September 2, 2026
Throughout this series, the Department of Labor’s cybersecurity best practices for employee benefit plans have been explored, from governance and access management to incident response, resiliency, training, and monitoring.
Throughout all of those topics, good cybersecurity practices alone are not enough. Organizations also need to be able to demonstrate them. As a third-party assessor for financial and information security audits, this is the most common type of deficiency: “The activity was completed, but no record exists to demonstrate it.”
As mentioned earlier in the series, cybersecurity continues to receive attention from the Department of Labor (DOL)’s Employee Benefits Security Administration (EBSA), and the DOL has made clear that its cybersecurity guidance applies broadly to ERISA plans. The guidance calls for formal, documented cybersecurity programs, risk assessments, independent assessments of security controls, documented incident-response processes, vendor oversight, training, and other safeguards.
Before turning to documentation, however, one additional piece of the cybersecurity puzzle is worth understanding: insurance.
In the DOL’s cybersecurity best practices, the DOL specifically recommends notifying the appropriate insurer when a cybersecurity incident or breach occurs, but the this raises the question: Which insurer?
Employee benefit plans and plan sponsors may have several different forms of insurance protection, and they are not interchangeable. For most plans, an ERISA Fidelity Bond is required, but a plan may also wish to have fiduciary liability and cybersecurity insurance. These later two are not required.
ERISA Fidelity Bond
An ERISA fidelity bond generally protects the plan itself from losses caused by fraud or dishonesty by individuals who handle plan funds or other property. Unlike the other coverages discussed below, ERISA generally requires persons who handle plan funds or property to be bonded, subject to certain exceptions.
For example, if an individual with access to plan assets fraudulently transfers or misappropriates those assets, the fidelity bond may be the relevant coverage.
Fiduciary Liability Insurance
Fiduciary liability coverage is different. Rather than protecting plan assets specifically from fraud or dishonesty, it generally addresses claims alleging a breach of fiduciary responsibility, subject to the specific terms, exclusions, and insured parties under the policy.
For example, a claim alleging that a plan fiduciary failed to prudently oversee a service provider could potentially implicate fiduciary liability coverage, depending on the circumstances and policy language.
Cyber Liability Insurance
Cyber coverage may respond to costs associated with certain privacy and security incidents. Depending on the policy, that could include forensic investigation, breach-response services, notification costs, legal or regulatory expenses, business interruption, data restoration, and other incident-response costs. The scope varies significantly from one policy to another, making an understanding of the policy’s specific coverage essential.
Before an incident occurs, know where the policies are located, what types of events may trigger them, what notification requirements apply, and who needs to be contacted. It may also be worthwhile to understand how the policies interact when an event potentially implicates more than one type of coverage.
Every plan sponsor should be able to identify the insurance in place, its general coverage, and the appropriate points of contact.
Documentation is important throughout the cybersecurity program to prove that components are actually operating. This evidence may be important for internal or external evaluations.
Imagine receiving a request tomorrow to demonstrate how the organization manages cybersecurity risk for the plan. Statements such as “Access is reviewed regularly” or “Vendor oversight is effective” will only go so far.
The next question is likely to request supporting documentation.
That evidence may look different depending on the control. The following examples illustrate evidence that may demonstrate the effective operation of various components of an organization’s cybersecurity program:
One additional challenge is that cybersecurity evidence rarely lives in one place.
HR may own training records. IT may own access logs and vulnerability scans. Legal or finance may maintain insurance policies. A committee secretary may have meeting minutes. The recordkeeper or another service provider may possess evidence for controls that have been outsourced.
That means documentation readiness is partly an ownership problem.
For each important area, plan sponsors should know two things:
Where does the evidence live, and who is responsible for producing it?
Third-party providers deserve particular attention. If an important control is performed by the recordkeeper, TPA, cloud provider, or another vendor, consider how the necessary documentation would be obtained. Contractual provisions governing access to information should be reviewed, along with the provider’s process and expected response time.
A useful way to evaluate a documentation program is to consider the following question:
If the Department of Labor sent an inquiry today, could the supporting documentation be assembled within 10 business days?
Based on discussions with practitioners who have seen these inquiries, 10 business days is often the time frame required for a response by the DOL. Regardless of the exact deadline on a particular request, the broader point is the same: the response may need to be prompt.
Try the following readiness exercise:
This exercise can help guide next steps in becoming better prepared.
Ultimately, a strong evidence file should tell a fairly simple story:
The risks were identified. Controls were established to address them. Those controls were performed. When problems were found, responsibility was assigned and corrective action was completed. Supporting documentation demonstrates each step.
That documentation can make an external assessment or regulatory inquiry substantially easier and ideally gives plan fiduciaries greater visibility into whether the cybersecurity program is functioning as intended.
And if the answer to the 10-business-day test today is yellow, or even red, that is useful information.
It is much better to find out before the letter arrives.
What types of insurance coverage may apply to an employee benefit plan?
An employee benefit plan or plan sponsor may have an ERISA fidelity bond, fiduciary liability insurance, and cyber liability insurance. An ERISA fidelity bond generally protects the plan from losses caused by fraud or dishonesty involving plan assets. Fiduciary liability insurance may respond to claims alleging a breach of fiduciary responsibility, while cyber liability insurance may cover certain costs associated with privacy and security incidents, subject to each policy’s terms and exclusions.
What documentation can demonstrate that a cybersecurity program is operating effectively?
Relevant evidence may include approved policies, committee minutes, risk assessments, access requests and reviews, vulnerability scan results, penetration testing reports, backup and recovery records, vendor inventories, SOC reports, training records, incident-response plans, tabletop exercise documentation, and records showing that identified issues were remediated.
Who should be responsible for maintaining cybersecurity evidence?
Responsibility may be distributed across HR, IT, legal, finance, plan committees, and third-party service providers. Plan sponsors should identify where each important record is maintained, assign an owner responsible for producing it, and establish a process for obtaining documentation held by external providers.
How can an organization assess its readiness for a regulatory inquiry or external assessment?
A practical test is whether the organization could assemble supporting cybersecurity documentation within 10 business days. Evidence that can be located and produced promptly indicates stronger readiness, while uncertainty about whether records exist, where they are stored, or who owns them identifies areas requiring improvement.
For additional guidance, please contact the Larson Cybersecurity Team.