The U.S. Department of Labor (DOL) recently issued cybersecurity guidance for 401k plan sponsors, recordkeepers, other vendors, participants, and beneficiaries. This is the first official DOL guidance on 401k cybersecurity best practices.
The DOL issued its cybersecurity guidance through the three following resources:
- Cybersecurity Program Best Practices1 (for employers, other plan fiduciaries, and 401k plan service providers)
- Online Security Tips2 (for participants and beneficiaries)
- Tips for Hiring a Service Provider with Strong Cybersecurity Practices3 (for employers and other plan fiduciaries)
The DOL’s guidance demonstrates that the DOL takes the position that plan fiduciaries have a legal duty to mitigate cybersecurity risk. However, the DOL also recognizes that non-fiduciaries (such as participants, beneficiaries, and other third-party vendors) play an integral role in 401k plan cybersecurity.
12 DOL Best Practices to Mitigate Cybersecurity Risks
The DOL provided the following 12 best practices4 to help plan fiduciaries and/or vendors mitigate cybersecurity risks.
- Have a formal well-documented cybersecurity program.
- Conduct prudent annual risk assessments.
- Have a reliable annual third-party audit of security controls.
- Clearly define and assign information security roles and responsibilities.
- Have strong access control procedures.
- Ensure that any assets or data stored in a cloud or managed by a third-party service provider are subject to appropriate security review and independent security assessments.
- Conduct periodic cybersecurity awareness training.
- Implement and manage a secure system development life cycle (SDLC) program.
- Have an effective business resiliency program addressing business continuity, disaster recovery, and incident response.
- Encrypt sensitive data, stored and in-transit.
- Implement strong technical controls in accordance with best security practices.
- Appropriately respond to any past cybersecurity incidents.
Employer Actions
Although not required by statute or regulation, employers and plan third-party vendors are encouraged to consider adopting these best practices to help withstand any DOL scrutiny related to cybersecurity.
Additional Resources
- Employee Benefits Security Administration, United State Department of Labor, Cybersecurity Program Best Practices5
- U.S. Department of Labor Announces New Cybersecurity Guidance for Plan Sponsors, Plan Fiduciaries, Record-Keepers, Plan Participants6
- Employee Benefits Security Administration, United State Department of Labor, Cybersecurity Program Best Practices at https://www.dol.gov/sites/dolgov/files/ebsa/key-topics/retirement-benefits/cybersecurity/best-practices.pdf
- Employee Benefits Security Administration, United State Department of Labor, Online Security Tips at https://www.dol.gov/sites/dolgov/files/ebsa/key-topics/retirement-benefits/cybersecurity/online-security-tips.pdf
- Employee Benefits Security Administration, United State Department of Labor, Tips for Hiring a Service Provider with Strong Cybersecurity Practices at https://www.dol.gov/sites/dolgov/files/ebsa/key-topics/retirement-benefits/cybersecurity/best-practices.pdf
- Employee Benefits Security Administration, United State Department of Labor, Cybersecurity Program Best Practices at https://www.dol.gov/sites/dolgov/files/ebsa/key-topics/retirement-benefits/cybersecurity/best-practices.pdf
- Id.
- U.S. Department of Labor, News Release. U.S. Department of Labor Announces New Cybersecurity Guidance for Plan Sponsors, Plan Fiduciaries, Record-Keepers, Plan Participants. (April 14, 2021). https://www.dol.gov/newsroom/releases/ebsa/ebsa20210414
Pensionmark Financial Group, LLC (“Pensionmark”) is an investment adviser registered under the Investment Advisers Act of 1940. Financial Advisors at Pensionmark may also be registered representatives of Pensionmark Securities, LLC (member SIPC), which is affiliated with Pensionmark through common ownership.