PLANSPONSOR - June - July 2022 - 35

BEST PRACTICES | CYBERSECURITY
DOL put out a series of tip sheets to help
companies of all sizes learn the types of
cybersecurity questions to ask. The tip
sheets' guidance breaks down as: how-to's
for hiring a service provider that employs
strong security practices; best practices
for cybersecurity programs; and online
security tips for participants.
" I think, at a minimum, bring up
the tip sheets and discuss them at the
committee meeting, and start thinking
about these things, " Conley says.
Committees may use the tip sheets
as a guide when asking service providers
about their cybersecurity programs and
later when monitoring their work.
Lee especially likes the DOL's questions
to ask when interviewing a recordkeeper,
he says. For instance: What has the
provider's record been? Has it experienced
any breaches? What is its plan in case of a
breach? How would a breach be reported?
And what technical certifications do staff
members have in cybersecurity?
He recommends that plan committees
additionally review the cybersecurity
program best practices
tip sheet,
even though it is targeted toward recordkeepers
and other vendors. " It's a great
reference for committees to see what the
DOL considers best practices and the
types of questions it is likely to ask in the
event of an audit. "
Annual Updates
While asking about such practices should
be built into the RFP and the evaluation
process, " Where many fiduciaries come
up short is the fact that the relationship
with the major recordkeepers has
become routine, " Lee observes. " Have
these cybersecurity conversations with
them not just at renewal time, but also
on a periodic basis. " He recommends
having the recordkeeper and other
service providers make a presentation
about their cybersecurity protocols once
a year at a committee meeting. " That will
be part of your minutes and be well-documented
in case of an audit, " he notes.
Conley
likewise
suggests
that
providers lay out their procedures for the
committee to check. And invite a staff IT
or cybersecurity employee to that meeting;
this person will understand what questions
to ask, she adds.
As hackers
grow more
sophisticated-and
the methods to stop them
must continually evolve-requiring
annual reviews of providers' cybersecurity
practices is key.
" We've eliminated certain providers
because of the SOC 1 and SOC 2 discoveries
we made, " he says. These reports
document internal controls relevant to an
organization's financial statements.
Further, Kane helps plan commitcybersecurity
tees
perform annual
reviews. " We get updates every year from
the recordkeepers, " he says. " And we're
looking at their SOC 1 and SOC 2-not
He recommends having the
recordkeeper and other service
providers make a presentation
about their cybersecurity protocols
once a year at a committee meeting.
" This is a good time to reach out to
your service providers, if they haven't
reached out to you already, in response
to [the DOL] guidance, " says Lee. Some
vendors put out responses detailing how
they addressed each of the issues in the
DOL best practices guide, soon after the
tip sheets were released. " It can be good
to look at any service provider that has
access to sensitive or personal participant
information, because that can be
very valuable, too, " he says.
A Key Area for Advisers
A plan adviser can help with cybersecurity
reviews as well. Mike Kane,
founder and managing director of Plan
Sponsor Consultants, a division of Hub
International, in Atlanta, added cybersecurity
several years ago as one of the key areas
to address when helping plan committees
vet recordkeepers and other vendors.
" We have our own proprietary
recordkeeper, RFP, and we update it all
the time, " Kane says. " We added a cybersecurity
section and questions into the
RFP. " He also studies a firm's System and
Organization Controls 1 and/or 2 audit
reports for more information about how
it handled any cybersecurity situations.
just taking their word for it, " he says.
Besides asking service providers how they
identify, protect and respond to threats,
he asks detailed questions about what
internal testing is done on any threats,
what kind of penetration testing is done,
how often are unannounced assessments
conducted, and what kind of dark web
monitoring they perform.
" We have a discussion with the
committee about cybersecurity and what
the current recordkeeper is doing to meet
all of these criteria, " he says. " Then we go
a step further and request a report that
shows how you meet the cybersecurity
requirements and [DOL] guidance. "
Although most of the focus is on
the plan-and-provider
cybersecurity for
relationships, the third DOL tip sheet-
the online security tips for individuals-
can be the basis for a participant cybersecurity
education program. " There are
steps [plan sponsors] should be aware of
that they can take to protect their assets
in the plan, " says Conley. Plan committees
can sponsor educational events to help
participants learn about cybersecurity,
and some service providers offer cybersecurity
education programs, too.
-Kimberly Lankford
PLANSPONSOR.COM June - July 2022 35
http://www.PLANSPONSOR.COM

