Fiduciary duty has always required trustees to monitor their service providers. But the Employee Benefits Security Administration’s (EBSA) January 2026 enforcement recalibration clarifies that "monitoring" now means something far more specific — and far more demanding. Cybersecurity has been elevated to a named, top-tier enforcement priority, and the agency's existing guidance gives investigators a precise framework for evaluating whether funds are asking the right questions of the vendors, custodians, and administrators they trust with participant data and plan assets. Most funds are not asking those questions. And most service providers are counting on that.
Annually, the United States Department of Labor (DOL) publishes its “national enforcement projects,” revealing EBSA’s focus in a potential investigation of an employee benefit plan.
There are many different national enforcement projects. This year, cybersecurity is at the top of the list.
In its description of the 2026 cybersecurity national enforcement project, EBSA stated “as part of its investigations, EBSA reviews how plans and service providers protect their systems and data from cyber threats. This project builds on cybersecurity guidance issued in 2021 and updated in 2024.”
With cybersecurity now listed on the national enforcement project, plan fiduciaries are called on to prove compliance with existing EBSA cybersecurity guidance. If plan fiduciaries have yet to develop a cybersecurity framework, it’s crucial to begin immediately. Review of a cybersecurity framework includes policies and procedures governing staff and fiduciary training, incident response, participant data protections, and access controls.
For in-house administrator offices, there’s an extra layer of compliance, because the persons staffing these offices are likely plan employees. Fiduciaries maintaining plan data in these offices should ensure that their internal environments have protections that comply with the EBSA guidance.
Plan fiduciaries should assemble a group of individuals vested with the authority to oversee compliance with the EBSA guidance. This could be a committee, a task force, or an independent third party. How it looks matters less than its function. This group can take on policy drafting and development, perform third-party service provider oversight, define breach notification timelines, control requirements and independent assessments. The group should continuously review and assess the plan’s cybersecurity program and confirm that the plan’s service providers have sufficient contract provisions to demonstrate compliance with the EBSA guidance. Plan service providers like Fund Counsel, Fund Auditor, and third-party administrator are strong resources for compliance assistance.
It's ill-advised for a board of trustees to rely solely on its third-party administrator as a security blanket to prove DOL cybersecurity compliance. Trustees of Taft-Hartley plans are plan service providers, and they must demonstrate an understanding of the importance of compliance and illustrate adequate processes that show cybersecurity risk mitigation is a high priority.
Now that cybersecurity is DOL priority national enforcement project, it’s important for plan fiduciaries to understand how this became so important for EBSA.

Since April 2021, the DOL has articulated an ERISA fiduciary duty to mitigate the risk of harm a cybersecurity breach might cause to a plan and plan participants. This is distinguished from the inaccurate statement that there is an ERISA fiduciary duty to prevent any cybersecurity breach. There is a struggle distinguishing between the ideas that plan fiduciaries must act in a way to prevent a cybersecurity breach from ever happening and how a plan can address corrective actions after a cybersecurity breach has happened. As these ideas competed over the years, it became clear that it’s not a question of whether a cybersecurity breach will happen but rather when it will happen. Accordingly, the discussions between ERISA industry experts focused largely on damage remediation after a breach. In 2021, the DOL issued three pieces of sub-regulatory guidance.
The 2021 EBSA guidance focused on “best practices for maintaining cybersecurity.” It came in three forms: Tips for Hiring a Service Provider, Cybersecurity Program Best Practices, and Online Security Tips. According to then-EBSA Acting Secretary Ali Khawar,
“the cybersecurity guidance we issued today is an important step towards helping plan sponsors, fiduciaries, and participants to safeguard retirement benefits and personal information. …”
The use of the word “retirement” created confusion as to whether the guidance applied to welfare plans. EBSA resolved the confusion by issuing Compliance Assistance Release No. 2024-01 to clarify that the guidance applies to retirement and welfare plans.
“Today’s Compliance Assistance Release provides an important clarification for plan sponsors and fiduciaries, confirming that our guidance on cybersecurity applies to all plans covered by the Employee Retirement Income Security Act,” explained Assistant Secretary for Employee Benefits Security Lisa M. Gomez. “All ERISA covered-plans need to implement appropriate best practices to help protect participants and their beneficiaries from cybercrime and emerging threats. These updates remind plan sponsors and fiduciaries of the critical importance of safeguarding job-based benefits and personal information.”
Between 2021 and 2026, EBSA often investigated a plan’s cybersecurity risk mitigation framework as if it had been a national enforcement project. It’s likely the inclusion of cybersecurity risk mitigation to the list of DOL national enforcement projects will further magnify EBSA’s focus on a plan’s cybersecurity policies and procedures.
The importance of cybersecurity risk mitigation cannot be overemphasized. The plan’s exposure is not limited to financial holdings but also to participant information. Cyber-thieves use sensitive participant information to accomplish their tasks. Incidents of participant data theft have raised the question whether participant data are “plan assets.” The answer turns on the plan fiduciaries’ duties with respect to protecting participant information.
In the United States Code of Federal Regulations (29 CFR 2510.3-101), the DOL’s definition of plan assets comes in the context of plan investments. In Harmon v. Shell Oil, the U.S. District Court in the Southern District of Texas cited this regulation to conclude that participant data is not a plan asset. The issue in Harmon v. Shell Oil was that the retirement plan’s recordkeeper used plan participant data to market non-plan financial products. The Harmon court, however, admonished plan fiduciaries to monitor plan service providers to ensure that plan participant data is used appropriately.
In another case involving the use of plan participant data by a third-party plan service provider, Divane v. Northwestern University, the U.S. District ruled that participant data is not a plan asset even though it has "some value." Although no court has ruled that participant data are considered plan assets, there is likely going to be more litigation on the question. There is no guarantee a court won’t conclude that the “value” of participant data elevates it to “plan asset” status. Plan fiduciaries are wise to keep plan participant data in mind when developing and improving cybersecurity risk mitigation.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.