Guidance ‘Counseling’
When the Labor Department issued last month what it called “new guidance” that it further described as “the first time the department’s Employee Benefits Security Administration has issued cybersecurity guidance”—well, I, for one, was expecting… guidance. However, rather than an advisory opinion, information letter or even a field assistance bulletin, it turned out instead to be three documents outlining what were termed “ best practices for maintaining cybersecurity.” The issue of cybersecurity has, of course, loomed large in recent months, reportedly emerging as a focus in Labor Department audits and as a point of contention [i] in participant lawsuits. In fact, even the preamble to the final e-delivery regulations stated a year ago that “…the Department expects that many plan administrators, or their service or investment providers, already have secure systems in place to protect covered individuals’ personal information.” ...