Just a few years ago, cybersecurity still lived mostly in the IT closet. It mattered, of course. But for many funds, it was still discussed in the language of firewalls, passwords, backups, spam filters, and software updates. It was something handled by the technology team, the outside IT provider, or the vendor who was “taking care of it.”
That conversation has changed. In 2026, cybersecurity was thrust into the forefront of the Department of Labor’s Employee Benefits Security Administration’s National Enforcement Projects. That shift sends a clear signal: cybersecurity is now part of the regular governance conversation for ERISA-covered plans.
That does not mean trustees need to become cybersecurity experts. It does not mean administrators need to understand every technical control. And it certainly does not mean funds should panic. But it does mean the conversation has moved.
The focus is no longer simply on whether cybersecurity tools, policies, or vendors exist. The better question is whether the fund has a documented process for overseeing them — and documented verification that the process is actually working.
That is the theme of this issue of CyberSecure Magazine: EBSA’s new National Enforcement Project on cybersecurity, viewed from several different angles.
Our contributors examine several key areas: enforcement, fiduciary responsibility, oversight of service providers, cybersecurity questionnaires, plan data, and practical governance. Collectively, these articles lead to a practical conclusion: effective cybersecurity governance involves more than just having the right tools, vendors, policies, or insurance. It requires understanding how these components interact, asking insightful questions, and maintaining a clear record that demonstrates the fund is actively engaged in cybersecurity efforts.
For trustees and fund professionals, the question is, “How do we know cybersecurity is being handled well across the entire fund ecosystem — our staff, our systems, our partners, and our vendors — and where is that documented?”
That is the purpose of this issue: to help translate EBSA’s cybersecurity enforcement focus into practical conversations fund leaders can have with counsel, administrators, vendors, insurers, and one another.
Cybersecurity may have started in the IT closet. But in 2026, it belongs at the governance table.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.