Retirement plan committees should expect cybersecurity to remain a recurring governance topic. The U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) clarified in 2024 that its cybersecurity guidance applies broadly across Employee Retirement Income Security Act of 1974 (ERISA) plans, including both pension plans and health and welfare plans. EBSA subsequently identified cybersecurity and benefit distribution protection as enforcement priorities, emphasizing the importance of understanding service provider controls, participant protections, and incident response. These developments reinforce cybersecurity as an ongoing fiduciary oversight responsibility rather than a one-time compliance exercise.
Retirement plan committees increasingly are treating cybersecurity as a priority they must address on a regular basis. While committees are not expected to evaluate technical controls, they should understand how service providers manage cyber risk and should revisit key oversight topics periodically.
Common retirement plan committee governance practices include:
EBSA’s “Cybersecurity Program Best Practices” outlines common elements of a mature control environment. For retirement plan committees, the point is not to perform a technical assessment themselves but to understand whether providers operate within a structured, tested, and well-documented control framework.
Committees can ask service providers the following questions to understand their alignment to the control framework:
EBSA’s 2024 clarification did not create a new technical standard, but it reinforced that cybersecurity remains relevant to ERISA plan oversight. For retirement plan committees, that means making cybersecurity a recurring governance discussion – understanding how service providers manage cyber risk, asking informed questions, documenting oversight activities, and staying engaged as risks and technologies evolve. Retirement plan committees should consider implementing a cadence for their recurring reviews, such as an annual cybersecurity and vendor review, periodic committee agenda items and discussion, and event-driven review after incidents, major provider changes, or significant control findings. These ongoing discussions can help support prudent fiduciary oversight while reinforcing the committee’s role in protecting plan participants and assets.
For an overview of EBSA’s cybersecurity guidance and the responsibilities of plan sponsors, service providers, and participants, read the Crowe article “Cybersecurity for ERISA Benefit Plans.”
Crowe professionals can help retirement plan committees evaluate governance practices, discuss service provider oversight, assess cybersecurity-related risks, and strengthen fiduciary processes. Learn how our retirement plan audit and advisory services can help support your committee’s oversight responsibilities.