Guest comment: Being cyber prepared

Cybersecurity and the protection of member data has shot right to the top of trustee risk registers.

Many trustees will have had detailed training leading up to the introduction of GDPR in May 2018 and will have been through a wholesale review of their contracts, policies and procedures.

There is a risk that some of the training may be a little rusty. In particular, I find myself pushing trustees to re-run their response training so they are on the front foot when a breach occurs. And unfortunately, it is ‘when’, not ‘if ’.

Attacks always seem to happen on a Friday evening, there is never enough information and it is stressful.

A simple plan helps navigate first interactions, gives structure to the discussions and increases the chances of making good decisions over whether ICO notification is needed within the 72-hour deadline.

This includes confirming facts such as who is impacted, implementing the response plan, establishing who needs to know what and determining remediation.

The plan should also make sure that the increased focus on member data doesn’t obscure other priorities such as running payroll, member transactions and good governance.

Any real-life threat along these lines will be difficult to deal with, but training and a robust response plan will give structure and help to alleviate stress

    Share Story:

Recent Stories


Being retirement ready
Gavin Lewis, Head of UK and Ireland Institutional at BlackRock, talks to Francesca Fabrizi about the BlackRock 2024 UK Read on Retirement report, 'Ready or not. How are we feeling about retirement?’

Time for CDI
Laura Blows speaks to AXA Investment Managers (AXA IM) senior portfolio manager for fixed income, Rob Price, about cashflow-driven investing (CDI) in Pensions Age’s latest video interview

The role of CDC
In the latest Pensions Age podcast, Laura Blows speaks to TPT Retirement Solutions Chief Client Strategy Officer, Andy O’Regan, about the role of collective DC (CDC) within the UK pensions space
Keeping on track
In the latest Pensions Age podcast, Sophie Smith talks to Pensions Dashboards Programme (PDP) principal, Chris Curry, about the latest pensions dashboards developments, and the work still needed to stay on track

Advertisement