CyberSecure

FOR LOCAL UNIONS

What Cybersecurity Questionnaires Are Actually Asking

 

The cybersecurity questionnaire is now standard practice across the Taft-Hartley world. Funds send them to administrators, recordkeepers, custodians, payroll providers, and outside counsel. Responses get filed, summarized in vendor-review meetings, and occasionally cited as evidence of due diligence.

At first glance, the answers look reassuring. Do you have multi-factor authentication? Yes. Do you conduct cybersecurity awareness training? Yes. Do you have an incident response plan? Yes. Do you maintain cyber insurance? Yes. The trouble is that unless the respondent understands the intended depth of the questions, "yes" can mean almost anything.

The "Yes" That Should Have Been a "No"

Consider the simplest example: Do you have multi-factor authentication (MFA)? A vendor who's enabled MFA on three executives' email accounts can honestly answer yes. So can a vendor who's enforced MFA across every employee, every administrative account, ery remote access path, and every externally exposed application. Both check the same box. They're not running the same program.

One organization treats the questionnaire as an "if the answer isn't no, answer yes" exercise. The other reads it as asking whether the control is in place thoroughly, completely, and under active review. Only one produces an answer that holds up under examnation.

The responsibility for answering at the depth the question actually asks rests with the respondent. The responsibility for asking the right questions, evaluating answers with scrutiny, and documenting that process rests with the fund. Under the red-flag principle, it's reasonable to trust a service provider's representations unless something gives you reason not to — a missed deadline, an inconsistent answer, a security incident, a refusal to provide documentation. Any of these shifts the fund's posture from reliance t inquiry.

This is what cybersecurity professionals call security theater: the visible artifacts of a program — policies, training records, deployed tools — without the operational discipline that gives those artifacts meaning. It's not deception; it's what happens when a respondent reads a short question as a short question rather than as the surface of a deeper one.

The same dynamic applies across the questionnaire. Do you have an incident response plan? A vendor with a binder on a shelf can answer yes. So can a vendor whose team has exercised the plan under pressure and refined it from after-action notes. Do you back up your data? A vendor with copies on the same network can answer yes. So can a vendor with isolated, encrypted, regularly tested backup recovery procedures. Same question. Same answer. Vastly different programs.


Reading the Question

The questions themseves aren't vague. They only appear that way to a reader who doesn't speak the language they're shorthand for.

The foundation of that language is the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0, released in 2024, which organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Aligned with it are specialized frameworks for particular sectors: the Cybersecurity Maturity Model Certification (CMMC) for federal contractors, the Financial Industry Regulatory Authority's (FINRA) cybersecurity rules for broker-dealers, Service Organization Control 2 (SOC 2) trust services criteria for service organizations, and EBSA's cybersecurity best practices for ERISA-covered plans. The Center for Internet Security (CIS) Controls v8.1 adds the operational layer — 18 controls broken into 153 specific safeguards, with three Implementation Groups that scale to organizational size and risk profile. These frameworks aren't competitors; they work in tandem, each adding specificity to the layer above it.

When a questionnaire asks, "Do you have multi-factor authentication?", a fluent reader sees the Protect function of NIST CSF 2.0, three CIS Controls v8.1 safeguards (6.3 for externally-exposed applications, 6.4 for remote network access, 6.5 for administrative access), and EBSA's expectation that access controls be documented and reviewed.
A "yes" given without recognizing that underlying stack isn't an answer to the question being asked. It's an answer to a simpler question the respondent imagined. That difference is where exposure lives.


Are You Asking the Fiduciary Question?

Under ERISA, plan fiduciaries have a duty to act with prudence — a duty that long predates cybersecurity guidance and has always included the selection and ongoing monitoring of service providers. EBSA's 2021 guidance applied that existing duty to cybersecurity, and the 2024 update extended it explicitly to all ERISA-covered plans, covering essentially the entire multi-employer Taft-Hartley universe.

The questionnaire isn't an administrative formality. It's one of the principal ways a fund documents the prudent process it's required to follow. A questionnaire whose responses are accepted at face value leaves the fund without the evidence its own duty of prudence requires.

Prudence doesn't require omniscience. Few trustees, administrators, or counsel will have the time or training to evaluate vendor responses against NIST CSF 2.0, EBSA's Best Practices, and CIS Controls v8.1 on their own. What's expected is that the fund have access to the relevant fluency — and that trustees ensure the right questions are being asked and the documentation supports the fund's position. The cybersecurity questions are technical. The duty to ask them with fiduciary rigor is legal.

What About the Fund Itself?

If vendor responses can be entirely honest while not answering the real underlying questions, the next question follows naturally: what would our own responses reveal?

