DOL Issues Cybersecurity Guidance for Plan Fiduciaries

Laner Muchin, Ltd.
Contact

Laner Muchin, Ltd.

In April, the U.S. Department of Labor (DOL), for the first time, issued cybersecurity guidance that was focused on retirement plans governed by the Employee Retirement Income Security Act of 1974 (ERISA) but could be applicable to many different benefit plans subject to ERISA. The guidance, which was provided by the DOL’s Employee Benefits Security Administration (EBSA) in the form of tips and best practices, does not have the impact of law or formal regulations, but it does set forth the DOL’s expectations and recommendations as to plan sponsors and fiduciaries with respect to protecting against and mitigating cybersecurity risks. The guidance sets forth specific tips for:

  1. hiring service providers to maintain plan records and keep participant data confidentiality
  2. recordkeepers and service providers to manage cybersecurity risks, and
  3. online security for plan participants and beneficiaries.

However, a general takeaway for plan sponsors and other plan fiduciaries may be that it is now clear that the DOL takes the position that fiduciaries have an obligation to manage and guard against cybersecurity risks and that this may become a focus of DOL investigations in the near future. As a result, and considering the guidance provided, now would be an opportune time for plan sponsors and other fiduciaries to adopt cybersecurity policies that align with the DOL recommendations and consider purchasing cyber liability insurance to protect against breaches of cybersecurity.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Laner Muchin, Ltd. | Attorney Advertising

Written by:

Laner Muchin, Ltd.
Contact
more
less

Laner Muchin, Ltd. on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide