Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

DOL Issues First Ever Cybersecurity Guidance

By Audrey Fenske on April 16, 2021
Email this postTweet this postLike this postShare this post on LinkedIn

On April 14, 2021, the Department of Labor’s (DOL) Employee Benefits Security Administration issued guidance on cybersecurity for the first time to help plan sponsors, fiduciaries, service providers, and participants protect personal information and retirement assets. In the guidance, the DOL identifies evaluating cybersecurity practices as part of the plan sponsor’s or other plan fiduciary’s duty to prudently select and monitor plan service providers and states that ensuring proper mitigation of cybersecurity risks is a fiduciary obligation.  The guidance is provided in three documents:

  • Tips for Hiring a Service Provider, which provides plan sponsors and fiduciaries with questions to ask before selecting a service provider and items to include in contracts with service providers;
  • Cybersecurity Program Best Practices, which includes best practices for recordkeepers and service providers and can be used by fiduciaries to prudently select service providers; and
  • Online Security Tips, which includes steps participants and beneficiaries can take to reduce the risk of fraud and losses to their retirement accounts.

The guidance is intended to complement the DOL’s regulations on electronic records and disclosures, which require a plan administrator using electronic disclosure to take steps reasonably calculated to protect the confidential information of participants and beneficiaries. For more information on the electronic disclosure regulations, see Stinson’s previous blog post: New DOL Electronic Disclosure Safe Harbor Offers Relief for Retirement Plans.

There has been a recent increase in litigation involving cybersecurity and retirement plans. Some of these lawsuits allege a breach of fiduciary duty by a plan administrator or plan sponsor for failing to prudently select and monitor service providers or by a service provider for failing to establish processes to prevent fraudulent withdrawals. Plan sponsors and fiduciaries should carefully review the new DOL cybersecurity guidance as part of broader measures to protect plan assets and personal information.

For more information, contact Audrey Fenske, Stephanie Schmid, or the Stinson LLP contact with whom you regularly work.

Photo of Audrey Fenske Audrey Fenske

Audrey works with a wide range of clients, from individual executives, small private companies, and non-profit organizations to large multinational, publicly traded corporations to develop benefits, incentive, and equity plans, and executive employment agreements. She helps companies draft and amend qualified plans, reviews…

Audrey works with a wide range of clients, from individual executives, small private companies, and non-profit organizations to large multinational, publicly traded corporations to develop benefits, incentive, and equity plans, and executive employment agreements. She helps companies draft and amend qualified plans, reviews service provider contracts, advises on fiduciary issues, and advises on operational and tax issues impacting compensation and benefit programs, including issues under Code Sections 409A, 457(f), and 280G. Audrey also assists clients in participation in IRS (EPCRS) and DOL (VFCP) programs.

Read more about Audrey FenskeEmailAudrey's Linkedin Profile
Show more Show less
  • Posted in:
    Employment & Labor
  • Blog:
    Benefit Notes
  • Organization:
    Stinson LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo