In its continuing effort to protect U.S. workers’ retirement and health benefits, the U.S. Department of Labor (DOL) recently updated the 2021 cybersecurity guidance confirming that it applies to all types of plans governed by the Employee Retirement Income Security Act (ERISA), including health and welfare plans, and all employee retirement benefit plans.
The new Compliance Assistance Release issued by the department’s Employee Benefits Security Administration provides best practices in cybersecurity for plan sponsors, plan fiduciaries, recordkeepers and plan participants. The release updates EBSA’s 2021 guidance and includes the following:
- Tips for Hiring a Service Provider: Helps plan sponsors and fiduciaries prudently select a service provider with strong cybersecurity practices and monitor their activities, as ERISA requires.
- Cybersecurity Program Best Practices: Assists plan fiduciaries and recordkeepers in mitigating risks.
- Online Security Tips: Offers plan participants who check their online retirement accounts with rules for reducing the risk of fraud and loss.
Cybersecurity Program Best Practices
In light of this latest guidance, plan fiduciaries should review their cybersecurity practices to ensure cybersecurity risks are mitigated. Best practices include the following considerations:
- Maintain a cybersecurity program that is well-documented and responds to cybersecurity threats. These include written policies and procedures, notification requirements and correction of identified risks.
- Conduct comprehensive risk assessments to identify risks and gaps in compliance. Correct any deficiencies.
- Enlist third-party service providers to conduct annual audits of security to identify weaknesses in business cybersecurity practices.
- Implement and assign information security roles and responsibilities for overseeing the cybersecurity program.
- Implement access control procedures such as multi-factor authentication, limit and monitor access.
- Conduct annual cybersecurity awareness training for all personnel.
- Implement resiliency program and a secure system development life cycle program to ensure new systems are created with cybersecurity concerns addressed.
- Utilize encryption.
- Evaluate service provider cybersecurity practices to ensure level of security appropriate and that they conduct their own risk assessments and audits.
- Ensure service providers respond to potential security breaches according to their incident response plan.
- Ensure service provider contracts require compliance with these standards.
Conclusion
The updated guidance makes it clear that all employee benefits plans should have a cybersecurity business plan in place. Plan sponsors should evaluate their cybersecurity policies and procedures for compliance with this latest guidance. Need help? Contact your Leavitt Group Trusted Advisor for access to available resources.
