Cybersecurity enforcement by the Department of Labor’s Employee Benefits Security Administration (EBSA) affects a broad range of plans, as well as plan sponsors, fiduciaries, service providers, and participants. It’s important for these groups to keep up to date with EBSA’s guidance, goals, and the standards by which they seek to ensure compliance with cybersecurity best practices.
EBSA National Enforcement Projects
EBSA signals its priorities by releasing updates to its National Enforcement Projects. EBSA specifies its goal is to focus “enforcement resources where they can have the greatest impact.” National Enforcement Projects are how EBSA allocates these resources.
In January 2026, EBSA introduced cybersecurity as a new project, recognizing the growing risks of cybersecurity threats and signaling its intent to target plans and service providers who are inadequately protecting their systems and data. This assessment is carried out according to the EBSA cybersecurity guidance provided in Compliance Assistance Release No. 2024-01. Cybersecurity was the only new National Enforcement Project in 2026.
EBSA Cybersecurity Guidance
EBSA’s cybersecurity guidance applies to all plans covered under the Employee Retirement Income Security Act of 1974 (“ERISA”). The guidance recommends basic fraud prevention tips to plan beneficiaries and participants, outlines criteria for due diligence when it comes to hiring a service provider and provides cybersecurity program best practices.
EBSA Criteria for Hiring a Cybersecurity Service Provider
EBSA places the responsibility on fiduciaries to properly vet the cybersecurity practices of any outside service providers.
Recommended criteria includes:
EBSA Cybersecurity Best Practices
Walsh v. Alight Solutions, LLC illustrates that EBSA has broad discretion to investigate and enforce cybersecurity standards.
There can be serious consequences for not following EBSA’s guidance on cybersecurity. This is shown in Walsh v. Alight Solutions, LLC, where an EBSA investigation led to the enforcement of an administrative subpoena against Alight Solutions, LLC. 44 F.4th 716 (7th Cir. 2022).
Alight Solutions, LLC provides recordkeeping and administrative services for benefit plans, including ERISA plans. They received sensitive information in performing these services, which they had a duty to protect with robust cybersecurity procedures. EBSA began an investigation into Alight Solutions based on the suspicion that they failed to report unauthorized distributions of plan benefits due to cybersecurity breaches.
Alight Solutions attempted to argue that EBSA’s administrative subpoena was overly broad, requested unrelated documents, and most importantly, was outside of EBSA’s investigative authority and purpose.
These claims were clearly rejected by the court, which upheld that EBSA has broad discretion to investigate matters related to cybersecurity and that broad discretion can extend even to entities or persons that are not fiduciaries to an ERISA plan, so long as such investigation is reasonably relevant to an ERISA plan.
This case upholds that not just fiduciaries, but any entity or person, can be investigated by EBSA. The court emphasizes in Walsh v. Alight Solutions, LLC, “under 29 U.S.C. § 1134(a)(1), the Department has the power to launch investigations ‘in order to determine whether any person has violated or is about to violate any provision of this subchapter or any regulation or order thereunder.’” 44 F.4th at 723. Functionally, this allows EBSA to investigate any entity it deems necessary.
Importantly, this case affirms that EBSA does not need to confirm that ERISA or any related law is being violated in any way in order to investigate. Simply put, "an administrative agency's subpoena power is intended to permit the agency to 'investigate merely on suspicion that the law is being violated, or even just because it wants assurance that it is not.'" 44 F.4th at 716, quoting Chao v. Loc. 743, Int'l Brotherhood of Teamsters, AFL-CIO, 467 F.3d 1014, 1017 (7th Cir. 2006).
Lastly, EBSA focuses here on how cybersecurity procedures tie into the general prudence required when handling ERISA plan information. The court in Walsh states that “the reasonableness of Alight's cybersecurity services, and the extent of any breaches, is therefore relevant to determining whether ERISA has been violated — either by Alight itself, or by the employers that outsourced management of their ERISA plans to Alight.” 44 F.4th at 723. Therefore, this case specifically mirrors EBSA’s national enforcement projects in focusing on how cybersecurity is essential to adequately satisfy ERISA standards.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.