Articles | August 25, 2026

Cybersecurity Has Become a Fiduciary Governance Obligation

For years, cybersecurity within public pension systems was viewed primarily as a technical matter — important, but largely delegated to IT staff and vendors. Trustees were briefed occasionally, often after a system upgrade or audit, but cyber risk rarely featured prominently in board-level governance discussions. Given the rise of increasingly costly cyberattacks, that paradigm no longer holds.

Cybersecurity Has Become a Fiduciary Governance Obligation

Today, public pension organizations are prime cyber targets, and their systems hold vast quantities of personally identifiable information (PII), banking data and benefit records for millions of active members and retirees. Cyber incidents now carry consequences that extend well beyond technical disruption. They create fiduciary exposure, reputational risk, benefit-continuity threats and erosion of member trust — all squarely within the oversight responsibilities of pension boards.

The evolution of cyber risk from an operational concern to a fiduciary one is not theoretical. It is already playing out across the public pension landscape.

Why cyber risk has moved to the boardroom

That urgency is increasing as artificial intelligence (AI) and automation lower the time, skill and marginal cost required for malicious actors to launch phishing, credential-harvesting, social-engineering and reconnaissance campaigns at scale. In this environment, no organization should assume it is “too small” or too specialized to be targeted. Attackers can probe many organizations cheaply and repeatedly, making weak or informal control environments increasingly difficult to defend as prudent governance.

Recent multi-state cyber incidents have demonstrated how quickly pension systems can be impacted — even when internal controls are sound. For example, the MOVEit file-transfer vulnerability affected multiple public pension systems after attackers exploited weaknesses at a commonly used third-party vendor. In several cases, the breach did not originate within the pension system itself, yet sensitive participant data was still exposed.

The lesson was not simply that third-party risk is real. It was that accountability does not stop at the vendor boundary.

The same lesson applies beyond any single vendor event. When attacks are cheaper to generate and easier to personalize, pension systems should expect more frequent probing of both internal operations and third-party dependencies.

The practical governance implication is that cybersecurity can no longer be treated as a periodic exercise in IT vigilance. It must be managed as an ongoing enterprise-risk discipline, with layered controls, defined accountability and regular reporting to the board.

Industry associations, such as NCPERS, have increasingly emphasized that cyber incidents now escalate into board-level events, requiring trustee awareness, decision-making and oversight. Cyber risk has joined investment risk, funding risk and operational risk as a core governance issue for public retirement systems.

8 questions trustees should be asking about board governance of cybersecurity

  1. How is cybersecurity risk reflected in our enterprise risk-management framework?
  2. What cyber incidents or near misses has the system experienced, and how were they handled?
  3. What information does the board receive about incidents, near misses and emerging threats?
  4. How are third-party vendors evaluated, monitored and held accountable for cybersecurity risks?
  5. Do we have a clear, board-approved, incident response and communications plan?
  6. How do cybersecurity assessments inform our cyber insurance coverage decisions?
  7. Are we receiving the right information to fulfill oversight responsibilities?
  8. Who has decision-making authority during the first 24–72 hours of a cyber incident?

Cyber incidents threaten benefit continuity as well as data

One reason cybersecurity has become a fiduciary concern is its direct connection to benefit continuity. Modern public pension systems depend on highly interconnected digital ecosystems that include payroll interfaces, banking platforms, document management systems, call centers and member self‑service portals. A ransomware attack or prolonged system outage can disrupt contribution processing, delay benefit payments or impair communication with members at critical moments.

For trustees, the implications are clear: cyber risk is no longer just about privacy. It is about the pension system’s ability to meet its core mission to pay benefits accurately and on time even under adverse conditions.

This reality has pushed boards to rethink how cyber preparedness fits into their broader operational resilience and disaster recovery strategies.

Federal guidance reinforces fiduciary expectations

This shift is reinforced by federal guidance. The U.S. Department of Labor (DOL) has made clear — particularly in its cybersecurity best-practice guidance for retirement plans — that fiduciaries have an obligation to mitigate cybersecurity risks associated with plan data, systems and service providers.

Although public pension plans are not subject to ERISA, the DOL’s framing is influential. It articulates a governance standard that resonates strongly in the public sector: trustees are expected to act prudently, monitor service providers and ensure appropriate safeguards are in place to protect plan assets and participant information.

Boards may not manage firewalls, encryption keys or endpoint tools, but they are responsible for ensuring that cybersecurity is governed through a prudent process: risk assessment, documented policies, vendor oversight, incident response planning, business continuity, independent review and regular board-level reporting.

From IT controls to trustee oversight

Importantly, none of this requires trustees to become cybersecurity experts. It requires a shift in focus, from technical controls to governance oversight.

