Subscribe (Free) to
Daily or Weekly Newsletters
Post a Job

Featured Jobs

Plan Consultant

BPAS
(Remote / Utica NY / Hybrid)

BPAS logo

Plan Consultant

BPAS
(Utica NY / PA / Hybrid)

BPAS logo

Retirement Plan Administrator

Southern Pension Services
(Remote / Tampa FL / CO / Hybrid)

Southern Pension Services logo

Plan Consultant - DB/CB

MAP Retirement
(Remote)

MAP Retirement logo

Retirement Plan Consultant

July Business Services
(Remote / Waco TX)

July Business Services logo

Relationship Manager for Defined Benefit/Cash Balance Plans

Daybright Financial
(Remote)

Daybright Financial logo

Cash Balance/ Defined Benefit Plan Administrator

Steidle Pension Solutions, LLC
(Remote / NJ)

Steidle Pension Solutions, LLC logo

ESOP Administration Consultant

Blue Ridge Associates
(Remote)

Blue Ridge Associates logo

Relationship Manager

Retirement Plan Consultants
(Urbandale IA / Hybrid)

Retirement Plan Consultants logo

Retirement Plan Administration Consultant

Blue Ridge Associates
(Remote)

Blue Ridge Associates logo

Managing Director - Operations, Benefits

Daybright Financial
(Remote / CT / MA / NJ / NY / PA / Hybrid)

Daybright Financial logo

Retirement Relationship Manager

MAP Retirement
(Remote)

MAP Retirement logo

3(16) Fiduciary Analyst

Anchor 3(16) Fiduciary Solutions
(Remote / Wexford PA)

Anchor 3(16) Fiduciary Solutions logo

DB Account Manager

Pentegra
(Remote)

Pentegra logo

Staff Accountant

BPAS
(Huntingdon Valley PA / Hybrid)

BPAS logo

Regional Vice President, Sales

MAP Retirement USA LLC
(Remote)

MAP Retirement USA LLC logo

View More Employee Benefits Jobs

Free Newsletters

“BenefitsLink continues to be the most valuable resource we have at the firm.”

-- An attorney subscriber

Mobile app icon
LinkedIn icon     Twitter icon     Facebook icon

103,710 Items Curated by BenefitsLink®

News Archive

All News > Cybersecurity

Get this news and more in our free daily email newsletters.
American Retirement Association [ARA] Link to more items from this source
Nov. 13, 2025

"A professional uniquely positioned to discuss cybersecurity in the context of retirement plans offers her insights on the nuances and hard realities of protecting assets, balances, sensitive information and more from unauthorized access.... She observed that 73% of the organizations that experience a breach of security experience a second one. And this, she said, 'is because they didn't identify the cause and didn't fix it.' "  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

The Rosenbaum Law Firm P.C. Link to more items from this source
[Opinion]
Nov. 11, 2025

"ERISA’s Section 404 talks about acting prudently and solely in the interest of participants. That used to mean watching fees, monitoring investments, and keeping minutes. But in 2025, prudence means locking down your participant data like it’s Fort Knox. Every Social Security number, every date of birth, every account balance—those are plan assets in digital form."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties

EPIC Link to more items from this source
Nov. 11, 2025

"Recent guidance from both the [DOL] and the New York State Department of Financial Services (DFS) underscores the importance of due diligence and ongoing oversight of ... third-party administrators (TPAs), carriers, and technology platforms ... Outsourcing the administration does not absolve you of your fiduciary duty.... Here's a checklist to guide your due diligence related to cybersecurity."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Health Plan Administration

The Rosenbaum Law Firm P.C. Link to more items from this source
Oct. 9, 2025

"[1] Cybersecurity is a fiduciary issue.... [2] Vet and tighten your vendor contracts now.... [3] Look for documentation, not just policies ... [4] Train your people, and document that training.... [5] Check your insurance, and insist on cyber coverage.... [6] Bring cybersecurity into your plan oversight meetings.... Cybersecurity isn't just an IT problem, it's an ERISA oversight issue. "  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Tags: Cybersecurity  •  Retirement Plan Administration

