who also note: 

  • Regulatory expectations have shifted from guidance to proof. The DOL now asks for written programs, evidence of testing, and vendor oversight documentation. 
  • DOL cybersecurity investigations of employee benefit plans are active and intensifying. As much as 40% of an information request may be focused exclusively on cybersecurity.
  • Plan sponsors may have as few as 10 business days to respond to a DOL information request, making proactive preparation far less disruptive than a deadline-driven scramble.

 

Recently, in naming cybersecurity its number one enforcement priority, the DOL’s Employee Benefits Security Administration (EBSA) has underscored the importance of “protecting systems and data from cyber threats.” Meanwhile, acting on the government’s cybersecurity guidance has proven challenging for retirement plan sponsors. As professionals at Eisner Amper observe, the responsibilities of plan sponsors vis a vis cybersecurity is indeed complex, given the “vendor heavy environment” most retirement plans rely on: 

  • Recordkeepers, custodians, payroll and HRIS systems, third-party administrators, and other vendors often have overlapping access, making it difficult to explain “who can access what.” 
  • Without a formal data-flow inventory, that question has no clear answer. 
  • If an incident does occur, the consequences may extend beyond the incident response, resulting in response, participant communications, potential litigation, remediation costs, and regulator questions about preparedness and oversight. 
  • To overcome such obstacles, plan sponsors should document programs, test controls, and establish clear vendor evidence to act proactively.

Concluding that most plan sponsors will face a scurry to meet the customary 10 day response period upon receipt of a DOL inquiry letter, Eisner Amper’s professionals advise taking proactive steps to “establish a defensible cybersecurity baseline, assess service provider risk, and organize documentation.” Examples of the questions being asked on DOL inquiry letters include: 

  • Provide the plan sponsor’s written cybersecurity program, which includes procedures for identifying and assessing cybersecurity threats and risks, securing the Plan from attempted intrusions, responding to incursions, and the recovery plan.
  • Cybersecurity Liability Policy and related documents, if applicable.
  • Documents sufficient to describe the plan sponsor’s acceptable use policy regarding Plan participant data.
  • Documentation of any internally conducted assessment of cybersecurity controls (risks, threats, or vulnerabilities), including any reports created relating to the assessment.
  • Documentation of any third-party audit of cybersecurity controls, including any reports created and any recommendations made by the third party.
  • Documents sufficient to describe the cybersecurity policies and procedures of any service provider handling Plan data, including service agreements and other contracts.
  • Documentation of periodic employee cybersecurity awareness training.
  • Copies of any documents distributed to plan participants encouraging cybersecurity awareness.

An Ounce of Protection Is Worth…A Lot!

Retirement plan sponsors can be held personally liable for errors or alleged oversights  in how the plan is run, and that liability cannot be handed off to a third party, even when you use a pension professional or TPA. 

For a plan sponsor, an oversight like failure to implement a proper response plan in the aftermath of even a minor cybersecurity breach can result in allegations of a fiduciary breach, with the sponsor personally liable for the costs associated with defense and penalties. 

Only fiduciary liability insurance (FLI) is provides sponsors with personal coverage for  legal defense costs and penalties in the event of errors, oversights and allegations—and only Colonial Surety Company puts three essential coverages into one seamless, affordable bundle for retirement plan sponsors:

  1. ERISA Fidelity Bond: Fulfills your federal mandate to protect plan funds from dishonesty. (Colonial Surety is a direct, Treasury-Listed bond writer).
  2. Fiduciary Liability Insurance (FLI): Shields your personal assets, covering up to $1,000,000 in legal defense costs and penalties for administrative errors or oversight omissions.
  3. Complimentary Cyber Liability Insurance: Provides $50k of vital protection for the plan and company against regulatory actions following a data breach and directly addresses the DOL’s response plan recommendations.

Protect your retirement plan, your business, and your personal assets in one smart move: bundle your ERISA Bond with Fiduciary and Cyber Liability Insurance at Colonial Surety Company. 

👉 Get Your Instant Quote & Download Your Proof of Coverage in Minutes

Why Choose Colonial Surety Company?

  • Trusted & Reliable: U.S. Treasury Listed, Rated “A” (Excellent) by A.M. Best Company, and in business since 1930.
  • Direct & Digital: Skip the middleman. Quote, purchase, and download your full protection package entirely online in minutes.
  • The Carrier, Not a Broker: No agent markups, no waiting for a callback, and no unnecessary fees.
  • National Reach, Local Support: Licensed nationwide with a knowledgeable, US-based customer service team ready to assist you

Frequently Asked Questions (FAQs)