There are some important developments concerning cybersecurity — so let’s push past the anxiety and talk about them. I was at a conference recently where a group of practitioners discussed cybersecurity for retirement plans. The topic admittedly makes me cringe as it dredges up some of the hardest situations I’ve ever helped clients navigate: theft — sometimes of nearly all a plan’s or saver’s assets. Ugh. Not exactly the kind of retirement policy discussion that brightens your day. While this isn’t a new topic — there are some important developments — so let’s push past the anxiety and talk about them. If, like me, you’re a fan of The Hitchhiker’s Guide to the Galaxy, you know the most important words printed on the cover of the Guide are simple: “Don’t Panic.” That’s excellent advice for both interstellar hitchhiking and cybersecurity incidents in retirement plans (which, trust me, feel almost as chaotic). Tempting as panic may feel in the moment — or even when contemplating the possibility of a theft from your plan — cybersecurity requires the opposite response. In today’s world, cybersecurity threats aren’t some sci-fi subplot. They’re part of the routine retirement plan administration that fiduciaries must face. Which brings us to an important lesson from Hitchhiker’s lore: Keep Calm and Carry a Towel (or, in this case, a prudent policy!). Or perhaps a towel and a policy — belt and suspenders never hurt anyone in ERISAland. Prudent Policy: The Cybersecurity Towel Translated into retirement plan terms, the wisdom “Keep Calm and Carry a Towel” holds up remarkably well. Keep calm: don’t let fear or confusion drive bad decisions or inaction. Carry a towel: be prepared with the right governance structures, documentation, and protections in place. Under ERISA, fiduciary prudence and loyalty don’t stop at selecting investments. The Department