Golan Christie Taglia Link to more items from this source
Aug. 29, 2025

"Cyber-attacks on Section 401(k) plans and their participant accounts are not only increasing in number but, with the use of AI, they are increasing in sophistication. Plan fiduciaries ... need to take steps to protect plan assets from these risks by implementing appropriate cybersecurity measures. All employees (not just HR staff) need to be aware of cybersecurity risks because those risks cannot be managed solely by IT security protocols such as secure messaging and multi-factor authentication."  MORE >>

Tags: 401(k) Plans  •  Cybersecurity  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
[Guidance Overview]
Aug. 20, 2025

"In its ongoing efforts to bolster cybersecurity in ERISA-covered plans, the [DOL] has issued multiple layers of guidance, one of which is a set of Online Security Tips.... These tips aren't directed at plan sponsors or fiduciaries, but the DOL, including them in the broader cybersecurity release, implies a clear expectation: you should inform your participants."  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

Health Affairs Scholar Link to more items from this source
[Opinion]
Aug. 18, 2025

"Over the past decade, the electronic health record (EHR) market has become increasingly consolidated, with the majority of care delivery organizations now using one of two vendors ... This consolidation creates a 'single-point-of-failure' tail risk for cybersecurity ... Given that reversing consolidation is unlikely due to high EHR switching costs, it is critical that policymakers establish safeguards that ensure robust protections for patients' sensitive data.... Sustained investment in regulatory oversight and continued partnerships between policymakers, care delivery organizations, and EHR vendors are essential to contain the catastrophic risk involved from this ongoing market consolidation."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration

PLANSPONSOR; registration may be required Link to more items from this source
July 29, 2025

"Personal data belonging to most of Allianz Life Insurance Co. of North America's 1.4 million U.S. customers was exposed on July 16 ... The breach was discovered one day after a 'malicious threat actor' hacked into a third-party customer relationship management system used by the insurer ... An attorney for Allianz submitted a disclosure of the breach to the office of the Maine attorney general."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Retirement Plan Administration

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Schechter Benefits Law Group LLP Link to more items from this source
June 24, 2025

"As a plan sponsor, taking steps to secure your plan data isn't optional, it's part of your legal duty to act in your participants' best interests.... [1] Review your vendor contracts for cybersecurity language. [2] Request and review audit reports from your service providers. [3] Implement basic security practices for your internal team. [4] Educate your participants about protecting their accounts. [5] Document your efforts as part of fiduciary oversight."  MORE >>

Tags: Cybersecurity  •  Fiduciary Duties  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
June 18, 2025

"[1] Establish a formal cybersecurity program ... [2] Conduct annual risk assessments ... [3] Require independent third-party audits ... [4] Define security roles and implement strong access controls ... [5] Ensure secure management of cloud services and vendors ... [6] Implement secure development practices and business resiliency programs ... [7] Encrypt sensitive data and maintain strong technical controls ... [8] Prepare for and respond to cybersecurity incidents."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Clark Schaefer Hackett Link to more items from this source
June 13, 2025

"Begin by asking providers about their cybersecurity policies and practices. Their protocols should align with standards like NIST or ISO/IEC 27001.... Explore the provider's history of handling security incidents. Transparency is key -- ask how they've responded to breaches in the past, and check for any related legal or regulatory issues.... Strong contracts reinforce good cybersecurity."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

National Conference on Public Employee Retirement Systems [NCPERS] Link to more items from this source
June 10, 2025

"[1] Review daily, weekly, or monthly reports from the vendor's cybersecurity monitoring tools ... [2] Audit the vendor site and perform your own cybersecurity review and/or assessment. [3] Ask the vendor to provide annual copies of approved and objective third-party cybersecurity assessments. [4] Contract with your own cybersecurity experts to do penetration testing against your vendor (with your vendor's knowledge that the tests are occurring, of course)."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Nixon Peabody LLP Link to more items from this source
June 4, 2025

"Ransomware attacks on healthcare organizations surged in 2024, with nearly 400 US providers reporting incidents.... [H]ealthcare breaches now average $9.77 million -- the highest across all industries for the 14th year. [HHS] also noted a sharp rise in ransomware cases, driven by outdated systems, misconfigured devices, and cloud vulnerabilities.... This article outlines key strategies for healthcare organizations to prevent, respond to, and recover from ransomware incidents -- while minimizing legal exposure and reputational harm."  MORE >>

