Introduction
All UK pension schemes should now be operating an “effective system of governance”, including a policy on cyber security measures taken to protect the scheme and its members from cyber criminals.
We asked Armstrong Watson’s Cyber Security Solutions Manager, Rebecca Wilson, to share some thoughts on the risks faced by pension schemes and what trustees can do to mitigate those risks.
Are pension schemes an easy target?
Pension schemes are increasingly a target of cyber criminals. Over the past 12 months, cyber-attacks on UK pension schemes have skyrocketed by more than 4,000%, making this sector the hardest hit within financial services and highlighting the urgent need for robust cyber security measures.
As digital threats grow, cyber security is now an issue that trustees cannot afford to overlook. Not only do trustees hold responsibility for safeguarding scheme assets, but also for protecting the personal data of scheme members.
Schemes hold large amounts of sensitive personal data such as bank details, dates of birth and National Insurance numbers. This combination makes them attractive to fraudsters who may attempt to redirect payments, steal identities, or extort administrators through ransomware attacks. A cyber incident could cause serious financial and reputational harm.
What should trustees be doing to address the risks?
The Pensions Regulator (TPR) has made it clear that trustees are expected to treat cyber security as a key risk as a failure to plan adequately exposes members to financial loss. Cyber resilience is now part of trustees’ fiduciary duty.
Many schemes rely on third-party administrators and service providers, and while this brings expertise, it can also introduce risks if contracts do not set clear expectations for cyber security. Other vulnerabilities include weak password controls, poor email practices, and a lack of trustee security awareness training on how to recognise and respond to attacks.
While trustees do not need to be cyber experts, they should be able to demonstrate active oversight. Good practice includes:
- Asking administrators about their cyber policies, testing and incident response plans.
- Reviewing contracts to ensure service providers are held to clear security standards.
- Ensuring the scheme has a business continuity plan that covers cyber incidents.
- Undertaking trustee training to build awareness and confidence in responding to risks.
- Having a clear process for member communications if a breach occurs.
Cyber security is not just an IT issue, it is a governance responsibility and therefore should be discussed and managed at board level.
Trustees who ask the right questions, set clear expectations of service providers, and plan for incidents are better placed to protect members and demonstrate strong stewardship of the scheme.
Next steps
At your next trustee meeting, consider making cyber security a standing agenda item. Even small steps can make a significant difference to resilience and member confidence.
Armstrong Watson Cyber Security Solutions can provide trusted advice and guidance. Contact help@armstrongwatson.co.uk with any cyber security queries, or visit www.armstrongwatson.co.uk/services/cyber-security-solutions to learn more.
Back