Retirement plan sponsors and financial professionals face a growing set of legal and operational responsibilities at the intersection of cybersecurity law and ERISA compliance. Cyberattacks on retirement plans have increased significantly in recent years, and the regulatory environment has evolved in response, with Department of Labor guidance creating new expectations for plan fiduciaries around cybersecurity practices and data security.

In this seminar, industry professionals explore the legal and practical dimensions of protecting retirement accounts from cyber threats while meeting fiduciary obligations under ERISA. The session addresses the full landscape of issues facing plan sponsors, wealth advisors, accountants, and financial professionals who need to understand both the security risks and the legal requirements that accompany them.

Topics Covered in the Seminar

The seminar addresses a range of cybersecurity and fiduciary issues that plan sponsors and their advisors encounter in today’s threat environment. Topics include:

  • Overview of cyber threats in the digital age, including the most common attack vectors targeting retirement plan data and assets
  • Fiduciary duties under ERISA as they apply to cybersecurity practices and data protection responsibilities
  • Legal implications of cyberattacks on retirement plans, including participant notification obligations and regulatory exposure
  • Trends in ransomware and how attackers target financial services and plan administration systems
  • Participant responsibilities and best practices for securing account access and protecting personal information
  • Cyber insurance and its role in a plan’s overall risk management strategy
  • Future directions in regulatory requirements beyond current DOL guidelines

Each topic is addressed with both practical guidance and attention to the legal framework that governs plan sponsors and their service providers.

ERISA Fiduciary Duties and Cybersecurity

The Department of Labor’s cybersecurity guidance, issued in 2021, established expectations for plan fiduciaries around cybersecurity practices for the first time. That guidance identifies best practices for online security, service provider oversight, and participant data protection, and it reflects the DOL’s position that cybersecurity is a component of a plan fiduciary’s overall duty of prudence under ERISA.

Plan sponsors who have not reviewed their cybersecurity practices in light of the DOL guidance face potential liability exposure if a breach occurs and the plan or its participants suffer losses as a result. Understanding what the guidance requires and how to implement appropriate controls is now a core component of fiduciary responsibility for any plan sponsor maintaining participant records or online access to plan accounts.

Who Should Watch This Seminar

This seminar was designed for plan sponsors who maintain retirement plans for their employees, wealth advisors who work with clients on retirement and financial planning, accountants who advise businesses on plan compliance, and financial professionals with responsibilities related to plan administration and security. The content is practical and accessible, covering both the threat landscape and the legal requirements that create obligations for plan fiduciaries and their advisors.

Privacy and Cybersecurity Law at Mandelbaum Barrett PC

Mandelbaum Barrett PC’s privacy and cybersecurity attorneys advise plan sponsors, financial institutions, and businesses on compliance with ERISA cybersecurity requirements, data privacy laws, and the full range of legal obligations arising from the evolving threat environment. The firm’s attorneys also handle matters involving cyber insurance, ransomware response, and data breach notification requirements.

To speak with a member of the firm’s legal team about ERISA cybersecurity compliance or other data privacy and security matters, contact Mandelbaum Barrett PC through the contact page. Our attorneys are prepared to assist plan sponsors and financial professionals with the legal dimensions of cybersecurity risk management.

Share: