Third party vulnerability is among the biggest cyber risks facing DB pension schemes, according to professional trustee survey

Administrators are causing sleepless nights for defined benefit (DB) trustees. Seven in ten DB trustees believe that third party or administrator vulnerability is among the biggest cyber risks facing pension schemes.

Trustees are doing many things right. Seven in ten regularly assess third party or administrator cyber risk and 60% have board level, clearly designated responsibilities for cyber incidents.

However, the research revealed that trustees may not be fully prepared for a cyberattack. Fewer than half (44%) regularly test their incident response plans through simulations.

Alex Pocock, managing director of Howden Retirement, which conducted the Retirement Runway research among 50 professional trustees of DB schemes said: “As schemes approach the Pensions Dashboard deadline, the preparation involved will inevitably shine a light on where vulnerabilities are still present, and cybersecurity is clearly one of these areas.

“While third-party cyber risk is already being regularly assessed by trustees, it still stands out as one of their greatest concerns. This is perhaps understandable given schemes are relying on external providers for increasingly critical parts of their operations.”

Pocock finished: “Ultimately, cyber resilience is about more than spotting where the risks sit. Trustees need confidence that both their own scheme and the providers they rely on are ready to respond when something goes wrong. This will be particularly more vital as protecting member data and minimising disruption comes into sharper focus ahead of the Pensions Dashboard deadline.”