PLANSPONSOR - April/May 2018 - 86

ERISA EXAMINATION
Cyber Risks
G
Electronic recordkeeping raises concerns
one are the days when plan records were all maintained
on paper. Now, most are kept electronically by
the employer, recordkeeper, trustee and/or third-party
administrator (TPA). Online access to plan records can help facilitate
retrieving and retaining participant information, as well as
in generating reports.
In the world of smart phones and increased technology,
participants expect to have instant electronic access. But electronic
recordkeeping also raises cybersecurity concerns. Cyber
breaches and hacking incidents appear in the news on a regular
basis. Plans are not immune to this risk. Cyber breaches with
respect to plans can result in improper access to personal information
and to plan assets.
So what does this mean for the plan committee? The
Employee Retirement Income Security Act (ERISA) regulation
governing electronic disclosure of plan communications
requires that plan fiduciaries take " appropriate and necessary "
steps designed to make sure the electronic system for
providing plan information protects the confidentiality of
personal information and includes measures designed to
prevent unauthorized access to it. Thus, the committee has
an obligation to protect participant information provided
through an electronic system.
But let's be realistic. There is no foolproof way to guarantee
a plan's information will not be the subject of a cyberattack.
As with other fiduciary obligations, the key becomes acting
prudently and taking reasonable steps based on all of the facts
and circumstances.
Plan fiduciaries can, and should, take steps designed to
protect participant data. This means reviewing and considering
the employer's records system protections as well as gathering
information and representations regarding cybersecurity
protections implemented by the plan's service providers. The
committee should ask service provider candidates about their
cybersecurity policies and protections during the request for
proposals (RFP) process.
Additionally, on a periodic basis-perhaps annually-the
committee should ask its current service providers for updates on
their: cybersecurity policies; compliance with policies; whether
any security breaches have occurred; and procedures for mitigating
a breach should one happen.
In 2016, the ERISA Advisory Council issued the report
86 PLANSPONSOR.com April-May 2018 Art by Joseph Ciardiello
" Cybersecurity Considerations for Benefit Plans " to the secretary
of Labor. The council recognized the significant cyber risks associated
with plans, given the amount of data maintained electronically-names,
birthdates, Social Security numbers, addresses,
account balances, etc.-and recommended steps to take in the
ongoing process of managing cybersecurity risks. The council
noted that any cyber-protection strategy should be specific to a
particular plan, but, generally, some steps to take include the
following:
* Implementation and monitoring. Someone should be
responsible for implementing and monitoring the plan's cybersecurity
strategy.
* Testing and updating systems. Establish the frequency and
type of testing.
* Reporting. Reporting is critical to ongoing monitoring.
* Training. Individuals with access to plan data should
understand and be aware of cyber risks.
* Controlling access. It's important to know who has access
to plan data and limit that to only those who need it to perform
plan functions.
* Data retention and destruction. Consider destroying information
when it's no longer needed-but not too soon; there are
ERISA and Internal Revenue Code (IRC) rules regarding document
retention (let's save that for a future article).
* Third-party risk management. The committee should
understand the plan's service provider systems and security
protections.
Developing a cybersecurity strategy that takes these points
into consideration can go a long way toward protecting participant
data. The committee may also consider purchasing insurance,
as more and more insurance carriers now offer cybersecurity
insurance. In any event, plan committees should not ignore
cybersecurity risks to plan data and assets.
Taking steps to consider and implement a cyber-riskmanagement
strategy internally and with respect to the plan's
service providers may not mean the plan will never be hacked,
but it is evidence that the committee is acting reasonably and
prudently concerning the plan's electronic data.
