The cybersecurity questionnaire is now standard practice across the Taft-Hartley world. Funds send them to administrators, recordkeepers, custodians, payroll providers, and outside counsel. Responses get filed, summarized in vendor-review meetings, and occasionally cited as evidence of due diligence.
At first glance, the answers look reassuring. Do you have multi-factor authentication? Yes. Do you conduct cybersecurity awareness training? Yes. Do you have an incident response plan? Yes. Do you maintain cyber insurance? Yes. The trouble is that unless the respondent understands the intended depth of the questions, "yes" can mean almost anything.
Consider the simplest example: Do you have multi-factor authentication (MFA)? A vendor who's enabled MFA on three executives' email accounts can honestly answer yes. So can a vendor who's enforced MFA across every employee, every administrative account, ery remote access path, and every externally exposed application. Both check the same box. They're not running the same program.
One organization treats the questionnaire as an "if the answer isn't no, answer yes" exercise. The other reads it as asking whether the control is in place thoroughly, completely, and under active review. Only one produces an answer that holds up under examnation.
The responsibility for answering at the depth the question actually asks rests with the respondent. The responsibility for asking the right questions, evaluating answers with scrutiny, and documenting that process rests with the fund. Under the red-flag principle, it's reasonable to trust a service provider's representations unless something gives you reason not to — a missed deadline, an inconsistent answer, a security incident, a refusal to provide documentation. Any of these shifts the fund's posture from reliance t inquiry.
This is what cybersecurity professionals call security theater: the visible artifacts of a program — policies, training records, deployed tools — without the operational discipline that gives those artifacts meaning. It's not deception; it's what happens when a respondent reads a short question as a short question rather than as the surface of a deeper one.
The same dynamic applies across the questionnaire. Do you have an incident response plan? A vendor with a binder on a shelf can answer yes. So can a vendor whose team has exercised the plan under pressure and refined it from after-action notes. Do you back up your data? A vendor with copies on the same network can answer yes. So can a vendor with isolated, encrypted, regularly tested backup recovery procedures. Same question. Same answer. Vastly different programs.
The questions themseves aren't vague. They only appear that way to a reader who doesn't speak the language they're shorthand for.
The foundation of that language is the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0, released in 2024, which organizes cybersecurity into six functions: Govern, Identify, Protect, Detect, Respond, and Recover. Aligned with it are specialized frameworks for particular sectors: the Cybersecurity Maturity Model Certification (CMMC) for federal contractors, the Financial Industry Regulatory Authority's (FINRA) cybersecurity rules for broker-dealers, Service Organization Control 2 (SOC 2) trust services criteria for service organizations, and EBSA's cybersecurity best practices for ERISA-covered plans. The Center for Internet Security (CIS) Controls v8.1 adds the operational layer — 18 controls broken into 153 specific safeguards, with three Implementation Groups that scale to organizational size and risk profile. These frameworks aren't competitors; they work in tandem, each adding specificity to the layer above it.
When a questionnaire asks, "Do you have multi-factor authentication?", a fluent reader sees the Protect function of NIST CSF 2.0, three CIS Controls v8.1 safeguards (6.3 for externally-exposed applications, 6.4 for remote network access, 6.5 for administrative access), and EBSA's expectation that access controls be documented and reviewed.
A "yes" given without recognizing that underlying stack isn't an answer to the question being asked. It's an answer to a simpler question the respondent imagined. That difference is where exposure lives.
Under ERISA, plan fiduciaries have a duty to act with prudence — a duty that long predates cybersecurity guidance and has always included the selection and ongoing monitoring of service providers. EBSA's 2021 guidance applied that existing duty to cybersecurity, and the 2024 update extended it explicitly to all ERISA-covered plans, covering essentially the entire multi-employer Taft-Hartley universe.
The questionnaire isn't an administrative formality. It's one of the principal ways a fund documents the prudent process it's required to follow. A questionnaire whose responses are accepted at face value leaves the fund without the evidence its own duty of prudence requires.
