Skip to content
male professional with checkmark icons on screen

Cybersecurity Documentation and Audit Readiness for Plan Sponsors

Cybersecurity Documentation and Audit Readiness for Plan Sponsors 

September 2, 2026

Article Summary

  • Employee benefit plans may have several forms of insurance protection, including an ERISA fidelity bond, fiduciary liability insurance, and cyber liability insurance, each serving a different purpose.
  • Effective cybersecurity programs require documentation showing that controls were designed, performed, reviewed, and remediated when issues were identified.
  • Plan sponsors should know where cybersecurity evidence is maintained, who owns it, and how supporting records can be obtained from internal teams and third-party providers.
  • A practical readiness test is whether the organization could assemble supporting cybersecurity documentation promptly, including within a potential 10-business-day response period.

Throughout this series, the Department of Labor’s cybersecurity best practices for employee benefit plans have been explored, from governance and access management to incident response, resiliency, training, and monitoring.

Throughout all of those topics, good cybersecurity practices alone are not enough. Organizations also need to be able to demonstrate them. As a third-party assessor for financial and information security audits, this is the most common type of deficiency: “The activity was completed, but no record exists to demonstrate it.”

As mentioned earlier in the series, cybersecurity continues to receive attention from the Department of Labor (DOL)’s Employee Benefits Security Administration (EBSA), and the DOL has made clear that its cybersecurity guidance applies broadly to ERISA plans. The guidance calls for formal, documented cybersecurity programs, risk assessments, independent assessments of security controls, documented incident-response processes, vendor oversight, training, and other safeguards.

Before turning to documentation, however, one additional piece of the cybersecurity puzzle is worth understanding: insurance.

Understanding the Plan’s Insurance Coverage

In the DOL’s cybersecurity best practices, the DOL specifically recommends notifying the appropriate insurer when a cybersecurity incident or breach occurs, but the this raises the question: Which insurer?

Employee benefit plans and plan sponsors may have several different forms of insurance protection, and they are not interchangeable. For most plans, an ERISA Fidelity Bond is required, but a plan may also wish to have fiduciary liability and cybersecurity insurance. These later two are not required.

ERISA Fidelity Bond

An ERISA fidelity bond generally protects the plan itself from losses caused by fraud or dishonesty by individuals who handle plan funds or other property. Unlike the other coverages discussed below, ERISA generally requires persons who handle plan funds or property to be bonded, subject to certain exceptions.

For example, if an individual with access to plan assets fraudulently transfers or misappropriates those assets, the fidelity bond may be the relevant coverage.

Fiduciary Liability Insurance

Fiduciary liability coverage is different. Rather than protecting plan assets specifically from fraud or dishonesty, it generally addresses claims alleging a breach of fiduciary responsibility, subject to the specific terms, exclusions, and insured parties under the policy.

For example, a claim alleging that a plan fiduciary failed to prudently oversee a service provider could potentially implicate fiduciary liability coverage, depending on the circumstances and policy language.

Cyber Liability Insurance

Cyber coverage may respond to costs associated with certain privacy and security incidents. Depending on the policy, that could include forensic investigation, breach-response services, notification costs, legal or regulatory expenses, business interruption, data restoration, and other incident-response costs. The scope varies significantly from one policy to another, making an understanding of the policy’s specific coverage essential.

Before an incident occurs, know where the policies are located, what types of events may trigger them, what notification requirements apply, and who needs to be contacted. It may also be worthwhile to understand how the policies interact when an event potentially implicates more than one type of coverage.

Every plan sponsor should be able to identify the insurance in place, its general coverage, and the appropriate points of contact.

Documentation: If You Did It, Can You Prove It?

Documentation is important throughout the cybersecurity program to prove that components are actually operating. This evidence may be important for internal or external evaluations.

Imagine receiving a request tomorrow to demonstrate how the organization manages cybersecurity risk for the plan. Statements such as “Access is reviewed regularly” or “Vendor oversight is effective” will only go so far.

The next question is likely to request supporting documentation.

