Pensions - Articles - Best practice for trustees amid sustained cyber pressure


Trafalgar House have set out what effective trustee oversight of cyber resilience should look like, following warnings from the National Cyber Security Centre of sustained national cyber pressure.

 The number of nationally significant attacks has more than doubled in the past year, with high-profile incidents at Marks & Spencer, Harrods and the Co-op showing how damaging breaches can be. Government reports have also highlighted severe resilience gaps across critical national systems, underscoring the urgency for stronger defences.

 Against this backdrop, Trafalgar House warns trustees to remain vigilant and to ensure they are receiving accurate and comprehensive reporting from their administrator. Without this visibility, trustees risk being unable to properly monitor threats or take timely action to protect members’ data and scheme integrity.

 Daniel Taylor, Director at Trafalgar House, said: “Trustees increasingly recognise that cyber resilience is a critical governance responsibility, but it can be difficult to judge what good looks like in practice. One of the most valuable steps they can take is to ask their administrators the right questions. Are defences being tested on a regular basis? Are vulnerabilities identified and resolved quickly? Can recovery procedures be proven and evidenced? Trustees should expect clear reporting on these points, not generic risk scores, so they can be confident that their schemes are protected.”

 “Administrators should be able to demonstrate transparency in their approach, whether that is through continuous threat monitoring, evidence of vulnerabilities being resolved, or the results of recovery testing and staff readiness exercises. These are the practical indicators that give trustees assurance and allow them to hold providers to account. The recent cyberattacks affecting large firms such as Marks & Spencer, Harrods and the Co-op are a powerful reminder of how damaging these incidents can be, not only financially but also in terms of public trust. For trustees, the lesson is clear, cyber resilience must stay high on the agenda, and it starts with demanding the right evidence from your providers.”
  

Back to Index


Similar News to this Story

Technical guidance to support Vote Reporting Template users
Pensions UK has today published new technical guidance to support users of the Vote Reporting Template. Launched in March 2025 in collaboration with t
Firms should not be forced to signpost Targeted Support
In time, firms should signpost targeted support as an option. But not before more widely available. And customers need to understand the limited situa
Stocks look to start week strong despite risk of US shutdown
US and European equity market futures up at the start of the week, as Asia stocks rise. Market buoyancy is despite risk of US government funding runni

Site Search

Exact   Any  

Latest Actuarial Jobs

Actuarial Login

Email
Password
 Jobseeker    Client
Reminder Logon

APA Sponsors

Actuarial Jobs & News Feeds

Jobs RSS News RSS

WikiActuary

Be the first to contribute to our definitive actuarial reference forum. Built by actuaries for actuaries.