cyber-security-employee-benefit

 

Cybersecurity and Employee Benefit Plans

Employee benefit plans continue to be targets of cyberattacks. In 2026, the Employee Benefit Security Administration (EBSA) added cybersecurity to its national enforcement projects for employee benefits plans. This made investigations into cybersecurity complaints a top priority. 

The EBSA reports that more than 156 million employees, retirees and family members are covered by employer health plans, private retirement plans or welfare benefits plans. Collectively, these plans hold around $13.8 trillion in assets. 

These numbers are a desirable target for cybercriminals.

Nearly all employee benefit plans contain high account balances and sensitive personal information for participants and beneficiaries. The following factors contribute to the increasing risk of a cyberattack:

  • Benefit plan information is almost always stored electronically.
  • Employers may not consider benefit plans when they formulate their cybersecurity policies.
  • Benefits plans have only been lightly regulated for cybersecurity in the past.

What information is at risk because of a cyberattack?

Employers and third-party service providers hold specific electronic information that is valuable for cyberattacks, including:

  • Personally identifiable information (PII), like Social Security numbers, birth dates and email addresses.
  • Participant account balances, direct deposit information, compensation and other financial information.
  • Electronic health information that can be used to acquire prescription drugs, falsify insurance claims, open credit accounts or obtain fraudulent government documents.

What are the consequences of a cyberattack?

A cybersecurity breach can damage your reputation and company finances, including costs related to the breach, losses to employees and benefit plans, lawsuits due to breach of fiduciary duty, and fines and sanctions from government agencies.

What responsibilities do plan sponsors have? 

Plan sponsors and certain third-party service providers have ERISA fiduciary obligations for each employee benefit plan they manage.

ERISA requires fiduciaries to administer the plan with the care, skill, prudence and diligence that a prudent person would use under the same circumstances. Department of Labor (DOL) regulations provide specific requirements for the protection and confidentiality of personal information. Depending on the state you do business in, you may have additional cybersecurity requirements.

Cybersecurity best practices:

  • Create a formal, documented cybersecurity program.
  • Perform annual risk assessments.
  • Conduct regular cybersecurity audits.
  • Establish defined security roles and responsibilities.
  • Use strong access controls including MFA.
  • Conduct employee training.
  • Integrate cybersecurity controls into system development, implementation, and technology changes.
  • Develop an incident response program.
  • Encrypt sensitive data and follow IT best practices.

Protect your business from cyber liability claims brought on by cyber criminals. To learn more about Cyber Liability Insurance and to get a quote, click here.