That evidence may look different depending on the control. The following examples illustrate evidence that may demonstrate the effective operation of various components of an organization’s cybersecurity program:

  • Governance: Committee or board minutes, a cybersecurity program description, charters, documented roles and responsibilities, and approved policies
  • Risk assessments: The assessment itself including identified risks, assigned owners, remediation activities, target dates, and resolution; documentation demonstrating active follow-through for remediation
  • Access management: Access requests and approvals, periodic access reviews, records showing completion of access granting, modification or removal according to the organization’s policy requirements
  • Technical controls and resiliency: Vulnerability scan results, penetration testing reports, backup logs, disaster recovery and incident-response plans, records from tabletop exercises, meeting notes, identified weaknesses, and subsequent remediation
  • Vendor oversight: A vendor inventory, due-diligence documentation, completed cybersecurity questionnaires, contracts, SOC 2 or SOC 1 reports including records showing that those reports were reviewed, and documentation of how exceptions or other concerns identified during the review were evaluated and resolved (Larson can provide a SOC report review template for organizations looking for a more structured way to document that process)
  • Training and monitoring: Training completion records, attendance reports, testing results or monitoring reports, and corrective actions taken when an issue was identified
  • Insurance and incident response: The policies themselves and their annual review, records of notices provided to insurers, incident records, and evidence that the incident-response process has been practiced (tabletop) even if the organization has not experienced a significant event

Know Where the Evidence Lives and Who Owns It

One additional challenge is that cybersecurity evidence rarely lives in one place.

HR may own training records. IT may own access logs and vulnerability scans. Legal or finance may maintain insurance policies. A committee secretary may have meeting minutes. The recordkeeper or another service provider may possess evidence for controls that have been outsourced.

That means documentation readiness is partly an ownership problem.

For each important area, plan sponsors should know two things:

Where does the evidence live, and who is responsible for producing it?

Third-party providers deserve particular attention. If an important control is performed by the recordkeeper, TPA, cloud provider, or another vendor, consider how the necessary documentation would be obtained. Contractual provisions governing access to information should be reviewed, along with the provider’s process and expected response time.

The 10-Business-Day Test

A useful way to evaluate a documentation program is to consider the following question:

If the Department of Labor sent an inquiry today, could the supporting documentation be assembled within 10 business days?

Based on discussions with practitioners who have seen these inquiries, 10 business days is often the time frame required for a response by the DOL. Regardless of the exact deadline on a particular request, the broader point is the same: the response may need to be prompt.

Try the following readiness exercise:

  • Green: The evidence, its location, and its owner are known, allowing prompt production
  • Yellow: The evidence is believed to exist, but finding or assembling it may require additional work
  • Red: The evidence’s existence or location is unknown, or timely retrieval is uncertain

This exercise can help guide next steps in becoming better prepared.

Documentation Should Tell the Story

Ultimately, a strong evidence file should tell a fairly simple story:

The risks were identified. Controls were established to address them. Those controls were performed. When problems were found, responsibility was assigned and corrective action was completed. Supporting documentation demonstrates each step.

That documentation can make an external assessment or regulatory inquiry substantially easier and ideally gives plan fiduciaries greater visibility into whether the cybersecurity program is functioning as intended.

And if the answer to the 10-business-day test today is yellow, or even red, that is useful information.

It is much better to find out before the letter arrives.

Frequently Asked Questions About Cybersecurity Insurance and Documentation Readiness

What types of insurance coverage may apply to an employee benefit plan?

An employee benefit plan or plan sponsor may have an ERISA fidelity bond, fiduciary liability insurance, and cyber liability insurance. An ERISA fidelity bond generally protects the plan from losses caused by fraud or dishonesty involving plan assets. Fiduciary liability insurance may respond to claims alleging a breach of fiduciary responsibility, while cyber liability insurance may cover certain costs associated with privacy and security incidents, subject to each policy’s terms and exclusions.

What documentation can demonstrate that a cybersecurity program is operating effectively?

Relevant evidence may include approved policies, committee minutes, risk assessments, access requests and reviews, vulnerability scan results, penetration testing reports, backup and recovery records, vendor inventories, SOC reports, training records, incident-response plans, tabletop exercise documentation, and records showing that identified issues were remediated.

Who should be responsible for maintaining cybersecurity evidence?

Responsibility may be distributed across HR, IT, legal, finance, plan committees, and third-party service providers. Plan sponsors should identify where each important record is maintained, assign an owner responsible for producing it, and establish a process for obtaining documentation held by external providers.

How can an organization assess its readiness for a regulatory inquiry or external assessment?

A practical test is whether the organization could assemble supporting cybersecurity documentation within 10 business days. Evidence that can be located and produced promptly indicates stronger readiness, while uncertainty about whether records exist, where they are stored, or who owns them identifies areas requiring improvement.

LEARN MORE ABOUT OUR EMPLOYEE BENEFIT PLAN CYBERSECURITY SERIES

For additional guidance, please contact the Larson Cybersecurity Team.