On September 6, 2024, the U.S. Department of Labor (DOL) issued Compliance Assistance Release No. 2024-01, titled “Cybersecurity Guidance Update.” The updated guidance clarifies that the DOL cybersecurity guidance applies to all ERISA-covered plans, and not just retirement plans, but also health and welfare plans. Also, as a direct response to service providers’


Cybersecurity has become an integral concern for employers and employee benefit plans alike. With an increase in DOL cybersecurity audits, plan fiduciaries are looking to strengthen their cybersecurity practices more than ever before. What specific risks are plans facing? Who is responsible for keeping plans safe, and what legal duties do they have? What steps