Guest comment: Being cyber prepared

Cybersecurity and the protection of member data has shot right to the top of trustee risk registers.

Many trustees will have had detailed training leading up to the introduction of GDPR in May 2018 and will have been through a wholesale review of their contracts, policies and procedures.

There is a risk that some of the training may be a little rusty. In particular, I find myself pushing trustees to re-run their response training so they are on the front foot when a breach occurs. And unfortunately, it is ‘when’, not ‘if ’.

Attacks always seem to happen on a Friday evening, there is never enough information and it is stressful.

A simple plan helps navigate first interactions, gives structure to the discussions and increases the chances of making good decisions over whether ICO notification is needed within the 72-hour deadline.

This includes confirming facts such as who is impacted, implementing the response plan, establishing who needs to know what and determining remediation.

The plan should also make sure that the increased focus on member data doesn’t obscure other priorities such as running payroll, member transactions and good governance.

Any real-life threat along these lines will be difficult to deal with, but training and a robust response plan will give structure and help to alleviate stress

    Share Story:

Recent Stories


Closing the gender pension gap
Laura Blows discusses the gender pension gap with Scottish Widows head of workplace strategic relationships, Jill Henderson, in our latest Pensions Age video interview

Endgames and LDI: Lessons to be learnt
At the PLSA Annual Conference, Laura Blows spoke to State Street Global Advisors EMEA head of LDI, Jeremy Rideau, about DB endgames and LDI in the wake of the gilts crisis of two years ago

Keeping on track
In the latest Pensions Age podcast, Sophie Smith talks to Pensions Dashboards Programme (PDP) principal, Chris Curry, about the latest pensions dashboards developments, and the work still needed to stay on track
Building investments in a DC world
In the latest Pensions Age podcast, Sophie Smith talks to USS Investment Management’s head of investment product management, Naomi Clark, about the USS’ DC investments and its journey into private markets

Advertisement