Trustees warned of cyber gaps as dashboard deadline nears
Image: Ebru DOĞAN/Pexels
Pardon the Interruption
This article is just an example of the content available to mallowstreet members.
On average over 150 pieces of new content are published from across the industry per month on mallowstreet. Members get access to the latest developments, industry views and a range of in-depth research.
All the content on mallowstreet is accredited for CPD by the PMI and is available to trustees for free.
Third-party cyber risk is a top concern for defined benefit trustees, but fewer than half regularly test their incident response plans. The new findings come ahead of a deadline for connecting to the pensions dashboard infrastructure by the end of this month.
A survey of 50 professional trustees of DB pension schemes by Howden Retirement concluded that 70% consider third-party or administrator vulnerability among the biggest cyber risks facing schemes. Half also cited the protection and security of member data.
Most schemes are acting on these concerns it appears, with seven in 10 saying they regularly assess third-party or administrator cyber risk and 60% having board-level reporting and assigned responsibilities for cyber incidents.
However, the survey also suggests that as the deadline for connecting to pensions dashboards nears, there are still gaps in cyber security and readiness. Just 44% of schemes regularly test their incident response plans through simulations, despite 38% of trustees saying that incident response and recovery capabilities are a notable cyber risk concern.
While more than three-quarters (78%) of survey respondents said they are on track to meet the dashboards deadline, one in six (16%) admitted they might struggle.
“As schemes approach the pensions dashboard deadline, the preparation involved will inevitably shine a light on where vulnerabilities are still present, and cybersecurity is clearly one of these areas," said Alex Pocock, managing director at Howden Retirement.
“Trustees need confidence that both their own scheme and the providers they rely on are ready to respond when something goes wrong. This will be particularly more vital as protecting member data and minimising disruption comes into sharper focus ahead of the pensions dashboard deadline," he added.
Has your scheme updated its cyber security plan ahead of 31 October?