Tags: Cybersecurity  •  HIPAA

Defined Contribution Institutional Investment Association [DCIIA] Link to more items from this source
May 30, 2025

"This paper seeks to help plan sponsors understand today's rapidly changing data risk environment. [The authors] discuss how participant accounts are vulnerable to data breaches, highlight updated regulatory guidance, and offer action steps for plan committee consideration, in partnership with the plan's overall organization, consultant/advisor and counsel as needed.' [Also available: 'Take Action" Checklist]  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

Craig Gottwals via Substack; registration may be required Link to more items from this source
[Opinion]
May 12, 2025

"[HIPAA's] outdated definitions and narrow scope have created a gaping hole -- one that data brokers, app developers, retail pharmacies, and even your stop-loss underwriter are sprinting through with glee. And the worst part? This data dragnet ... [is] making your health plan more expensive, less accurate, and more vulnerable to being rated and lasered based on guesswork."  MORE >>

Tags: Cybersecurity  •  HIPAA  •  Health Plan Policy

Tags: Cybersecurity  •  Fiduciary Duties  •  Health Plan Administration  •  Retirement Plan Administration

Tags: Cybersecurity  •  HIPAA

HUB International Link to more items from this source
May 5, 2025

"Health and welfare plan sponsors will find that many vendors already emphasize cybersecurity.... [T]he DOL's guidance serves as a valuable checklist for sponsors to evaluate their service providers through a fiduciary lens.... [S]ponsors should assess their internal cybersecurity measures, especially if they retain sensitive plan-related data. ERISA's 'prudence' requirement hinges on adopting a sound process -- a hallmark of effective fiduciary responsibility."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration

Segal via NCPERS Link to more items from this source
May 5, 2025

"The more vendors you work with, the greater the chance you'll be impacted by a cybersecurity incident affecting one of them.... [E]very vendor you work with likely works with other vendors, increasing the probability that you'll be affected by an incident.... If a vendor cannot provide an objective, third-party cybersecurity assessment, like a SOC2 report or other attestation, showing that it has solid cyber protections in place, that's a red flag."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration  •  Retirement Plan Administration

Colonial Surety Company Link to more items from this source
Apr. 23, 2025

"Not only is the cash in retirement accounts valuable, so too is the associated personal data.... While it is impossible to eliminate the cybersecurity threats to retirement plans, sponsors need to know that as ERISA fiduciaries, they are obligated to mitigate cybersecurity threats, and ... failure to mitigate cyber threats can result in fiduciary breach allegations which put the personal assets of sponsors at risk:"  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration

Gallagher Link to more items from this source
Apr. 16, 2025

"Exposures such as IT supply chain dependencies, website tracking litigation, ransomware attacks, new security regulations and data breach class actions put healthcare organizations of all sizes at high risk for cyber insurance claims. Understanding trends in cyber attacks as well as the evolving regulatory and litigation environment is critical to building resilience and maximizing insurance indemnification."  MORE >>

Tags: Cybersecurity  •  Health Plan Administration

Savant Link to more items from this source
Apr. 15, 2025

"[1] Why 401(k) plans are prime targets ... [2] The regulatory landscape: what the DOL expects ... [3] Key actions for plan sponsors in 2025 ... [4] More than risk management: a business advantage ... [5] Looking ahead: what's next in 401(k) cybersecurity ... [6] A fiduciary duty you can't ignore."  MORE >>

Tags: 401(k) Plans  •  Cybersecurity

Carol Buckmann Link to more items from this source
Apr. 2, 2025

"In the last week of February, six class actions were filed in the U.S. District Court for the Northern District of Illinois against [one] retirement plan administrator ... These complaints illustrate the many federal and state causes of action that can be pursued by aggrieved plaintiffs in addition to [ERISA] claims, including emotional distress, invasion of privacy and violation of consumer fraud laws. ... While no protections are 100% foolproof, [the plan administrator] might have avoided these suits by following a good written cybersecurity policy."  MORE >>

Tags: Cybersecurity  •  Retirement Plan Administration