In the Darkness at the Edge of Town…Cybersecurity Guidance for Plan Participants, Record-Keepers, and Plan Sponsors From The EBSA

Holland & Hart - The Benefits Dial
Contact

Holland & Hart - The Benefits Dial

On April 14, 2021, the Employee Benefits Security Administration (“EBSA”) published guidance for plan sponsors, plan fiduciaries, record-keepers, and plan participants on best practices for maintaining cybersecurity. This is the first time that the EBSA has given cybersecurity guidance to the estimated 34 million defined benefit plan and the 106 million defined contribution plan participants with an estimated $9.3 trillion in assets.

The guidance emphasizes that the participants and assets are at risk from internal and external cybersecurity threats, and that ERISA fiduciaries have an obligation to take appropriate precautions to minimize these risks.

There are three parts to the guidance:

(i) Tips for Hiring a Service Provider,

(ii) Cybersecurity Program Best Practices, and

(iii) Online Security Tips.

While this guidance is intended to help plan sponsors, fiduciaries, and participants to safeguard their retirement benefits and personal information, the mention of fiduciary duties should also be noted. We recommend that ERISA fiduciaries review this guidance because failure to follow these recommended practices, or at least to implement comparable procedures, would not look good in the event of a breach and claims by participants or other parties for lax security procedures.

In addition, we review service provider agreements, and many times the service providers reject liability for cybersecurity breaches altogether in initial drafts of these agreements. If you have not reviewed your service provider contracts for cybersecurity, this guidance would be a good occasion to do that. The guidance is intended to work with other EBSA guidance on electronic records and disclosures.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Holland & Hart - The Benefits Dial | Attorney Advertising

Written by:

Holland & Hart - The Benefits Dial
Contact
more
less

Holland & Hart - The Benefits Dial on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide