New findings from Howden Retirement reveal a degree of concern among Defined Benefit (DB) trustees around their schemes’ vulnerability to cyber risks, particularly from third-parties.
The research, The Retirement Runway, which surveyed 50 professional trustees of DB pension schemes, found that reliance on third-parties is creating challenges for security. Nearly seven in ten trustees (70%) say third-party or administrator vulnerabilities are among the biggest cyber risks facing schemes, while half (50%) also highlight the protection and security of member data.
While many schemes have cyber controls in place, preparedness remains uneven. Seven in ten (70%) regularly assess third-party or administrator cyber risk and 60% have board-level reporting and clear responsibilities for cyber incidents. However, fewer than half (44%) of schemes regularly test their incident response plans through simulations, despite well over a third (38%) of trustees saying that incident response and recovery capabilities are a notable cyber risk concern.
Cybersecurity is an integral requirement of the Pensions Dashboard programme, which relies on members to adhere to strict data protection procedures – with the data highlighting many trustees still have open concerns.. While more than three-quarters (78%) of trustees say they are on track to meet the 2026 Pensions Dashboard deadline, one in six (16%) warn they may struggle to do so.
Alex Pocock, Managing Director, Howden Retirement, said: “As schemes approach the Pensions Dashboard deadline, the preparation involved will inevitably shine a light on where vulnerabilities are still present, and cybersecurity is clearly one of these areas,
“While third-party cyber risk is already being regularly assessed by trustees, it still stands out as one of their greatest concerns. This is perhaps understandable given schemes are relying on external providers for increasingly critical parts of their operations.
“Ultimately, cyber resilience is about more than spotting where the risks sit. Trustees need confidence that both their own scheme and the providers they rely on are ready to respond when something goes wrong. This will be particularly more vital as protecting member data and minimising disruption comes into sharper focus ahead of the Pensions Dashboard deadline.”
|