Posts

Showing posts with the label cyber attack

‘Hacking’ Stances

Image
A couple of Saturdays back I discovered that one of my online accounts had been “hacked.”  The good news is that I “discovered” this via transaction emails confirming what appeared to be purchases—a half dozen of them… for various, small-ish (though not small) amounts… all about 4:00 a.m. on a Saturday morning. And trust me, while the pandemic has certainly fueled my online purchases, both the number and the timing were  not  normal behaviors (nor was the Chinese text in those emails). The even better news was that I was able to flag those transactions via the provider—and via my credit card company— almost  immediately (apparently the foreign hackers and I were the only ones awake at that hour). Even though there was no damage done by this incursion (aside from some temporary heartburn), it brought home to me again the importance of protecting  all  of my online accounts. Like many, perhaps most, of you, I have long found managing the sheer v...

Guidance ‘Counseling’

Image
 When the Labor Department issued last month what it called “new guidance” that it further described as “the first time the department’s Employee Benefits Security Administration has issued cybersecurity guidance”—well, I, for one, was expecting… guidance.  However, rather than an advisory opinion, information letter or even a field assistance bulletin, it turned out instead to be three documents outlining what were termed “ best practices  for maintaining cybersecurity.” The issue of cybersecurity has, of course, loomed large in recent months, reportedly emerging as a focus in Labor Department audits  and as a point of contention [i]  in participant lawsuits. In fact, even the preamble to the final e-delivery regulations  stated a year ago that “…the Department expects that many plan administrators, or their service or investment providers, already have secure systems in place to protect covered individuals’ personal information.”  ...

5 Steps to Cyber Security

Image
Recent reports of 401(k) thefts  and an ongoing concern about cybersecurity  (should) have everybody on the alert. Here’s some things you, your plan sponsor clients, and their participants should check out—now. Find Your Account(s) It may have been a while since you checked out your 401(k) balance—indeed, many may not have  ever   checked it out online. Start by tracking down the website, your user id, your password. If you haven’t done so in a while, you may have lost those credentials—or your access may have been disabled. Even if those credentials are still valid, it’s probably a good time to change them. Make sure you remember those account(s) at previous employers’ 401(k)s that you may have left “behind.”  Oh, and it will be less frustrating if you don’t do this on the weekend. In my experience, few offer customer service support then, and if you need help getting on, you’ll need some help. You might also find that it’s a good time to ...