For more stories like this, sign up for the PLANSPONSOR NEWSDash daily newsletter.
Responding to a Cyber Breach Takes a Village
Experts say participants, recordkeepers and plan sponsors share responsibilities in making participants whole after experiencing a loss.
While the Department of Labor continues to prioritize protecting retirement plans from cybersecurity risks, some attention must be given to dealing with and preventing those breaches that make it through the loopholes.
Experts say when a participant’s account is breached, it takes a multi-party effort to make the individual whole.
Brea Dantin, a retirement plan adviser at Shepherd Financial, says the first step any party can take in the wake of a cybersecurity breach is to notify the recordkeeper—that way the participant’s account can be locked down to prevent further harm.
“If I’m the participant, I want to notify the provider and plan sponsor, that way … everyone is on high alert,” Dantin says. She says some recordkeepers’ cybersecurity guarantees even require that the participant or sponsor notify the recordkeeper as soon as there is cause to believe there is a breach.
Participants’ Onus
The most engaged participants—those who log into their accounts frequently—may immediately notice signs of a cyber breach, Dantin says. But even the more diligent crowd could still miss signs.
However, participants are the “first line of defense” against breaches, Dantin says. Some insurers’ cybersecurity protection guarantees even require that participants create accounts and set secure passwords before they can enjoy the services of a financial backstop policy.
A big concern after a retirement account breach occurs is also what data—especially personally identifiable information, including the participant’s Social Security number, date of birth and home address—might unlock the door to further financial account breaches. Dantin says she encourages participants not to have their blinders on in thinking it is only their retirement account that is affected.
Liability as the “Wild West”
Dantin says the question as to who is responsible for making a participant whole if assets are stolen in a data breach is like the “wild, wild west.” Some recordkeepers will take responsibility, but not all will.
Lisa Matthews, vice president of fraud and risk at IRALogix, an individual retirement account rollover technology platform, says plan sponsors might want to determine whether their contract with a recordkeeper includes a provision for a data breach.
Matthews says that when investigating cybersecurity breaches, the DOL will often inquire about what the fiduciary’s recordkeeper’s insurance covers. Plan sponsors will often want to have it include a voluntary customer protection restoration guarantee, which can be important to negotiate at the beginning of the hiring process, she says.
The industry is “always hoping to find a way to make the participant whole,” says Kevin Walsh, a principal in Groom Law Group who advises clients on fiduciary matters. “But someone is going to be holding the bag as a result of criminal behavior.”
Walsh says a plaintiff filing a cybersecurity suit against a plan sponsor might probe whether the particular recordkeeper the company hired had known vulnerabilities, be it through disclosures made or complaints lodged against the recordkeeper. Hiring despite knowing of the vulnerabilities might help demonstrate the sponsor acted imprudently in its hiring of the recordkeeper.
Walsh describes the DOL Employee Benefits Security Administration’s “Cybersecurity Program Best Practices ,” issued in 2021 and updated in 2024, as “in-depth tips” for what plan sponsors would want to do to have a high standard of preventing loss. The guide is that it is meant to help fiduciaries make prudent service provider hiring decisions, he says.
The best practices state that when a cybersecurity breach occurs, steps to protect the plan and its participants include:
- “informing law enforcement;
- notifying the appropriate insurer;
- investigating the incident;
- notifying participants of unauthorized acquisition of their personal data, including personally identifiable information and protected health information, without reasonable delay;
- giving affected plans and participants the information necessary to prevent/reduce injury;
- honoring any contractual or legal obligations with respect to the breach, including complying with agreed upon notification requirements; and
- fixing problems that caused the breach to prevent its recurrence.”
Shepherd’s Dantin says the recordkeeper’s response, including its timeliness and scale, should help advise a sponsor whether they should continue that provider.
“If we’re going to have a voluntary [retirement] system, we can’t put employers in the business of insuring against all cybersecurity vulnerabilities,” Walsh says. “ERISA isn’t a strict liability statute—it’s a prudence statute.”
You Might Also Like:
Trade Groups Push for Overhaul of Consolidated Audit Trail
How Plan Sponsors Can Manage AI Opportunities, Risks
DOL ERISA Enforcement: 10 Areas of Current Focus
« As CIT Adoption Surges, Retirement Industry Races to Modernize

