Archived Insight | April 25, 2019
As plan fiduciaries, sponsors are ultimately responsible for data protection. That’s true even when day-to-day cybersecurity is delegated to the third-party administrator (TPA) handling benefits administration.
That’s why it’s important for sponsors of plans with outsourced administration to oversee cybersecurity and create an incident response plan.
Thorough oversight of outsourced cybersecurity includes these steps:
It’s also important for plan sponsors with outsourced administration to have an incident-response plan they can follow in the event of an actual data breach.
You'll need an incident response plan even if you've outsourced all of your administration tasks to a TPA. To develop a meaningful incident response plan in this scenario, address all of the following:
Monitoring outsourced cybersecurity gives you confidence that your plan data is being adequately protected.
Creating an incident response plan helps ensure you’ll be prepared to respond if plan data is breached. If you’ve outsourced functions to more than one vendor, having an incident response plan will help avoid finger-pointing among vendors in the event of a breach.
Retirement, Investment, Multiemployer Plans, Public Sector, Corporate, Technology, ATC
Health, Compliance, Multiemployer Plans, Public Sector, Healthcare Industry, Higher Education, Architecture Engineering & Construction, Pharmaceutical, Corporate
Compensation & Careers, Benefits Administration, Communications, Corporate, Retirement, Healthcare Industry, Benefit Audit Solutions, Architecture Engineering & Construction
This page is for informational purposes only and does not constitute legal, tax or investment advice. You are encouraged to discuss the issues raised here with your legal, tax and other advisors before determining how the issues apply to your specific situations.
© 2024 by The Segal Group, Inc.Terms & Conditions Privacy Policy California Residents Sitemap Disclosure of Compensation Required Notices
We use cookies to collect information about how you use segalco.com.
We use this information to make the website work as well as possible and improve our offering to you.