DOL Cybersecurity Series: Incident Response and Vendor Risk Management
Article Summary
An incident response plan helps organizations quickly investigate, contain, communicate, and recover from cybersecurity incidents while minimizing disruption. Organizations should define roles, responsibilities, notification obligations, and regularly test response procedures. Retirement plan sponsors should also perform due diligence before engaging third-party service providers and continue monitoring them throughout the relationship, evaluating independent assessments, contractual protections, and provider resiliency capabilities.
Introduction
In previous articles in this series, we discussed cybersecurity governance, risk assessments, access management, and oversight of service providers. We also introduced the concept of business resiliency through business continuity and disaster recovery planning.
Those plans establish how an organization will continue operating and restore critical systems following a disruption. Equally important is understanding how the organization will respond while a cybersecurity incident is unfolding.
This article focuses on two additional best practices emphasized by the Department of Labor (DOL): developing an effective incident response capability and performing ongoing due diligence over third-party service providers. While these recommendations are outlined in the DOL's Cybersecurity Program Best Practices, we've included practical recommendations based on Larson's experience performing cybersecurity and control-based audits.
Responding When an Incident Occurs
No organization can eliminate cybersecurity risk entirely. The goal is to detect incidents quickly, respond appropriately, minimize the impact, and learn from the event afterward. An incident response plan complements business continuity and disaster recovery planning by documenting procedures for investigating, containing, communicating, and recovering from cybersecurity events.
Define the Process Before You Need It
The first few hours of a cybersecurity incident are often the most important. An incident response plan should clearly define what constitutes a cybersecurity incident, who has authority to activate the response process, and the responsibilities of each individual involved. The plan should also establish procedures for documenting actions taken and preserving evidence for investigators, insurers, regulators, or law enforcement when appropriate.
Respond Quickly and Communicate Effectively
Once an incident has been identified, the focus shifts to understanding what happened, containing the issue, and limiting further damage. Depending on the circumstances, organizations may need to engage law enforcement, notify their cyber insurance carrier, preserve evidence, and determine whether legal or contractual notification requirements have been triggered.
If participant information such as personally identifiable information (PII) or protected health information (PHI) has been compromised, affected individuals should receive timely communication describing what occurred, the information involved, and practical steps they can take to reduce potential harm. Organizations should also comply with contractual notification obligations and coordinate closely with service providers throughout the investigation.
Learn From Every Incident
An incident response effort should not end when systems are restored. Every significant event should be followed by an after-action review to identify root causes, evaluate the effectiveness of the response, and determine what technical, procedural, or training improvements should be made. Updating the incident response plan after each exercise or incident helps reduce the likelihood and impact of future events.
Vendor Risk Management
Retirement plans rely heavily on third-party service providers. Third-party administrators, recordkeepers, payroll providers, custodians, and investment platforms often perform critical functions and maintain sensitive participant information.
Because so much of the day-to-day administration of a retirement plan is outsourced, selecting and overseeing service providers is an important part of a plan sponsor's cybersecurity responsibilities.
Evaluate Service Providers Before Engagement
Due diligence should begin before a contract is ever signed.
The DOL recommends understanding a provider's security standards, practices, and policies before entrusting them with sensitive information. This may include requesting copies of security policies, SOC reports, independent assessments, or other documentation demonstrating how the provider protects information.
Organizations should also ask how those controls are validated. Are they independently audited? Does management perform internal assessments? What evidence exists that the controls are operating effectively?
In addition to reviewing documentation, it is worthwhile to understand the provider's reputation within the industry. Public litigation, enforcement actions, or prior cybersecurity incidents do not necessarily mean a provider should be avoided, but they do provide an opportunity to understand how the provider responded and what improvements were made afterward.
Organizations should also ask whether critical services are performed by subcontractors. If so, understand how those downstream providers are selected, monitored, and included within the provider's security program.
Ultimately, ask yourself a simple question: If our organization were protecting this information ourselves, would we expect these same security practices?
Establish Expectations Through the Contract
A good contract establishes expectations before problems arise.
In addition to defining the services being provided, contracts should address:
- Minimum cybersecurity and information security requirements
- Independent audits or SOC reporting
- Incident notification timeframes
- Cooperation during investigations
- Confidentiality and acceptable use of participant information
- Data retention and destruction requirements
- Compliance with applicable privacy and information security laws
- Appropriate insurance coverage, including cyber liability and professional liability
Contracts should also be reviewed carefully for provisions that unnecessarily limit the provider's responsibility following a cybersecurity incident. Those limitations should be understood before entering into the relationship—not after an incident has occurred.
Continue Monitoring the Relationship
Vendor oversight does not stop after the onboarding process.
Organizations should maintain a vendor inventory or similar tracking document that identifies each provider, the services performed, the internal relationship owner, overall risk rating, dates of prior reviews, documentation received, and any outstanding issues identified during those reviews.
This inventory provides a practical way to prioritize oversight. A third-party administrator or recordkeeper responsible for participant information will naturally require more attention than a vendor providing office supplies or janitorial services.
Periodic reviews should evaluate both cybersecurity and operational performance. Has the provider continued to meet its contractual obligations? Have there been significant organizational changes, security incidents, or changes in ownership? Have updated SOC reports or cybersecurity assessments been obtained and reviewed?
Organizations should also understand whether critical service providers maintain their own business continuity, disaster recovery, and incident response capabilities. A resilient organization depends on resilient service providers.
Final Thoughts
Preventing cybersecurity incidents will always be an important objective. However, organizations should also assume that disruptions will occur from time to time.
Developing a practical business resiliency program and performing thoughtful oversight of third-party service providers can significantly reduce the impact of those events when they occur.
Like most areas of cybersecurity, these activities are not one-time projects. They should evolve alongside the organization, its technology, and the risks it faces.
Frequently Asked Questions
What is an incident response plan? It is a documented set of procedures for detecting, investigating, containing, recovering from, and learning from cybersecurity incidents.
When should participants be notified? If unauthorized access to participant information occurs, organizations should meet applicable legal and contractual notification requirements without unreasonable delay.
How often should organizations test their business continuity and incident response plans? The Department of Labor recommends testing business resiliency plans at least annually. For many organizations, a tabletop exercise involving key business leaders is an effective way to evaluate roles, communication procedures, and decision-making before an actual incident occurs. After each exercise—or an actual incident—organizations should perform an after-action review, document lessons learned, and update their plans to address any identified weaknesses.
What should retirement plan sponsors look for when evaluating a service provider's cybersecurity? Before engaging a service provider, plan sponsors should review the provider's security policies, independent assessments such as SOC reports, cybersecurity insurance coverage, breach history, and overall reputation. Organizations should also understand whether critical services are outsourced to subcontractors and how those subcontractors are monitored. The goal is to determine whether the provider's cybersecurity practices are appropriate for the sensitivity of the participant information and plan assets it will be responsible for protecting.
How should organizations monitor third-party service providers after they are hired? Vendor oversight should continue throughout the relationship, not just during the initial selection process. Organizations should maintain a vendor inventory documenting each provider, the services performed, the internal relationship owner, review dates, overall risk rating, and any outstanding issues identified during prior reviews. Periodic reviews can help confirm that providers continue to meet contractual cybersecurity requirements, maintain appropriate security controls, and effectively support the organization's business resiliency objectives.
For additional guidance, please contact the Larson Cybersecurity Team.
Cameron is an Audit Partner with Larson & Company. He specializes in audit and advisory services for a wide range of companies.
LinkedIn