Skip to content
Group employees attending cybersecurity awareness workshop.

DOL Cybersecurity Series: Ongoing Security and Awareness for Retirement Plan Systems

DOL Cybersecurity Series: Ongoing Security and Awareness for Retirement Plan Systems

September 3, 2026

Article Summary

  • Security awareness training plays an important role in the cybersecurity posture of an organization and should be conducted at least once a year.
  • Systems that support retirement plan administration should be subject to appropriate monitoring and alerting processes to identify potential security incidents and vulnerabilities.
  • Plan sponsors are responsible for regularly evaluating whether the service providers they engage with are meeting established cybersecurity expectations.

As part of the previous articles in this series, we discussed the importance of a robust cybersecurity program for retirement plans. Much of the focus in those articles was on implementing controls designed to prevent security incidents, mitigating risks within internal systems and third-party applications, and responding effectively to incidents as they occur. This article introduces two new best practices focused on regular cybersecurity awareness training and ongoing monitoring and testing. Like other installments in the series, the goal is to help retirement plan sponsors better understand the expectations for cybersecurity set by the Department of Labor’s Employee Benefits Security Administration and offer additional insights gained through Larson’s experience performing information security audits like SOC 2 and financial audits of employee benefit plans.

The importance of regular security awareness training

First Line of Defense

Regardless of how robust an organization’s security system may be, it is essential that employees remain diligent in their responsibilities for safeguarding the confidentiality, integrity, and availability of the systems and information they work with. Often the way in which attackers will compromise an organization is by stealing credentials from an employee and impersonating them. There are a variety of different ways that attackers will go about stealing these credentials, and these methods are continuing to change and evolve over time.

For this reason, a formal security awareness training should be held at least annually, with condensed security reminders and mini-trainings happening more frequently. All employees should be required to participate in these trainings. The subject matter and delivery format may vary, but the training should all be focused on educating employees to recognize common attack vectors, prevent cyber incidents, and report potential incidents to the appropriate channels. Training should also be updated to address specific risks identified through the organization’s most recent risk assessment.

One topic that should be a high priority to include in security awareness training is social engineering. Social engineering is where attackers will use social pressure or deception to persuade targets to divulge sensitive information or provide unauthorized access. The following are some common examples of social engineering.

Phishing

Phishing involves an attacker sending malicious emails disguised as legitimate requests. The email will typically contain an external link or an additional set of instructions that will attempt to persuade the recipient to disclose sensitive information or authorize a payment. Phishing attempts are not always obvious at first glance because attackers will often try to impersonate a coworker, manager, or client to disguise their request as one that is seemingly benign. It’s important that employees are trained on how to recognize and react to these emails. Security awareness training should provide guidance for spotting a fake or malicious email, as well as the steps employees should take if they suspect an email they have received is a phishing attempt. This is especially important for employees involved in retirement plan administration, as phishing attempts could be disguised as requests to change participant information, provide account access, or authorize distributions.

Vishing

Vishing is similar to phishing in the sense that an attacker will impersonate a trusted individual, but instead of email, they will initiate contact over the phone. Employees should be trained on how to recognize vishing attempts, such as the request appearing urgent or where the caller asks to circumvent a standard procedure. Employees should also be aware of what information should not be disclosed to an unverified caller, and what to do if they suspect they have been contacted in a vishing attempt. When in doubt, the employee should hang up and dial a known number for the caller. Where appropriate, identity-verification procedures should be established and closely followed to avoid the unauthorized disclosure of sensitive information.

Tailgating

Not all social engineering attempts will come digitally or over the phone. Tailgating is a method by which attackers gain physical access to restricted areas of a building by following closely behind an authorized individual or even asking someone to “hold the door” after the authorized individual scans their badge. Once inside, the attacker may try to blend in while looking for valuables, unattended devices, documents, or additional access to sensitive information. This method takes advantage of the human desire to be polite or helpful. Employees should therefore be trained on the organization’s physical security policies, including expectations for identifying and reporting suspicious individuals.

When we think of hackers or attempts to compromise our data, we tend to picture complex lines of code or malicious software breaking through robust digital defenses, but social engineering, although seemingly simpler, remains one of the most common ways organizations are compromised. For this reason, it’s important for organizations to see their personnel as a first line of defense against attacks and provide them with the knowledge necessary to recognize, respond to, and report social engineering attempts as they happen.

