Learn why cybersecurity now belongs in the boardroom and what public pension trustees should be asking about governance.
Primary sources. Practical insight. Every weekday.
A publication of The Inner Firm
Cybersecurity & Plan Data
Learn why cybersecurity now belongs in the boardroom and what public pension trustees should be asking about governance.
A May cyberattack on DentaQuest, the dental and vision benefits administrator serving 32 million Americans, compromised the health data of at least 15 million individuals, the largest health data breach reported to federal regulators this year. Plan sponsors whose group plans use DentaQuest should be reviewing their business associate agreements and notification obligations.
The security press take from late July: the ShinyHunters extortion group claimed responsibility for the May intrusion, stealing 234 GB of data after ransom negotiations failed, with files dating back to 2009 and a final assessment above 23.4 million people, well past the 15 million in initial reports.
Experts say participants, recordkeepers and plan sponsors share responsibilities in making participants whole after experiencing a loss.
Bessemer System Federal Credit Union sued TruStage Financial Group days after a cybersecurity incident forced TruStage, which serves 93% of U.S. credit unions, to shut down its systems and lock members out of 401(k) plans. The suit is an early test of whether institutional clients can hold a vendor liable for cybersecurity failures based on operational disruption alone, without proof that data was actually stolen.
Ari Sonneberg and Barry Salkin propose a federal insurance backstop for defined contribution plan cybersecurity losses, building on the DOL's January 2026 enforcement policy naming cybersecurity and data protection as its highest priority. A thought piece, but a timely one given plan sponsors' growing exposure to participant account theft.
In its January 2026 statement of enforcement policy, the Department of Labor (“DOL”) indicated that cybersecurity and data protection were its highest priority.
Tom Hawkins explains the logic behind Retirement Clearinghouse’s newly updated missing participant policy template