Pensions - Articles - Best practice for trustees amid sustained cyber pressure


Trafalgar House have set out what effective trustee oversight of cyber resilience should look like, following warnings from the National Cyber Security Centre of sustained national cyber pressure.

 The number of nationally significant attacks has more than doubled in the past year, with high-profile incidents at Marks & Spencer, Harrods and the Co-op showing how damaging breaches can be. Government reports have also highlighted severe resilience gaps across critical national systems, underscoring the urgency for stronger defences.

 Against this backdrop, Trafalgar House warns trustees to remain vigilant and to ensure they are receiving accurate and comprehensive reporting from their administrator. Without this visibility, trustees risk being unable to properly monitor threats or take timely action to protect members’ data and scheme integrity.

 Daniel Taylor, Director at Trafalgar House, said: “Trustees increasingly recognise that cyber resilience is a critical governance responsibility, but it can be difficult to judge what good looks like in practice. One of the most valuable steps they can take is to ask their administrators the right questions. Are defences being tested on a regular basis? Are vulnerabilities identified and resolved quickly? Can recovery procedures be proven and evidenced? Trustees should expect clear reporting on these points, not generic risk scores, so they can be confident that their schemes are protected.”

 “Administrators should be able to demonstrate transparency in their approach, whether that is through continuous threat monitoring, evidence of vulnerabilities being resolved, or the results of recovery testing and staff readiness exercises. These are the practical indicators that give trustees assurance and allow them to hold providers to account. The recent cyberattacks affecting large firms such as Marks & Spencer, Harrods and the Co-op are a powerful reminder of how damaging these incidents can be, not only financially but also in terms of public trust. For trustees, the lesson is clear, cyber resilience must stay high on the agenda, and it starts with demanding the right evidence from your providers.”
  

Back to Index


Similar News to this Story

Hedging comes good as yields fall
Fully hedged scheme sees funding level increase by over 1 full percentage point through February to reach strongest position since 2022. 50% hedged sc
Strong underlying support for auto enrolment reform
Over two in five (43%) business leaders say that the minimum workplace pension auto-enrolment contribution level should rise, with nearly three quarte
Master trusts to prepare for future scale requirements now
TPR sets out principles for how trustees can assess their scheme’s growth potential and prepare for proposed new scale requirements under the Pension

Site Search

Exact   Any  

Latest Actuarial Jobs

Actuarial Login

Email
Password
 Jobseeker    Client
Reminder Logon

APA Sponsors

Actuarial Jobs & News Feeds

Jobs RSS News RSS

WikiActuary

Be the first to contribute to our definitive actuarial reference forum. Built by actuaries for actuaries.