Cybersecurity guidance for 401(k) fiduciaries is lacking, GAO says

Cybersecurity guidance for 401(k) fiduciaries is lacking, GAO says
The GAO concluded that plan sponsors, record keepers and others have little to go on as far as guidelines from the Department of Labor and that it isn’t clear whether fiduciaries have the responsibility to minimize cybersecurity risks.
MAR 15, 2021

Cybersecurity poses a major risk to 401(k) plans, and there is chasm in guidance on how plan fiduciaries should address it, according to a report released Monday from the Government Accountability Office.

In the report made public by several members of Congress, the GAO analyzed feedback from dozens of retirement plan service providers and sponsors. It pointed to several instances of 401(k) accounts being fraudulently raided by thieves, events that have been well-publicized through the private litigation that followed.

But the GAO concluded that plan sponsors, record keepers and others have little to go on as far as guidance from the Department of Labor, and that it also isn’t clear whether fiduciaries have responsibility to minimize cybersecurity risks, according to the report.

“GAO is making two recommendations to DOL to formally state whether it is a fiduciary’s responsibility to mitigate cybersecurity risks in DC plans and to establish minimum expectations for addressing cybersecurity risks in DC plans,” the report stated. “DOL agreed with GAO’s second recommendation, but did not state whether it agreed or disagreed with the first one.”

The report illuminates the web of personal information shared among plan sponsors, record keepers, custodians, third-party administrators and payroll service providers. The information includes names, Social Security numbers, birthdates, addresses, usernames, passwords, asset data and account numbers. The storage and sharing of that data amounts to a mountain of risks.

Among the stakeholders the GAO interviewed, 21 of 22 said that assuring cybersecurity is in fact a fiduciary duty.

How fiduciaries should go about that is currently a bit of a mystery.

“DOL officials told GAO that the agency intends to issue guidance addressing cybersecurity-related issues, but they were unsure when it would be issued,” the report read. “Until DOL clarifies responsibilities for fiduciaries and provides minimum cybersecurity expectations, participants’ data and assets will remain at risk.”

In 2019, the year that Congress commissioned the GAO report, there were roughly half a million reports to the FBI of suspected cybercrimes, with associated losses of more than $3.5 billion, according to the report. With 106 million people participating in 401(k)s and assets of about $6.3 trillion in the system in 2018, that is a big target for cyberfraud, the GAO noted.

Sen. Patty Murray, D-Wash., said in a statement that she would be working with the Biden administration and Congress to further address cybersecurity for 401(k)s.

“It’s clear that in too many ways, the policies we have to protect families as they plan for the future are stuck in the past,” Murray said in the announcement. “This report confirms cybersecurity and retirement security go hand in hand, and it’s time we make sure we have policies that reflect that reality.” 

Latest News

Advisor moves: RBC swipes $1.7B UBS team, Baird duo departs for LPL's Linsco channel
Advisor moves: RBC swipes $1.7B UBS team, Baird duo departs for LPL's Linsco channel

RBC Wealth Management's latest move in New York adds an elite eight-member team to its recently opened Westchester office.

Stifel star broker, Chuck Roberts, leaves firm under cloud of investor complaints
Stifel star broker, Chuck Roberts, leaves firm under cloud of investor complaints

Stifel – so far - is on the hook for more than $166 million in damages, legal fees and settlements in investor complaints involving Roberts, a 35-year industry veteran.

iCapital secures $820M in latest funding, hits $7.5B
iCapital secures $820M in latest funding, hits $7.5B

The giant alt investments platform's latest financing led by T. Rowe Price and SurgoCap Partners, along with State Street, UBS, and BNY, will fuel additional growth on multiple fronts.

Merrill Lynch on the hook for $3.7M after clients claimed sale of unsuitable private equity
Merrill Lynch on the hook for $3.7M after clients claimed sale of unsuitable private equity

Some investors recently have seen million dollar plus decisions by FINRA arbitration panels involving complex products decisions go their way.

What does it take to feel 'financially comfortable' or 'wealthy' in 2025?
What does it take to feel 'financially comfortable' or 'wealthy' in 2025?

New report shines a light on how Americans view wealth today.

SPONSORED How advisors can build for high-net-worth complexity

Orion's Tom Wilson on delivering coordinated, high-touch service in a world where returns alone no longer set you apart.

SPONSORED RILAs bring stability, growth during volatile markets

Barely a decade old, registered index-linked annuities have quickly surged in popularity, thanks to their unique blend of protection and growth potential—an appealing option for investors looking to chart a steadier course through today's choppy market waters, says Myles Lambert, Brighthouse Financial.