Business professionals collaborating during a strategic meeting, discussing business planning, leadership, and organizational goals.

EBSA Cybersecurity Guidance for Retirement Plan Committees 

Charlie Hollingworth, Sue Morsawala
9/22/2026

Learn how retirement plan committees can use EBSA cybersecurity guidance to strengthen vendor oversight, governance, and fiduciary discussions.

Retirement plan committees should expect cybersecurity to remain a recurring governance topic. The U.S. Department of Labor’s Employee Benefits Security Administration (EBSA) clarified in 2024 that its cybersecurity guidance applies broadly across Employee Retirement Income Security Act of 1974 (ERISA) plans, including both pension plans and health and welfare plans. EBSA subsequently identified cybersecurity and benefit distribution protection as enforcement priorities, emphasizing the importance of understanding service provider controls, participant protections, and incident response. These developments reinforce cybersecurity as an ongoing fiduciary oversight responsibility rather than a one-time compliance exercise.

Integrate cybersecurity into ongoing committee governance

Retirement plan committees increasingly are treating cybersecurity as a priority they must address on a regular basis. While committees are not expected to evaluate technical controls, they should understand how service providers manage cyber risk and should revisit key oversight topics periodically.

Common retirement plan committee governance practices include:

  • Reviewing SOC 1 reports and, where available, SOC 2 reports from key providers. Service providers often share System and Organization Controls (SOC) 1 reports (financial-reporting-related controls) and sometimes SOC 2 reports (broader security controls) with committees. At a high level, the review might focus on coverage period, opinion, notable exceptions, management’s response, and complementary user entity controls.
  • Discussing authentication and distribution-validation practices with recordkeepers. Given the frequency of credential compromise cases, multi-factor authentication (MFA) adoption and distribution validation processes have become more common agenda topics. MFA is widely viewed as an effective risk-reduction tool because it adds a layer of login verification. Distribution validation processes might include bank account change verification, address and contact change monitoring, transaction holds, callback procedures, and added verification for full-balance distributions.
  • Understanding incident-notification and related escalation protocols. Committees might seek to understand, at a high level, how service providers identify and respond to cybersecurity events, including communication protocols, escalation steps, and expectations for notifying the plan sponsor if participant data or accounts are affected. Consideration also might apply to the review of the plan sponsor’s incident and escalation process.
  • Considering insurance interactions. Committees also might consider how ERISA bonds, fiduciary liability policies, and stand-alone cyber insurance policies interact in different scenarios. Typically, these discussions are conducted in coordination with insurance professionals.
  • Reinforcing participant security as part of committee oversight. Committee oversight also includes participant awareness. Participant education is one part of the broader control environment, and committees might want to understand how recordkeepers communicate security practices such as MFA, phishing awareness, and account monitoring. Retirement plan committees might consider sending periodic reminders or incorporating EBSA’s participant tips into ongoing communications.

Question service providers

EBSA’s “Cybersecurity Program Best Practices” outlines common elements of a mature control environment. For retirement plan committees, the point is not to perform a technical assessment themselves but to understand whether providers operate within a structured, tested, and well-documented control framework.

Committees can ask service providers the following questions to understand their alignment to the control framework:

  • Do you maintain a documented cybersecurity program that includes periodic risk assessments?
  • How do you identify, prioritize, and address emerging cybersecurity risks?
  • What independent assessments or audits do you undergo, and how are identified issues remediated?
  • Can you share relevant assurance reports, such as SOC reports, and discuss any significant findings?
  • How are your incident response and business resiliency plans tested and maintained?
  • How will you notify our organization if a cybersecurity incident affects participant data or plan operations?
  • What controls do you have in place for access management, MFA, and high-risk transactions?

Make cybersecurity a recurring governance discussion

EBSA’s 2024 clarification did not create a new technical standard, but it reinforced that cybersecurity remains relevant to ERISA plan oversight. For retirement plan committees, that means making cybersecurity a recurring governance discussion – understanding how service providers manage cyber risk, asking informed questions, documenting oversight activities, and staying engaged as risks and technologies evolve. Retirement plan committees should consider implementing a cadence for their recurring reviews, such as an annual cybersecurity and vendor review, periodic committee agenda items and discussion, and event-driven review after incidents, major provider changes, or significant control findings. These ongoing discussions can help support prudent fiduciary oversight while reinforcing the committee’s role in protecting plan participants and assets.

For an overview of EBSA’s cybersecurity guidance and the responsibilities of plan sponsors, service providers, and participants, read the Crowe article “Cybersecurity for ERISA Benefit Plans.”

Strengthen plan governance
Explore audit and advisory services that help support fiduciary oversight and governance.

Work with us


Crowe professionals can help retirement plan committees evaluate governance practices, discuss service provider oversight, assess cybersecurity-related risks, and strengthen fiduciary processes. Learn how our retirement plan audit and advisory services can help support your committee’s oversight responsibilities.

Charlie Hollingworth
Charlie Hollingworth
Partner, Audit & Assurance, Crowe LLP
Morsawala-Sue
Sue Morsawala
Senior Manager, Audit & Assurance, Crowe LLP

Related insights

loading gif
Alt Text: “Financial professionals discuss regulatory and accounting developments during a team meeting.
September 2026 Financial Reporting, Governance, and Risk Management
Fed vice chair calls for CECL relief, SEC proposes rules changes, FDIC and OCC rule prioritizes material financial risks, and more.
Business professionals collaborating during a strategic meeting, discussing business planning, leadership, and organizational goals.
EBSA Cybersecurity Guidance for Retirement Plan Committees
Explore practical guidance to help retirement plan committees strengthen cybersecurity oversight and support prudent fiduciary governance.
Business professionals reviewing information on a tablet while collaborating with colleagues in a modern office.
Why Fraud Oversight Is Becoming an Audit Committee Priority
Fraud risk governance has become an audit committee priority as enterprise risks continue to evolve across the organization.
Alt Text: “Financial professionals discuss regulatory and accounting developments during a team meeting.
September 2026 Financial Reporting, Governance, and Risk Management
Fed vice chair calls for CECL relief, SEC proposes rules changes, FDIC and OCC rule prioritizes material financial risks, and more.
Business professionals collaborating during a strategic meeting, discussing business planning, leadership, and organizational goals.
EBSA Cybersecurity Guidance for Retirement Plan Committees
Explore practical guidance to help retirement plan committees strengthen cybersecurity oversight and support prudent fiduciary governance.
Business professionals reviewing information on a tablet while collaborating with colleagues in a modern office.
Why Fraud Oversight Is Becoming an Audit Committee Priority
Fraud risk governance has become an audit committee priority as enterprise risks continue to evolve across the organization.