For years, cybersecurity for a 401(k) worked on an unspoken assumption: the recordkeeper has it handled. Then participant accounts started getting drained by criminals with stolen credentials, lawsuits followed, and in April 2021 the Department of Labor's Employee Benefits Security Administration (EBSA) put the assumption in writing — and reversed it. Protecting plan data and assets, the DOL said, is part of the fiduciary job. Not the vendor's job. Yours.
If you sponsor a retirement plan, or you're the third-party administrator sitting between sponsors and recordkeepers, this guidance is the quiet standard you're being measured against.
What the DOL actually issued
The April 2021 guidance came in three pieces, each aimed at a different audience:
- Tips for Hiring a Service Provider with Strong Cybersecurity Practices — for sponsors and fiduciaries: what to ask recordkeepers, TPAs, and custodians before and after hiring them.
- Cybersecurity Program Best Practices — twelve practices the DOL expects of recordkeepers and every other service provider that touches plan IT systems and data.
- Online Security Tips — for participants themselves: account hygiene, MFA, monitoring for fraud.
Then came the update. In September 2024, EBSA issued Compliance Assistance Release No. 2024-01, and its message was scope: the guidance applies to all ERISA-covered plans — health and welfare plans included — not just retirement plans. Some service providers had argued the 2021 documents were retirement-only; the DOL, prompted by a 2022 recommendation from its ERISA Advisory Council, shut that reading down. As of mid-2026 that framework still stands, and cybersecurity questions now show up inside EBSA plan investigations alongside the traditional fee and document requests.
Why "guidance" still reaches you
None of this is a formal regulation. It doesn't need to be. ERISA's duty of prudence is statute, and the DOL's position is that prudently selecting and monitoring service providers already includes their cybersecurity. The guidance simply spells out what prudent looks like. That has two practical consequences: EBSA investigators use it as their checklist, and plaintiffs' attorneys use it as their yardstick when a participant's account gets emptied. Fiduciary liability is personal — which makes this the rare IT topic that belongs on the owner's desk, not just the administrator's.