Summer Conley is a partner in the Los Angeles office of
Drinker Biddle & Reath LLP. Michael Rosenbaum is a partner
in the firm's Chicago office.
http://www.PLANSPONSOR.com

PLANSPONSOR - April/May 2018

Table of Contents for the Digital Edition of PLANSPONSOR - April/May 2018

2018 Plan Sponsors of the Year
Plan Administration Guide, Part 1
From Strength to Strength
Finding the Best Course
Managed Accounts
Rising Costs
Taking Responsibility
PLANSPONSOR - April/May 2018 - C1
PLANSPONSOR - April/May 2018 - FC1
PLANSPONSOR - April/May 2018 - FC2
PLANSPONSOR - April/May 2018 - C2
PLANSPONSOR - April/May 2018 - 1
PLANSPONSOR - April/May 2018 - 2
PLANSPONSOR - April/May 2018 - 3
PLANSPONSOR - April/May 2018 - 4
PLANSPONSOR - April/May 2018 - 5
PLANSPONSOR - April/May 2018 - 6
PLANSPONSOR - April/May 2018 - 7
PLANSPONSOR - April/May 2018 - 8
PLANSPONSOR - April/May 2018 - 9
PLANSPONSOR - April/May 2018 - 10
PLANSPONSOR - April/May 2018 - 11
PLANSPONSOR - April/May 2018 - 12
PLANSPONSOR - April/May 2018 - 13
PLANSPONSOR - April/May 2018 - 14
PLANSPONSOR - April/May 2018 - 15
PLANSPONSOR - April/May 2018 - 2018 Plan Sponsors of the Year
PLANSPONSOR - April/May 2018 - 17
PLANSPONSOR - April/May 2018 - 18
PLANSPONSOR - April/May 2018 - 19
PLANSPONSOR - April/May 2018 - 20
PLANSPONSOR - April/May 2018 - 21
PLANSPONSOR - April/May 2018 - 22
PLANSPONSOR - April/May 2018 - 23
PLANSPONSOR - April/May 2018 - 24
PLANSPONSOR - April/May 2018 - 25
PLANSPONSOR - April/May 2018 - 26
PLANSPONSOR - April/May 2018 - 27
PLANSPONSOR - April/May 2018 - 28
PLANSPONSOR - April/May 2018 - 29
PLANSPONSOR - April/May 2018 - 30
PLANSPONSOR - April/May 2018 - 31
PLANSPONSOR - April/May 2018 - 32
PLANSPONSOR - April/May 2018 - 33
PLANSPONSOR - April/May 2018 - 34
PLANSPONSOR - April/May 2018 - 35
PLANSPONSOR - April/May 2018 - 36
PLANSPONSOR - April/May 2018 - 37
PLANSPONSOR - April/May 2018 - 38
PLANSPONSOR - April/May 2018 - 39
PLANSPONSOR - April/May 2018 - 40
PLANSPONSOR - April/May 2018 - 41
PLANSPONSOR - April/May 2018 - 42
PLANSPONSOR - April/May 2018 - 43
PLANSPONSOR - April/May 2018 - 44
PLANSPONSOR - April/May 2018 - 45
PLANSPONSOR - April/May 2018 - 46
PLANSPONSOR - April/May 2018 - 47
PLANSPONSOR - April/May 2018 - 48
PLANSPONSOR - April/May 2018 - 49
PLANSPONSOR - April/May 2018 - 50
PLANSPONSOR - April/May 2018 - 51
PLANSPONSOR - April/May 2018 - 52
PLANSPONSOR - April/May 2018 - 53
PLANSPONSOR - April/May 2018 - 54
PLANSPONSOR - April/May 2018 - 55
PLANSPONSOR - April/May 2018 - Plan Administration Guide, Part 1
PLANSPONSOR - April/May 2018 - 57
PLANSPONSOR - April/May 2018 - 58
PLANSPONSOR - April/May 2018 - 59
PLANSPONSOR - April/May 2018 - 60
PLANSPONSOR - April/May 2018 - 61
PLANSPONSOR - April/May 2018 - 62
PLANSPONSOR - April/May 2018 - 63
PLANSPONSOR - April/May 2018 - 64
PLANSPONSOR - April/May 2018 - 65
PLANSPONSOR - April/May 2018 - 66
PLANSPONSOR - April/May 2018 - 67
PLANSPONSOR - April/May 2018 - From Strength to Strength
PLANSPONSOR - April/May 2018 - 69
PLANSPONSOR - April/May 2018 - 70
PLANSPONSOR - April/May 2018 - 71
PLANSPONSOR - April/May 2018 - 72
PLANSPONSOR - April/May 2018 - 73
PLANSPONSOR - April/May 2018 - 74
PLANSPONSOR - April/May 2018 - 75
PLANSPONSOR - April/May 2018 - 76
PLANSPONSOR - April/May 2018 - 77
PLANSPONSOR - April/May 2018 - Finding the Best Course
PLANSPONSOR - April/May 2018 - 79
PLANSPONSOR - April/May 2018 - Managed Accounts
PLANSPONSOR - April/May 2018 - 81
