Site icon The Law Firm of Anthony L. Scialabba, LLC

DOL Releases Cybersecurity Best Practices

On April 14, 2021, the DOL issued a package of cybersecurity guidance for retirement plan sponsors; fiduciaries who are subject to the Employee Retirement Income Security Act of 1974, as amended (“ERISA”); recordkeepers and other service providers; and participants and beneficiaries.  This is the first time that the DOL has issued guidance directly addressing cybersecurity.  The DOL’s cybersecurity guidance package was set forth in three separate documents:

1.   “Tips for Hiring a Service Provider With Strong Cybersecurity Practices”;

2.   “Cybersecurity Program Best Practices”; and

3.   “Online Security Tips”.

The DOL refers to the guidance as “tips”.  However, the guidance itself does appear to attempt to establish minimum expectations.  Thus, it would not be surprising if the DOL compares the cybersecurity practices concerning a retirement plan against the guidance that the government issued in an investigation situation. 


I.  Tips for Monitoring Whether a Service Provider Has Strong Cybersecurity Practices

A. Due Diligence

The DOL’s tips for hiring and monitoring service providers suggest significant due diligence obligations.  Plan sponsors should consider taking steps to evaluate existing service providers using the government’s inquiries.  The DOL’s suggested due diligence steps include the following:

  1. Ask about the service provider’s information security standards, practices and policies, and audit results, and compare that information to industry standards adopted by other service providers.  The DOL states that plan fiduciaries should look for service providers that follow a recognized standard for information security and use an outside (third-party) auditor to review and validate cybersecurity.  The government sets forth that a plan fiduciary can have “much more confidence” in the service provider’s systems and security practices if they are backed by annual audit reports verifying information security, system/data availability, processing integrity, and data confidentiality.
  1. Ask how the service provider validates its cybersecurity practices, and what levels of security standards have been implemented.
  1. Evaluate the service provider’s “track record” in the industry, including public information about information security incidents, other litigation, and legal proceedings related to the vendor’s services.
  1. Ask whether the service provider has experienced past security data breaches, what occurred, and how the vendor responded.
  1. Determine whether the service provider has any insurance policies that would cover losses covered by cybersecurity and identity theft breaches (including breaches caused by internal threats, such as misconduct by the service provider’s own employees or contractors, and breaches caused by external threats, such as a third party hijacking a plan participants’ account).

B. Contracting

The DOL’s tips on contracting with a service provider state that plan fiduciaries should “beware [of] contract provisions that limit the service provider’s responsibility for IT security breaches”  and should “look for” or “try to include” certain contract provisions.  The DOL’s tips for contract provisions are set forth as follows:

  1. Information Security Reporting:  Requiring the service provider to obtain a third-party audit annually to determine compliance with information security policies and procedures.
  1. Clear Provisions on the Use and Sharing of Information and Confidentiality:  Specifying and defining a service provider’s obligations to maintain the confidentiality of private information; to prevent the use or disclosure of confidential information without written permission; and to employ a strong standard of care to protect against unauthorized access, loss, disclosure, modification, or misuse of confidential information.
  1. Notification of Cybersecurity Breaches:  Identifying how quickly a fiduciary would be notified of any cyber incident or data breach and ensuring the service provider’s corporation to investigate and reasonably address the cause of the breach.
  1. Compliance With Records Retention and Destruction, Privacy and Information Security Laws:  Specifying the service provider’s obligations to meet all applicable laws (federal, state, and local) applicable to the privacy, confidentiality, or security of participants’ personal information.
  1. Insurance:  Requiring insurance coverage such as professional liability, errors and omissions liability, cyber liability and privacy breach, and/or fidelity bond/blanket crime coverage.  The DOL states that a plan fiduciary should understand the terms and limits of any such coverage.

II.  Recommendations

In light of the DOL guidance, plan fiduciaries should do the following:

  1. Review their service provider hiring practices and contracts with their vendors.
  1. Ensure that plan participants receive a copy of the DOL’s Online Security Tips document and keeping a record of that distribution.
Exit mobile version