401k cybersecurity incident and how to handle
Viewpoints

Key Action Steps to Take if Your 401(k) Service Provider Has a Cyber Incident

  • Article

A cybersecurity incident at a third-party administrator can quickly disrupt more than system access. Payroll contribution remittances, loan repayments, participant distributions, investment elections and deferral changes may all be affected. While the 401(k) service provider works to restore operations, the plan sponsor remains responsible for overseeing the plan and responding prudently.

That response should begin with clear ownership, disciplined recordkeeping and a plan for reconciling every affected transaction. Contemporaneous documentation can help demonstrate how management evaluated the disruption, protected participant information and resolved plan activity, without having to reconstruct events later. 

Five Actions to Take Immediately

Plan sponsors should take the following five actions immediately following a cybersecurity incident from their 401(k) provider: 

  1. Designate an incident owner and establish a secure, centralized incident file.
  2. Identify upcoming payrolls and participant transactions that could be affected.
  3. Obtain written instructions from the service provider for alternate submission or processing methods.
  4. Begin separate payroll and participant-transaction logs before systems are restored.
  5. Prepare the post-restoration reconciliation plan, including data sources, reviewers and sign-off requirements.

Why Documentation Matters

A third-party outage does not eliminate a plan sponsor's responsibility to oversee plan operations. The United States Department of Labor cybersecurity guidance emphasizes prudent service provider oversight, documented incident response processes and effective business resiliency procedures. The appropriate response will depend on the facts, but a complete incident file can help support fiduciary oversight, audit procedures, correction decisions, participant inquiries, insurance claims and legal or regulatory evaluations.

Assign one person to maintain the file. Preserve original emails, notices, screenshots and files with their dates and metadata. Use secure transmission methods and retain only the personal information needed to administer and substantiate affected transactions.

What Plan Sponsors Should Document and Retain

Communications, Timeline and Internal Decisions

Create one reliable record of what was known, when it was known and how the organization responded, this includes:

  • Service provider notices, alerts, emails, frequently asked questions (FAQs), support tickets, case numbers, call notes and screenshots of outage messages.
  • The date and time of each communication, affected functions, available workarounds, expected follow-up and plan-specific instructions.
Payroll Contributions and Participant Loan Repayments

For each affected payroll, document the normal remittance process and the specific facts surrounding any delay, including:

  • Payroll registers, pay dates, amounts withheld, contribution and loan-repayment files, approval records, bank activity and funding confirmations.
  • The date funds ordinarily would have been transmitted, each unsuccessful attempt, timestamps, error messages and rejected files, and any written alternate instructions.
  • The date funds were ultimately remitted, accepted and allocated, analyzed separately for each payroll.
  • The earliest date amounts reasonably could have been segregated from company assets, whether available processes could have been used and the facts causing any delay.
  • Any lost-earnings calculation, correction analysis, deposit confirmation or Form 5500 reporting evaluation.
Participant Transactions and Temporary Procedures

Track every request that was delayed, rejected, manually processed or otherwise affected, including distributions, loans, hardship withdrawals, investment changes and deferral elections. This data should include:

  • The request date and time, delivery method, requested effective date, amount or election, processing date, status, participant communication and final resolution.
  • Complaints, inquiries, potential market-impact concerns and management responses.
  • Written instructions for any workaround, including permitted transaction types, approvals, identity verification, secure transmission, system access and review controls.
  • An exception log identifying items processed outside normal systems and who prepared, approved and reviewed each item.
Service Provider Controls and Contractual Matters

Review the information available about the service provider and the obligations established in the relationship, including:

  • Relevant system and organization controls (SOC) reports and bridge letters, together with management’s review of incident-specific communications affecting controls over plan administration, recordkeeping or financial reporting.
  • The service provider’s written assessment of whether the incident affected plan administration, recordkeeping, participant access, financial reporting or data.
  • Relevant service agreements, cybersecurity provisions, business-continuity commitments, notification requirements, indemnification terms and cyber insurance notices.
  • Consultations with Employee Retirement Income Security Act (ERISA) counsel, the service provider, payroll provider, investment adviser, auditor, cyber insurer or other specialists.
Restoration, Reconciliation and Correction

Do not close the incident file simply because systems are available again. Confirm all affected activity was processed completely and accurately.

  • Reconcile contributions, loan repayments, cash or suspense activity and participant transactions from the outage period.
  • Compare internal payroll and transaction logs with recordkeeper reports, trust or custodian activity and participant account postings.
  • Test for missing, duplicate, late or incorrectly dated transactions and document how each exception was resolved.
  • Record participant reimbursements, lost earnings, corrective contributions, transaction reversals or other remedial actions.
  • Obtain management review and sign-off, then prepare a final memorandum summarizing the impact, affected population and dollars, corrections, control changes, unresolved matters and conclusions.

Important Distinction

Documenting an outage is not the same as concluding a delay or transaction error is excused. Management should evaluate each affected item under the plan document, ERISA, applicable correction programs and the specific facts. For delayed participant contributions or loan repayments, the analysis should consider the normal remittance process, unsuccessful transmission attempts, available alternate procedures, the earliest date amounts reasonably could have been remitted and whether lost earnings or another correction is required.

The Bottom Line

A well-organized incident file should show a clear progression from notice, to response, to reconciliation. The objective is not simply to accumulate records. It is to demonstrate management identified the risks, acted prudently, protected participant information and corrected affected plan activity as promptly as practicable.

We’re here to support you. Need additional guidance? Contact Doeren Mayhew’s employee benefit plan pros today, we know the way.

Ready to put this brain power to work?

Contact Our Pros

Subscribe for more VIEWPoints