That oversight should include an expectation that management and service providers maintain a defense-in-depth control environment that consists of multiple, overlapping administrative, technical, physical and third-party controls designed so that no single control failure creates unacceptable exposure. Mature programs typically align those controls to one or more recognized frameworks, such as the NIST Cybersecurity Framework, DOL Cybersecurity Best Practices, CIS Controls and ISO 27001. The board’s role is to ask whether the framework is appropriate, implementation is evidenced, gaps are tracked and remediation is timely.

Increasingly, incident-response planning is recognized as a governance-proven deliverable, not just a technical playbook. Clear escalation paths, defined roles and communication protocols protect systems and public confidence in the institution.

The hidden exposure of third-party vendors

Third-party risk remains one of the most challenging aspects of cybersecurity governance. Public pension systems rely on a broad range of vendors, including recordkeepers, software providers, payroll processors, custodians, consultants and file-transfer services. A vulnerability at any point in that chain can expose the entire system. As attacker automation improves, weak vendors, legacy file-transfer processes, stale access rights and poorly tested incident-response obligations become more attractive paths of least resistance.

Trustees approve vendor contracts, risk tolerances, and oversight frameworks. Increasingly, boards are being asked to consider whether vendor governance practices adequately reflect the sensitivity and scale of pension data.

Cyber liability insurance: A necessary governance discussion

As cyber incidents become increasingly foreseeable, boards are also being called upon to consider cyber liability insurance as part of a prudent fiduciary risk-management strategy.

Cyber liability insurance cannot prevent breaches, and it should never be treated as a substitute for layered controls, vendor oversight, tested incident response or board-level governance. However, when paired with a mature control environment, it can play a critical role in financial resilience and response readiness, helping cover costs associated with forensic investigations, legal counsel, member notification, credit monitoring, system restoration and regulatory response. In complex incidents — particularly those involving third-party vendors — those costs can escalate quickly.

From a fiduciary perspective, the key issue is whether coverage levels, exclusions and response services align with the system’s risk profile, data footprint and operational dependencies. Cyber insurance decisions are increasingly informed by objective risk assessments, including the size of the member population, the volume of sensitive data held and the system’s reliance on external service providers.

Independent cybersecurity assessments support fiduciary oversight

Boards increasingly rely on independent cybersecurity compliance audits to inform both governance decisions and insurance strategies. These assessments provide an objective view of how well a system’s policies, controls, vendor oversight and incident-response capabilities align with recognized standards. In a higher-frequency threat environment, periodic independent assessment also helps boards distinguish between the existence of controls on paper and the operational sufficiency of those controls in practice.

Cybersecurity as fiduciary stewardship

Cybersecurity is no longer about eliminating all risk, which is an unrealistic goal in today’s threat environment. Instead, it is about demonstrating prudent governance, preparedness and accountability. For public pension boards, this aligns naturally with their fiduciary mission: protecting member assets, ensuring continuity of promised benefits and preserving trust in the institution. Cyber risk now sits alongside investment risk and funding policy as a core component of fiduciary stewardship.

The question for trustees is whether governance structures have evolved to reflect the reality that cyber incidents are foreseeable, increasingly frequent and potentially mission-disruptive — and that cybersecurity oversight is now part of fiduciary stewardship.

Cybersecurity assessments and informed cyber liability insurance decisions enable boards to demonstrate prudent fiduciary oversight — understanding exposure, implementing reasonable safeguards and preparing for the financial and operational realities of a cyber event.

Interested in strengthening your system’s cybersecurity oversight?

We can help. 

Contact Us

Our Administration and Technology Consulting (ATC) Practice has extensive experience conducting cybersecurity assessments aligned with the NIST Cybersecurity Framework, Department of Labor Cybersecurity Best Practices, HIPAA security standards and third-party vendor-risk evaluations. These reviews go beyond technical testing to evaluate governance structures, roles and responsibilities, policy maturity and readiness to respond when incidents occur.

Our Insurance Brokerage Practice helps systems evaluate cyber liability insurance as part of a broader enterprise risk strategy recognizing that insurance is most effective when integrated with governance and preparedness, not treated as a standalone solution. Segal brokers assist in assessing coverage options, understanding policy terms and ensuring access to specialized cyber response resources.

See all of our insights on cybersecurity.

See more insights

Two Colleagues Using Laptop To Work Project At Office

A Structured Approach to AI Implementation Ensures Success

A structured approach to AI implementation helps organizations move from experimentation to real value through strategy, training and execution.
Young Businesswoman Analyzing Data On Laptop In Modern Office

Seeking Better Benefits Engagement? Use AI Strategically

Learn how blending human empathy, smart design and AI can improve employee benefits engagement and make benefits easier to find and use.
Two Businesspeople Working Together On A Laptop In The Office

Why Oversight of Vendors’ AI Use Is a Governance Essential

When vendors add AI features, risk profiles can shift quietly. Learn how structured oversight makes vendor AI use visible and governable.

This page is for informational purposes only and does not constitute legal, tax or investment advice. You are encouraged to discuss the issues raised here with your legal, tax and other advisors before determining how the issues apply to your specific situations.