CyberSecure

FOR LOCAL UNIONS

The Future of EBSA Cybersecurity Enforcement for Benefit Plans

 

Cybersecurity enforcement by the Department of Labor’s Employee Benefits Security Administration (EBSA) affects a broad range of plans, as well as plan sponsors, fiduciaries, service providers, and participants. It’s important for these groups to keep up to date with EBSA’s guidance, goals, and the standards by which they seek to ensure compliance with cybersecurity best practices.

EBSA National Enforcement Projects
EBSA signals its priorities by releasing updates to its National Enforcement Projects. EBSA specifies its goal is to focus “enforcement resources where they can have the greatest impact.” National Enforcement Projects are how EBSA allocates these resources. 

 In January 2026, EBSA introduced cybersecurity as a new project, recognizing the growing risks of cybersecurity threats and signaling its intent to target plans and service providers who are inadequately protecting their systems and data. This assessment is carried out according to the EBSA cybersecurity guidance provided in Compliance Assistance Release No. 2024-01. Cybersecurity was the only new National Enforcement Project in 2026.

EBSA Cybersecurity Guidance
EBSA’s cybersecurity guidance applies to all plans covered under the Employee Retirement Income Security Act of 1974 (“ERISA”). The guidance recommends basic fraud prevention tips to plan beneficiaries and participants, outlines criteria for due diligence when it comes to hiring a service provider and provides cybersecurity program best practices.


EBSA Criteria for Hiring a Cybersecurity Service Provider 

EBSA places the responsibility on fiduciaries to properly vet the cybersecurity practices of any outside service providers. 

Recommended criteria includes: 

  • Review a potential service provider’s information security standards, practices and policies, and audit results. Compare them to industry standards.
  • Review how a service provider validates and checks its practices.
  • Evaluate the service provider's track record in the industry.
  • Ask whether the service provider has experienced past security breaches, what happened, and how the service provider responded.
  • Find out if the service provider has any insurance policies that would cover losses caused by cybersecurity and identity theft breaches.
  • Create a robust services agreement that includes provisions related to information security reporting, confidentiality and information sharing, cybersecurity breaches, records retention and destruction, and insurance. 

EBSA Cybersecurity Best Practices

  • Have a formal, well-documented cybersecurity program.
  • Conduct prudent annual risk assessments.
  • Have a reliable annual third-party audit of security controls.
  • Clearly define and assign information security roles and responsibilities.
  • Have strong access control procedures.
  • Ensure that any assets or data stored in a cloud or managed by a third-party service provider are subject to appropriate security reviews and independent security assessments.
  • Conduct periodic cybersecurity awareness training.
  • Implement and manage a secure system development life cycle (SDLC) program.
  • Have an effective business resiliency program addressing business continuity, disaster recovery, and incident response.
  • Encrypt sensitive data, stored and in transit.
  • Implement strong technical controls in accordance with best security practices.
  • Appropriately respond to any past cybersecurity incidents.

Walsh v. Alight Solutions, LLC illustrates that EBSA has broad discretion to investigate and enforce cybersecurity standards.

There can be serious consequences for not following EBSA’s guidance on cybersecurity. This is shown in Walsh v. Alight Solutions, LLC, where an EBSA investigation led to the enforcement of an administrative subpoena against Alight Solutions, LLC. 44 F.4th 716 (7th Cir. 2022). 

Alight Solutions, LLC provides recordkeeping and administrative services for benefit plans, including ERISA plans. They received sensitive information in performing these services, which they had a duty to protect with robust cybersecurity procedures. EBSA began an investigation into Alight Solutions based on the suspicion that they failed to report unauthorized distributions of plan benefits due to cybersecurity breaches.

Alight Solutions attempted to argue that EBSA’s administrative subpoena was overly broad, requested unrelated documents, and most importantly, was outside of EBSA’s investigative authority and purpose. 


 

These claims were clearly rejected by the court, which upheld that EBSA has broad discretion to investigate matters related to cybersecurity and that broad discretion can extend even to entities or persons that are not fiduciaries to an ERISA plan, so long as such investigation is reasonably relevant to an ERISA plan.


 

This case upholds that not just fiduciaries, but any entity or person, can be investigated by EBSA. The court emphasizes in Walsh v. Alight Solutions, LLC, “under 29 U.S.C. § 1134(a)(1), the Department has the power to launch investigations ‘in order to determine whether any person has violated or is about to violate any provision of this subchapter or any regulation or order thereunder.’” 44 F.4th at 723. Functionally, this allows EBSA to investigate any entity it deems necessary.

Importantly, this case affirms that EBSA does not need to confirm that ERISA or any related law is being violated in any way in order to investigate. Simply put, "an administrative agency's subpoena power is intended to permit the agency to 'investigate merely on suspicion that the law is being violated, or even just because it wants assurance that it is not.'" 44 F.4th at 716, quoting Chao v. Loc. 743, Int'l Brotherhood of Teamsters, AFL-CIO, 467 F.3d 1014, 1017 (7th Cir. 2006). 

Lastly, EBSA focuses here on how cybersecurity procedures tie into the general prudence required when handling ERISA plan information. The court in Walsh states that “the reasonableness of Alight's cybersecurity services, and the extent of any breaches, is therefore relevant to determining whether ERISA has been violated — either by Alight itself, or by the employers that outsourced management of their ERISA plans to Alight.” 44 F.4th at 723. Therefore, this case specifically mirrors EBSA’s national enforcement projects in focusing on how cybersecurity is essential to adequately satisfy ERISA standards.

 

 

 

 

Let’s build something better - together.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.

Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.

Thank you for your inquiry. Your submission request has been received.
Onsite Logic