PLANSPONSOR - June - July 2022

Table of Contents for the Digital Edition of PLANSPONSOR - June - July 2022

INSIGHTS
RULES & REGULATIONS
UPFRONT
2022 Plan Sponsor of the Year Winners
By Extension
Talent Management
The Best Line of Defense
Under-the-Radar Plan Errors
FIDUCIARY FORUM
INSIDE ANGLE
PLANSPONSOR - June - July 2022 - Cover1
PLANSPONSOR - June - July 2022 - Cover2
PLANSPONSOR - June - July 2022 - 1
PLANSPONSOR - June - July 2022 - INSIGHTS
PLANSPONSOR - June - July 2022 - 3
PLANSPONSOR - June - July 2022 - RULES & REGULATIONS
PLANSPONSOR - June - July 2022 - 5
PLANSPONSOR - June - July 2022 - 6
PLANSPONSOR - June - July 2022 - 7
PLANSPONSOR - June - July 2022 - UPFRONT
PLANSPONSOR - June - July 2022 - 9
PLANSPONSOR - June - July 2022 - 10
PLANSPONSOR - June - July 2022 - 11
PLANSPONSOR - June - July 2022 - 12
PLANSPONSOR - June - July 2022 - 13
PLANSPONSOR - June - July 2022 - 2022 Plan Sponsor of the Year Winners
PLANSPONSOR - June - July 2022 - 15
PLANSPONSOR - June - July 2022 - 16
PLANSPONSOR - June - July 2022 - 17
PLANSPONSOR - June - July 2022 - 18
PLANSPONSOR - June - July 2022 - 19
PLANSPONSOR - June - July 2022 - 20
PLANSPONSOR - June - July 2022 - 21
PLANSPONSOR - June - July 2022 - 22
PLANSPONSOR - June - July 2022 - 23
PLANSPONSOR - June - July 2022 - 24
PLANSPONSOR - June - July 2022 - 25
PLANSPONSOR - June - July 2022 - 26
PLANSPONSOR - June - July 2022 - 27
PLANSPONSOR - June - July 2022 - By Extension
PLANSPONSOR - June - July 2022 - 29
PLANSPONSOR - June - July 2022 - 30
PLANSPONSOR - June - July 2022 - 31
PLANSPONSOR - June - July 2022 - Talent Management
PLANSPONSOR - June - July 2022 - 33
PLANSPONSOR - June - July 2022 - The Best Line of Defense
PLANSPONSOR - June - July 2022 - 35
PLANSPONSOR - June - July 2022 - Under-the-Radar Plan Errors
PLANSPONSOR - June - July 2022 - 37
PLANSPONSOR - June - July 2022 - FIDUCIARY FORUM
PLANSPONSOR - June - July 2022 - 39
PLANSPONSOR - June - July 2022 - INSIDE ANGLE
PLANSPONSOR - June - July 2022 - Cover3
PLANSPONSOR - June - July 2022 - Cover4
https://www.plansponsordigital.com/plansponsor/march_april_2024
https://www.plansponsordigital.com/plansponsor/january_february_2024
https://www.plansponsordigital.com/plansponsor/november_december_2023
https://www.plansponsordigital.com/plansponsor/september_october_2023
https://www.plansponsordigital.com/plansponsor/july_august_2023
https://www.plansponsordigital.com/plansponsor/may_june_2023
https://www.plansponsordigital.com/plansponsor/march_april_2023
https://www.plansponsordigital.com/plansponsor/december_2022_february_2023
https://www.plansponsordigital.com/plansponsor/october_november_2022
https://www.plansponsordigital.com/plansponsor/august_september_2022
https://www.plansponsordigital.com/plansponsor/june_july_2022
https://www.plansponsordigital.com/plansponsor/excellenceawards_2022
https://www.plansponsordigital.com/plansponsor/april_may_2022
https://www.plansponsordigital.com/plansponsor/february_march_2022
https://www.plansponsordigital.com/plansponsor/december_2021_january_2022
https://www.plansponsordigital.com/plansponsor/october_november_2021
https://www.plansponsordigital.com/plansponsor/august_september_2021
https://www.plansponsordigital.com/plansponsor/june_july_2021
https://www.plansponsordigital.com/plansponsor/april-may_2021
https://www.plansponsordigital.com/plansponsor/february-march_2021
https://www.plansponsordigital.com/plansponsor/december-january_2021
https://www.plansponsordigital.com/plansponsor/october-november_2020
https://www.plansponsordigital.com/plansponsor/august-september_2020
https://www.plansponsordigital.com/plansponsor/june-july_2020
https://www.plansponsordigital.com/plansponsor/april-may_2020
https://www.plansponsordigital.com/plansponsor/february-march_2020
https://www.plansponsordigital.com/plansponsor/december-january_2020
https://www.plansponsordigital.com/plansponsor/october-november_2019
https://www.plansponsordigital.com/plansponsor/august-september_2019
https://www.plansponsordigital.com/plansponsor/june-july_2019
https://www.plansponsordigital.com/plansponsor/april-may_2019
https://www.plansponsordigital.com/plansponsor/february-march_2019
https://www.plansponsordigital.com/plansponsor/december_2018-january_2019
https://www.plansponsordigital.com/plansponsor/october-november_2018
https://www.plansponsordigital.com/plansponsor/august-september_2018
https://www.plansponsordigital.com/plansponsor/june-july_2018
https://www.plansponsordigital.com/plansponsor/april-may_2018
https://www.plansponsordigital.com/plansponsor/february-march_2018
https://www.plansponsordigital.com/plansponsor/december_2017-january_2018
https://www.plansponsordigital.com/plansponsor/november_december_2017
https://www.plansponsordigital.com/plansponsor/october_2017
https://www.plansponsordigital.com/plansponsor/september_2017
https://www.nxtbookmedia.com