Retirement plans have “high balances and low engagement,” explained David Ogg, a business information security officer at Principal at the PSCA National Conference in St. Louis, Missouri. And these factors make them vulnerable to cyber-attacks. The Employee Benefit Security Administration (EBSA) flagged cybersecurity as key enforcement priority for this year. Panelists discussed how sponsors can reduce risk for their participants. When polled during the session, 64% of attendees responded that participants’ behavior was the greatest source of cybersecurity risk for their company, with lower values for internal processes and vendor relationships. However, only 21% of attendees said that cybersecurity responsibilities are clearly defined at their firm and only 10% said that they had a documented cyber response policy that is tested annually (45% said they were unsure if they even had one). All polls had around 55 respondents. Ogg added that inactive accounts are vulnerable to fraud because they aren’t monitored as much, and workers in industries that make limited use of computers also tend to check their accounts less frequently. Employers should urge plan participants to check their accounts regularly. How to Protect Accounts The panelists discussed the Colgate-Palmolive lawsuit from 2022. This case featured a woman who lost over $750,000 in retirement savings from a cyber fraud scheme. The case settled in 2024. Ogg explained that multi-factor authentication should be mandatory in retirement plans, but it was only optional for this plan, which is what made it possible for the fraudsters to empty the account. He added that biometric passkeys will likely be more common in the future. Stephen McCaffrey, a senior counsel at National Grid, urged sponsors to negotiate for specific provisions when contracting vendors. He explained that responsibility for cyber events should be clearly defined. Sponsors should follow-up on these contractual provisions at least annually to
Managing <b>Cybersecurity</b> Risk as a Plan Fiduciary: PSCA National
Read the original article
psca.org →