Cybersecurity
Employee benefit plans possess sensitive data. As cyberattacks constantly change, cybersecurity preparedness and risk mitigation strategies should be top of mind for benefit plans. The resources below can help plan sponsors protect their organizations, plans and participants.
Accounting and Auditing Institute for Employee Benefit Plans
Attend The Accounting and Auditing Institute for Employee Benefit Plans to stay up to date on the latest in reporting and disclosure requirements and best practices in your profession. This is the premier conference for those who audit employee benefit plans. The program offers focused learning on the technical topics of greatest concern to the accounting and auditing profession. Learn best practices, interact with other professionals who face similar issues and fulfill your need for continuing professional education.
More InformationBenefit Communication and Technology Institute
The Benefit Communication and Technology Institute will bring you up to speed on the latest requirements, current trends and best practices for communicating your plans. Driven by ever-changing technological enhancements, social media, and new benefits legislation and regulations, this institute will give you the tools you need to evaluate your existing communications program. Take away practical ideas to ensure your plans are meeting their objectives and your employees are engaged in their benefit offerings.
More InformationHealth Plan Cybersecurity Update
Data breaches aren’t just an IT issue anymore—They’re a people, compliance, and fiduciary risk. In this webcast, we’ll unpack the latest cyber and data security trends, the most common threats targeting employee benefit data and actionable prevention strategies. Plus, we’ll cover post-breach response steps and what regulators are prioritizing in 2026. New trends to be aware of include:
- Identifying common threats
- Steps for prevention
- Post-breach action steps
- 2026 national enforcement projects.
Workplace Emergency Preparedness: 2020 Survey Report
Within the past five years, 80% of businesses in the United States experienced one or more unexpected events that caused a significant disruption in "business as usual." The unexpected disruptions come in many forms, such as natural disasters, cyberattacks or workplace violence. Over the last five years, winter storms/extreme cold (38%), loss of power due to blackouts or brownouts (34%), and loss of internet/phone service (31%) were the most frequently cited reasons for interruptions.
View ReportQuick Links
- Tips for Hiring a Service Provider [DOL]
- Cybersecurity Program Best Practices [DOL]
- Online Security Tips for Plan Participants [DOL]
- How to Create a Written Information Security Plan for Data Safety [IRS]
- Third‑Party Cyber Risk: Looking at Vendors’ Cybersecurity [NCPERS via Segal]
- Cybersecurity Audit Survival Kit: What Plan Sponsors Must Do to Pass [NAPA]
Articles
The Human Firewall: Training Workers to Outsmart Modern Cybersecurity Threats (Benefits Magazine, March/April 2026)
Comprehensive cybersecurity training addresses one of the leading causes of data breaches—human error. Employee benefit funds that provide such training to employees reduce the risk of a cyberattack while maintaining regulatory compliance. What content should cybersecurity training cover? Multiemployer benefit fund offices should cover the nature of the threats posed, organizational cybersecurity policies and procedures (the “why” behind the training), legal ramifications that organizations face if they fail to address cybersecurity, and how to report suspicious activity.
Crisis Management for Employee Benefit Fund Operations (Benefits Magazine, July/August 2025)
A crisis can occur at any time, without warning and with potentially serious consequences, especially if you are unprepared. Fortunately, proper planning can help your employee benefit plan ameliorate the impacts of hacking or other cybersecurity events. How can employee benefit plans assess what is needed to sustain operations and minimize damage in times of crisis? Start by conducting a formal risk assessment, then periodically remind staff of the cyber-risks and the red flags of fraud, and how they can be avoided. Key areas to address in business continuity include communication, access to information and equipment and maintaining confidentiality.
Evaluating Cybersecurity Vulnerabilities (Plans & Trusts, January/February 2024)
As the persistence of cyber threats grows, organizations and their employee benefit plans are attractive targets. What proactive measures can plan sponsors and trustees implement to support an effective cybersecurity program? Best practices for plans and trusts when implementing a cybersecurity program include identifying what data your plan needs to protect and determining its location, developing an incidence response plan, understanding breach notification requirements, maintaining detailed records of a breach, consulting legal counsel and training your employees on how to recognize and report security incidents promptly.
More articles available in Benefits Knowledge Center
Podcasts
Videos
Ask a Benefits Question
Not finding what you're looking for? We'll do the digging for you on any benefits-related topic.
Reach out to an Information Specialist today.