PLANSPONSOR - April/May 2018 - Rising Costs
PLANSPONSOR - April/May 2018 - 83
PLANSPONSOR - April/May 2018 - Taking Responsibility
PLANSPONSOR - April/May 2018 - 85
PLANSPONSOR - April/May 2018 - 86
PLANSPONSOR - April/May 2018 - 87
PLANSPONSOR - April/May 2018 - 88
PLANSPONSOR - April/May 2018 - C3
PLANSPONSOR - April/May 2018 - C4
https://www.plansponsordigital.com/plansponsor/september_october_2024
https://www.plansponsordigital.com/plansponsor/july_august_2024
https://www.plansponsordigital.com/plansponsor/may_june_2024
https://www.plansponsordigital.com/plansponsor/march_april_2024
https://www.plansponsordigital.com/plansponsor/january_february_2024
https://www.plansponsordigital.com/plansponsor/november_december_2023
https://www.plansponsordigital.com/plansponsor/september_october_2023
https://www.plansponsordigital.com/plansponsor/july_august_2023
https://www.plansponsordigital.com/plansponsor/excellenceawards_2023
https://www.plansponsordigital.com/plansponsor/may_june_2023
https://www.plansponsordigital.com/plansponsor/march_april_2023
https://www.plansponsordigital.com/plansponsor/december_2022_february_2023
https://www.plansponsordigital.com/plansponsor/october_november_2022
https://www.plansponsordigital.com/plansponsor/august_september_2022
https://www.plansponsordigital.com/plansponsor/june_july_2022
https://www.plansponsordigital.com/plansponsor/excellenceawards_2022
https://www.plansponsordigital.com/plansponsor/april_may_2022
https://www.plansponsordigital.com/plansponsor/february_march_2022
https://www.plansponsordigital.com/plansponsor/december_2021_january_2022
https://www.plansponsordigital.com/plansponsor/october_november_2021
https://www.plansponsordigital.com/plansponsor/august_september_2021
https://www.plansponsordigital.com/plansponsor/june_july_2021
https://www.plansponsordigital.com/plansponsor/april-may_2021
https://www.plansponsordigital.com/plansponsor/february-march_2021
https://www.plansponsordigital.com/plansponsor/december-january_2021
https://www.plansponsordigital.com/plansponsor/october-november_2020
https://www.plansponsordigital.com/plansponsor/august-september_2020
https://www.plansponsordigital.com/plansponsor/june-july_2020
https://www.plansponsordigital.com/plansponsor/april-may_2020
https://www.plansponsordigital.com/plansponsor/february-march_2020
https://www.plansponsordigital.com/plansponsor/december-january_2020
https://www.plansponsordigital.com/plansponsor/october-november_2019
https://www.plansponsordigital.com/plansponsor/august-september_2019
https://www.plansponsordigital.com/plansponsor/june-july_2019
https://www.plansponsordigital.com/plansponsor/april-may_2019
https://www.plansponsordigital.com/plansponsor/february-march_2019
https://www.plansponsordigital.com/plansponsor/december_2018-january_2019
https://www.plansponsordigital.com/plansponsor/october-november_2018
https://www.plansponsordigital.com/plansponsor/august-september_2018
https://www.plansponsordigital.com/plansponsor/june-july_2018
https://www.plansponsordigital.com/plansponsor/april-may_2018
https://www.plansponsordigital.com/plansponsor/february-march_2018
https://www.plansponsordigital.com/plansponsor/december_2017-january_2018
https://www.plansponsordigital.com/plansponsor/november_december_2017
https://www.plansponsordigital.com/plansponsor/october_2017
https://www.plansponsordigital.com/plansponsor/september_2017
https://www.nxtbookmedia.com