When a fund's cyber insurer asks whether MFA is deployed, what does the fund's "yes" actually mean — 6.3, 6.4, 6.5, or just the bank portal? A fund can't reasonably demand of its vendors a discipline it hasn't built internally. The same gap between "having" and "operating and governing" that makes a vendor's response unreliable makes the fund's own posture unreliable in the same way. While many of these topics involve computers and data, they're miles away from work traditionally performed by IT staff.

Why Does This Matter Now?

In January 2026, EBSA elevated cybersecurity to the first-listed priority in its national enforcement projects. Earlier inquiries tended toward, "do you have policies? Current inquiries sound more like: "show us the policies, when were they last reviewed, who approved the exceptions, when was the incident response procedure last tested, and what evidence is there that trustees received reporting?" The distance between those two question sets is the distance between an inventory and a governance process.

Are You Defending the Answer?

The cybersecurity questionnaire is useful only when the requester and respondent speak the same language. Without that fluency, it captures what an organization owns, not what it operates. For most of the past decade, that gap was an inconvenience. As of January 2026, it's a regulatory and fiduciary exposure.

Closing that gap leaves a documentary trail — evidence that a program is operated, not merely owned. The same evidence that satisfies an EBSA investigator also satisfies a plaintiff's lawyer, an insurer's underwriter, and a trustee's own duty of prudence. There's only one record.

The question to ask — of vendors and of the fund itself — is no longer whether the box was checked. It's whether the answer could be defended: by reference to a framework, by evidence of practice, and by the documented governance that turns a control from an artifact into a protection.

A "yes" that can't be defended isn't really a yes at all.


The Framework Stack

Modern cybersecurity questionnaires draw on an ecosystem of standards. Each layer adds specificity to the one above it.

Layer

What it provides

NIST Cybersecurity Framework 2.0 (2024)

Strategic foundation. Six functions: Govern, Identify, Protect, Detect, Respond, Recover.

Sector and regulatory frameworks (CMMC, FINRA, SOC 2, EBSA Cybersecurity Best Practices)

Domain-specific expectations. EBSA’s 2021 guidance, updated 2024, applies to ERISA plans including multi-employer funds.

CIS Controls v8.1 (2024)

Operational specificity. 18 controls, 153 safeguards, three Implementation Groups. Added “Govern” function aligned to NIST CSF 2.0.

 These layers are not competing standards. They function the way aviation safety standards function — multiple authoritative parties contributing, in tandem, to define what a defensible answer looks like.

When “Yes” Isn’t a Yes 

What the Short Questions Actually Ask

Questionnaire

question

The deeper question behind it

Do you have multi-factor authentication?

Is MFA required for externally-exposed applications (CIS Safeguard 6.3)? For remote network access (6.4)? For administrative access (6.5)?

Do you back up
your data?

Are backups automated, isolated, encrypted, and regularly tested for recovery? (CIS Control 11)

Do you conduct security awareness training?

Is training role-specific, ongoing, and verified — including for social engineering recognition? (CIS Control 14)

Do you have an incident response plan?

Are response roles assigned, procedures documented, and the plan exercised regularly? (CIS Control 17)


Five Signs a Vendor Questionnaire Response May Be Mostly Theater

  • Responses are uniformly affirmative with no caveats, exceptions, or “in progress” entries.
  • The vendor cannot map its program to a named framework (CIS Controls, NIST CSF, ISO 27001).
  • Policies referenced in the response have not been reviewed or updated in over a year.
  • Cybersecurity training is reported as “annual completion” with no mention of phishing simulation or role-specific content.
  • The vendor reports an incident response plan but cannot describe when it was last tested.

The same five signs are worth applying inward.


Questions Trustees and Counsel Should Ask This Quarter

  • When was our incident response plan last tested, and what did the test reveal?
  • How are privileged and dormant accounts reviewed and removed?
  • Which vendors currently have access to fund systems or participant data, and when were their cybersecurity postures last assessed?
  • How are cybersecurity exceptions documented and approved?
  • What cybersecurity reporting reaches the trustee package, and at what frequency?
  • What framework do we name in our own documentation — and does our practice match it?
  • What evidence could we produce if EBSA requested it next month?

Evidence of Governance — What Investigators Often Want to See

  • Board and committee meeting minutes referencing cybersecurity oversight
  • Cybersecurity policy review records with dates and approvers
  • Vendor risk assessments mapped to a defined framework
  • Access review documentation, including dormant account removal logs
  • Incident response procedures and exercise records
  • Cybersecurity awareness training participation records, including phishing simulation results
  • Exception approvals and remediation tracking
  • Reporting provided to trustees, summarized and dated

 

Let’s build something better - together.

The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.

Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.

Thank you for your inquiry. Your submission request has been received.
Onsite Logic