If your retirement plan provider’s systems went dark tomorrow and stayed offline for weeks, would you know how contributions, participant transactions, and fiduciary responsibilities would be handled?
This is not a hypothetical exercise. It is a real-world disruption affecting plan sponsors and participants right now. For more than two weeks, a cybersecurity incident has disrupted the retirement plan operations of a major retirement plan services provider. As of July 27, its benefits platform remains offline, and the incident remains under investigation. The provider says account balances and plan benefits have not been affected, but participants cannot view account information, change investments or beneficiaries, or request loans and distributions. Plan sponsors cannot submit payroll contribution files, and service representatives cannot access account information or process transactions. The provider has not yet determined whether any data was accessed.
The dynamics of this incident bring to light an important realization, a cyber incident does not need to result in stolen assets or participant data to materially disrupt a retirement plan. When a critical provider becomes unavailable, plan operations can stop. The fiduciary question quickly broadens from “Was data taken?” to “Can the plan continue operating, can participants access their money, and who bears the consequences if it cannot?”