Ongoing monitoring

Detection and Response

As touched on briefly in previous articles, security monitoring and alerting are key components of a robust cybersecurity program. System monitoring consists of activities that analyze network traffic, system events, or user actions to identify suspicious activity, policy violations, or anomalies that may require investigation. Activities that indicate attempts at unauthorized actions in the system, unauthorized access to information, actions taken at abnormal times of the day, or attempted connections from unexpected geographic locations could all be an indication of an attempted attack and should be flagged by monitoring systems for additional review.

Monitoring can be performed manually by personnel reviewing system logs and activity, through automated systems that analyze data and generate alerts, or through a combination of both. Although automated systems can operate continuously, there is always a risk of false positives, in which automated systems identify legitimate or authorized actions as being potentially malicious. For this reason, organizations should establish a process for prioritizing, reviewing, escalating, and documenting alerts depending on the potential severity of the risk they pose. This approach helps to leverage the benefits of both automated analysis and human judgment. Automated systems can parse through much more information, while human review can help determine whether an alert represents authorized activity, a configuration error, or a potential cybersecurity incident.

Retirement plan administrators should ensure that the systems they are using for plan administration will generate logs for relevant activity, which may include user sign-ins, failed authentication attempts, requests to change personal or plan information, or requests to distribute funds. Additional review may be appropriate when related events occur in close succession, such as a distribution request following closely after a change to a participant’s personal or banking information.

ADDITIONAL CONSIDERATIONS FOR THIRD-PARTY SERVICE PROVIDERS

A Shared Responsibility

When plan sponsors rely on third-party service providers for systems or services, they should review and understand the service providers’ cybersecurity practices, including their approach to security awareness training, system monitoring, and alerting. Organizations should perform due diligence activities before engaging with service providers to understand how frequently personnel receive security awareness training, how relevant systems are monitored, and how the plan sponsor would be notified in the event of any incidents that might affect plan-related systems or plan participant data. For current vendors, there should also be a risk-based vendor review process performed at regular intervals (e.g. annually), through which the organization will review the services provided, evaluate current agreements, determine whether the arrangement remains appropriate, and assess whether the service provider continues to meet the organization's cybersecurity standards. For more information on managing vendor relationships refer to the previous article in this series.

Independent reports, such as SOC 1 or similar attestation engagements, can be helpful when reviewing a service provider. These reports are typically available every year and, depending on the scope of the examination and the controls included, may provide information pertaining to personnel training, event detection, and incident response processes the service provider has in place. Plan sponsors should review the report’s scope, the reporting period, the auditor’s opinion, and any exceptions (Larson can provide a template for this annual review upon request!). Plan sponsors should also keep in mind that if there are different providers supporting distinct aspects of the retirement plan system, the responsibilities and security commitments of each provider should be understood and evaluated. 

Final Thoughts

Unfortunately, cybersecurity in retirement plan administration does not have a one-size-fits-all solution, nor does it function like a switch that can be “flipped” to make our systems and data perfectly secure, confidential, and available. A truly robust cybersecurity program will continue to evolve as system parameters change and new risks emerge. For this reason, a thorough and frequent security awareness training program and continuous monitoring help to ensure that both the system and the personnel administering it are informed, vigilant and ready to detect and respond to any threats that come their way. 

Frequently Asked Questions about Secure software development and system resiliency

What topics should be covered in security awareness training?

Security awareness training should cover topics that are relevant to the industry and the personnel participating in the training. While most employees are likely to encounter phishing attempts or malicious websites, these topics may not be pertinent to all. A good practice is to base the topics of the training on the risks identified in the risk assessment. This will improve the likelihood that the training will be relevant to the employees and the systems they work with.

How can I make sure all my systems are monitored?

It’s very possible that your team works with many different systems that each generate unique logs for activity. One potential solution to assist in monitoring is a SIEM, or a Security Information and Event Management system. These systems can aggregate logs from multiple systems and generate alerts from a centralized location. Although this may not ensure these systems are perfectly monitored, it can help with sorting through many different logs.

How can plan sponsors determine whether a service provider has appropriate monitoring and security awareness practices in place?

Before engaging with a service provider, plan sponsors should verify what certifications they hold or which independent reports are performed for the provider. Plan sponsors could also create security questionnaires to send to potential service providers with questions pertaining to the provider’s security practices and standards. After reviewing these reports and questionnaires, plan sponsors can make a determination as to whether the service provider has fully addressed their concerns or if they would like to gather more information.

LEARN MORE ABOUT OUR EMPLOYEE BENEFIT PLAN CYBERSECURITY SERIES

For additonal guidance, please contact the Larson Cybersecurity Team.