Prudence doesn't require omniscience. Few trustees, administrators, or counsel will have the time or training to evaluate vendor responses against NIST CSF 2.0, EBSA's Best Practices, and CIS Controls v8.1 on their own. What's expected is that the fund have access to the relevant fluency — and that trustees ensure the right questions are being asked and the documentation supports the fund's position. The cybersecurity questions are technical. The duty to ask them with fiduciary rigor is legal.
If vendor responses can be entirely honest while not answering the real underlying questions, the next question follows naturally: what would our own responses reveal?
When a fund's cyber insurer asks whether MFA is deployed, what does the fund's "yes" actually mean — 6.3, 6.4, 6.5, or just the bank portal? A fund can't reasonably demand of its vendors a discipline it hasn't built internally. The same gap between "having" and "operating and governing" that makes a vendor's response unreliable makes the fund's own posture unreliable in the same way. While many of these topics involve computers and data, they're miles away from work traditionally performed by IT staff.
In January 2026, EBSA elevated cybersecurity to the first-listed priority in its national enforcement projects. Earlier inquiries tended toward, "do you have policies? Current inquiries sound more like: "show us the policies, when were they last reviewed, who approved the exceptions, when was the incident response procedure last tested, and what evidence is there that trustees received reporting?" The distance between those two question sets is the distance between an inventory and a governance process.
The cybersecurity questionnaire is useful only when the requester and respondent speak the same language. Without that fluency, it captures what an organization owns, not what it operates. For most of the past decade, that gap was an inconvenience. As of January 2026, it's a regulatory and fiduciary exposure.
Closing that gap leaves a documentary trail — evidence that a program is operated, not merely owned. The same evidence that satisfies an EBSA investigator also satisfies a plaintiff's lawyer, an insurer's underwriter, and a trustee's own duty of prudence. There's only one record.
The question to ask — of vendors and of the fund itself — is no longer whether the box was checked. It's whether the answer could be defended: by reference to a framework, by evidence of practice, and by the documented governance that turns a control from an artifact into a protection.
A "yes" that can't be defended isn't really a yes at all.

Modern cybersecurity questionnaires draw on an ecosystem of standards. Each layer adds specificity to the one above it.
|
Layer |
What it provides |
|
NIST Cybersecurity Framework 2.0 (2024) |
Strategic foundation. Six functions: Govern, Identify, Protect, Detect, Respond, Recover. |
|
Sector and regulatory frameworks (CMMC, FINRA, SOC 2, EBSA Cybersecurity Best Practices) |
Domain-specific expectations. EBSA’s 2021 guidance, updated 2024, applies to ERISA plans including multi-employer funds. |
|
CIS Controls v8.1 (2024) |
Operational specificity. 18 controls, 153 safeguards, three Implementation Groups. Added “Govern” function aligned to NIST CSF 2.0. |
These layers are not competing standards. They function the way aviation safety standards function — multiple authoritative parties contributing, in tandem, to define what a defensible answer looks like.
What the Short Questions Actually Ask
|
Questionnaire question |
The deeper question behind it |
|
Do you have multi-factor authentication? |
Is MFA required for externally-exposed applications (CIS Safeguard 6.3)? For remote network access (6.4)? For administrative access (6.5)? |
|
Do you back up |
Are backups automated, isolated, encrypted, and regularly tested for recovery? (CIS Control 11) |
|
Do you conduct security awareness training? |
Is training role-specific, ongoing, and verified — including for social engineering recognition? (CIS Control 14) |
|
Do you have an incident response plan? |
Are response roles assigned, procedures documented, and the plan exercised regularly? (CIS Control 17) |
The same five signs are worth applying inward.



The Department of Labor emphasizes the importance of cybersecurity for those responsible for plan-related IT systems and data.
Don't leave your cybersecurity to chance. Ensure best practices with a comprehensive solution tailored for unions.