• Contact Us
  • 484-574-8782

Torrillo & Associates

  • Home
  • About
    • specialists
    • our team
    • Careers
  • Audit Process
  • Services
    • CPA firm partnership
  • Clients
  • Videos
  • Blog
Monday, September, 09, 2024 / Published in Employee Benefit Plans, News and Press Releases, Policy Updates, Retirement - 401(k), 403(b)

DOL Updates Cybersecurity Guidance

In its continuing effort to protect U.S. workers’ retirement and health benefits, the U.S. Department of Labor updated current cybersecurity guidance confirming that it applies to all types of plans governed by the Employee Retirement Income Security Act, including health and welfare plans, and all employee retirement benefit plans.

The new Compliance Assistance Release issued by the department’s Employee Benefits Security Administration provides best practices in cybersecurity for plan sponsors, plan fiduciaries, recordkeepers and plan participants. The release updates EBSA’s 2021 guidance and includes the following:

  • Tips for Hiring a Service Provider: Helps plan sponsors and fiduciaries prudently select a service provider with strong cybersecurity practices and monitor their activities, as ERISA requires.
  • Cybersecurity Program Best Practices: Assists plan fiduciaries and recordkeepers in mitigating risks.
  • Online Security Tips: Offers plan participants who check their online retirement accounts with rules for reducing the risk of fraud and loss.

As of June 2024, EBSA estimates ERISA covers 2.8 million health plans, 619,000 other welfare benefit plans and 765,000 private pension plans in America. These plans include 153 million workers, retirees and dependents who participate in private sector pension and welfare plans with $14 trillion in estimated assets. Without sufficient protections, digital participant and assets information may be vulnerable to the internal and external risks of computer-related crimes and losses. Federal regulations require plan fiduciaries to take appropriate precautions to mitigate these risks.

The Employee Benefits Security Administration believes cybersecurity is a great concern for all employee benefit plans and continues to investigate potential ERISA violations related to the issue.

The guidance complements EBSA’s regulations on electronic records and disclosures to plan participants and beneficiaries. These include provisions on ensuring that electronic recordkeeping systems have reasonable controls, adequate records management practices are in place and that electronic disclosure systems include measures calculated to protect Personally Identifiable Information.

Tagged under: 401(k), 403(b), Cybersecurity, Defined Benefit Plans, DOL, EBSA, Enforcement priorities, Pension Plans

What you can read next

IRS Terminating Proposed Penalty Notices for Untimely Filed or Incomplete Forms 5500
403(b) Pre-Approved Plan Program Established
New Revenue Procedures for the Employee Plan Compliance Resolution System, including 403(b) Plan Failures

Recent Posts

  • DOL Issues Guidance on Missing Participants and Transfers to State Unclaimed Property Funds

    Field Assistance Bulletin No. 2025-01, Missing ...
  • DOL Updates the Voluntary Fiduciary Correction Program

    Following up on proposed changes, the DOL has u...
  • Proposed Regulations on New Automatic Enrollment Requirement

    The Department of the Treasury and the Internal...

Categories

  • Employee Benefit Plans
  • Forms and Procedures
  • News and Press Releases
  • Policy Updates
  • Retirement – 401(k), 403(b)
  • Uncategorized

Torrillo & Associates, LLC specializes in employee benefit plan audits, 401k audits, 403b audits, pension plan audits, and retirement plan audits. We are licensed in 7 states including New York, New Jersey, and Pennsylvania.  With firm mobility, we are also able to practice in an additional 27 states.

36 Regency Plaza
Glen Mills, PA 19342

view on map »

Careers
Phone: 484-574-8782
Fax: 484-574-8785

  • GET SOCIAL
Torrillo & Associates

Copyright © 2010 to 2025 Torrillo & Associates, LLC. All rights reserved. v07.03.22.WPE| Privacy Policy | Terms of Use

TOP