Cyber risk is an operational, financial, and governance issue for organizations that sponsor and administer employee benefit plans. Retirement plans and health and welfare plans covered by the Employee Retirement Income Security Act of 1974 (ERISA) can hold substantial assets and process sensitive participant data, making them attractive targets for cybercriminals.
Cybersecurity is a shared responsibility across the benefits ecosystem
The U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) guidance addresses cybersecurity across three points of control, and each point matters. A plan’s cybersecurity outcome is only as strong as its weakest dependency, often a third party or a participant with compromised credentials.
These three key audiences are the focus of the EBSA guidance:
- Plan sponsors and fiduciaries are responsible for governance, vendor selection, and oversight. EBSA frames cybersecurity as part of prudent risk mitigation for these roles. The roles are defined as:
- ERISA plan sponsor: Typically, the employer (or other entity) that establishes or maintains the benefit plan
- Plan fiduciary: A person or entity with discretionary authority or control over plan management, plan assets, or plan administration, often including individuals who select and oversee service providers
- Recordkeepers and other service providers are responsible for controls, monitoring, and resilience. They are defined as:
- Third parties that operate plan-related IT systems and handle plan data (for example, participant account platforms, claims systems, payroll integrations, enrollment portals, call centers, and cloud hosting)
- Plan participants are responsible for secure use of online accounts. Participant behavior (including password hygiene, phishing resistance, and monitoring) is an important layer of defense. Participants are defined as:
- Employees, retirees, and beneficiaries who access plan services and accounts
How plan sponsors and fiduciaries can strengthen vendor oversight
Plan sponsors and fiduciaries can demonstrate prudent vendor selection and monitoring by following a due diligence and contracting road map:
- Ask about security standards, policies, and System and Organization Controls (SOC) 1 reports and compare them to industry norms; look for recognized standards and SOC 1 audits.
- Understand how the provider validates its controls; ensure contracts allow sponsors and fiduciaries to review SOC 1 reports.
- Evaluate the provider’s track record, including publicly known security incidents and related proceedings.
- Ask directly about past breaches and how the provider responded.
Assess insurance coverage for cyber and identity theft losses (including internal and external threat scenarios).
- Build cybersecurity into the contract. Include ongoing compliance requirements, clear confidentiality and data-use terms, defined breach notification timelines and cooperation obligations, compliance with applicable privacy and security laws, and appropriate insurance requirements.
Crowe takeaway
Third-party risk is fiduciary risk. Oversight needs to be structured and repeatable, not a one-time onboarding exercise. Cybersecurity due diligence should extend beyond vendor selection. Plan sponsors and fiduciaries should establish ongoing monitoring processes that help validate whether service providers continue to meet security expectations as threats, technologies, and business relationships evolve. See EBSA’s publication “Tips for Hiring a Service Provider With Strong Cybersecurity Practices” for more information.
What EBSA expects from service providers and recordkeepers
At a high level, EBSA emphasizes that providers should maintain a formal, well-documented cybersecurity program that identifies and assesses internal and external risks and enables the organization to identify, protect, detect, respond, recover, and restore operations.
From there, EBSA highlights recurring program elements that are worth treating as bare minimum requirements:
- Annual risk assessments with a defined scope, methodology, and cadence, updated to stay on top of changing threats and technology
- Independent third-party SOC 1 examinations of security controls and documented remediation of issues
-
Clear security roles and responsibilities, managed at a senior level and executed by qualified personnel (including training and background checks)
- Strong access controls, including least privilege, periodic access reviews, unique strong passwords, and broad deployment of multifactor authentication (MFA), especially for internet-facing and remote-access pathways
- Third-party and cloud risk management, including security reviews and independent assessments, contractual protections, and defined notification protocols for incidents
- Cybersecurity awareness training at least annually, recognizing that social engineering and identity theft are persistent drivers of loss
- Secure system development life cycle practices, including security testing (for example, code review and penetration testing) and controls related to account changes and high-risk distributions
-
Business resiliency across business continuity, disaster recovery, and incident response, with clear reporting, communications protocols, testing, and after-action improvement
- Encryption for sensitive data at rest and in transit, plus strong technical controls (such as patching, firewalls, malware protection, segmentation, hardening, and backups)
- Incident responsiveness, including investigation, notifications as required, and corrective actions to prevent recurrence
Crowe takeaway
The presence of a policy is not the point. Effective cybersecurity programs are demonstrated through execution, not documentation alone. Fiduciaries should look for evidence that providers regularly test controls, address findings, and continually improve their security posture. See EBSA’s publication “Cybersecurity Program Best Practices” for a concrete view of what EBSA expects capable service providers to have in place.
Reducing fraud risk through participant account security
Credential theft, phishing, and weak authentication remain among the most common real-world paths to fraud. Participants should:
- Register, set up, and routinely monitor online plan accounts to detect unauthorized activity
- Use strong, unique passwords and passphrases (including longer passphrases and passwords created by a password manager)
- Avoid reusing credentials
- Enable MFA wherever available
- Keep contact information current and close unused accounts; turn on activity notifications
-
Avoid risky connectivity (such as free public Wi-Fi) and stay alert to phishing warning signs
- Keep devices updated with current patches and reputable anti-malware tools
- Know how to report identity theft and cyber incidents
Crowe takeaway
Participant security often is treated as out of scope, but EBSA’s posture is clear: It is a material line of defense. Even the strongest governance and technology controls can be undermined by compromised credentials. Participant education and awareness can serve as an important layer of protection against fraud and account takeover risks. EBSA offers a participant-facing publication “Online Security Tips.”
Cybersecurity is an ongoing fiduciary consideration
Cybersecurity threats continue to evolve, and employee benefit plans remain attractive targets because of the assets and sensitive information they hold. While EBSA's guidance is not a one-size-fits-all framework, it provides a practical foundation for evaluating governance practices, third-party oversight, cybersecurity controls, and participant security.
Plan sponsors and fiduciaries should treat cybersecurity as an ongoing risk management and oversight responsibility. Organizations that regularly assess risks, monitor service providers, and reinforce participant security practices can be better positioned to protect plan assets and demonstrate prudent fiduciary stewardship.