Compliance
15 min read

When Your 401(k) Recordkeeper Goes Dark: A Fiduciary's Cyber Incident Playbook

A cyberattack on your recordkeeper is not an IT problem you outsourced — it is a monitoring problem you own. Concrete steps for plan fiduciaries before, during, and after a cybersecurity event at a plan service provider.

In July 2026 a recordkeeping platform serving retirement plans was taken offline by a cyberattack. Access for sponsors and participants was limited or unavailable for weeks, and in places months. The plan assets themselves were reported unaffected — which is real and important, and also cold comfort to a participant who cannot process a hardship withdrawal, or to a plan sponsor whose payroll contribution file will not transmit.

The initial vector, as reported, was mundane: an employee downloaded a malicious file while trying to install a legitimate tool. That detail is worth sitting with. The scenarios that take a recordkeeper offline are rarely exotic, which means the odds of one happening to a platform you use are not remote.

This guide covers what a plan fiduciary should do before, during, and after a cybersecurity event at a plan service provider. It is written for the sponsor who has just learned their recordkeeper is down and is trying to work out what is now their problem.

The Duty You Cannot Outsource

Start here, because everything else follows from it. You hired a recordkeeper to run the plan's operations. You did not, and could not, transfer your fiduciary duty to them.

ERISA requires a fiduciary to act prudently in selecting service providers and to monitor them on an ongoing basis. A vendor failure is precisely the moment that monitoring duty becomes visible. The Department of Labor's position is straightforward: a third-party outage does not suspend the plan sponsor's responsibility to oversee plan operations.

In practice this means that when your recordkeeper goes dark, a set of obligations that were being handled quietly on your behalf land back on your desk — and several of them carry deadlines that do not move.

The DOL's Cybersecurity Guidance

The DOL issued cybersecurity guidance in April 2021 and confirmed in Compliance Assistance Release No. 2024-01 (September 6, 2024) that it applies to all plans governed by ERISA, including health and welfare plans. It comes in three parts:

  • Tips for Hiring a Service Provider with Strong Cybersecurity Practices — for selecting and monitoring vendors.
  • Cybersecurity Program Best Practices — for fiduciaries and third-party administrators managing the risk itself.
  • Online Security Tips — written for participants, and worth distributing to yours.

This guidance is the standard your conduct will be measured against. It is short. Read it before you need it.

Before: The Work That Only Counts If You Do It Early

Almost everything that determines how badly an outage hurts is decided before the outage happens. Six things are worth doing now.

1. Ask the questions the DOL tells you to ask

The Tips document is explicit about what to raise with a provider: any past security breaches and what came of them; their information security standards, practices, policies and audit results; how they validate those practices; and whether they carry insurance covering cybersecurity losses and breaches. Ask at hire, and ask again at review.

2. Read the SOC report properly

Most recordkeepers will hand you a SOC 1 or SOC 2 Type 2 report. The section sponsors skip is the one that matters most to them: the complementary user entity controls. That is the list of things the auditor assumed you would be doing. If you are not doing them, the report's clean opinion does not cover you. Check the exceptions listed too, not just the opinion letter.

3. Know what your contract actually promises

Before an incident, pull the service agreement and find four things: the business continuity and disaster recovery commitments, including any stated recovery time; the breach notification window and what triggers it; the cyber liability insurance the provider carries; and the indemnification terms. Many sponsors discover during an outage that their agreement promises far less than they assumed.

4. Keep an offline copy of your own data

This is the cheapest insurance available and almost nobody does it. Quarterly, export and store outside the recordkeeper's system: your participant census, account balances by participant, outstanding loan balances and amortisation schedules, beneficiary designations, and deferral elections. If the platform is unreachable, this file is the difference between managing an outage and being blind for its duration.

5. Write down the manual fallback

How does payroll data reach the recordkeeper today — SFTP, an integration, a portal upload? What is the alternative if that path is gone? Who at the provider do you call, and who is the backup when the contact centre is closed? A one-page runbook, written while calm, is worth more than any amount of improvisation later.

6. Document the review in your minutes

The cybersecurity review is a fiduciary act, and an undocumented fiduciary act is difficult to defend. Your committee minutes should show that you asked about the provider's security practices, considered the answers, and made a decision. That record is the artifact a regulator or plaintiff's counsel will ask for.

During: The First Week

When an incident starts, the instinct is to wait for the provider. Waiting is not a fiduciary act. Five things should happen immediately.

  1. Name an owner and open a dated file. One person accountable, one secure, centralised place where every notice, email, support ticket, and call note goes with a date and timestamp. This file is the deliverable.
  2. Identify every affected transaction. Upcoming payrolls, in-flight distributions, loan requests, hardship withdrawals, required minimum distributions, QDROs, investment election changes, and enrollments. You cannot manage what you have not listed.
  3. Get written instructions from the provider. Not a phone call. Ask in writing what is affected, what the alternate processing method is, and what they need from you. Their written answer protects both of you.
  4. Start parallel logs now. A payroll log and a participant transaction log, maintained by you, from the moment systems go down. Reconstructing this later from memory is close to impossible.
  5. Write the reconciliation plan before you need it. Which data source is authoritative, who reviews, who approves. Decide this while the facts are fresh rather than during the scramble to restore.

The Three Deadlines That Do Not Pause

This is the part sponsors most often get wrong. A vendor outage is an excellent explanation and a poor defence. Three obligations keep running.

Depositing participant contributions

Money withheld from an employee's pay becomes a plan asset as of the earliest date it can reasonably be segregated from the employer's general assets (29 CFR 2510.3-102). Plans with fewer than 100 participants at the start of the plan year have an optional seven-business-day safe harbor. The often-quoted “15th business day of the following month” is an outer limit, and the DOL has consistently said it is not a safe harbor.

None of that changes because your recordkeeper cannot accept the file. If you can segregate the money, segregate it — move it out of general assets and into the plan trust even if it cannot yet be allocated to individual accounts. Log the date you did. Late deferrals are a prohibited transaction, and the correction runs through the DOL's Voluntary Fiduciary Correction Program with lost earnings owed to participants.

The blackout notice

If participants lose the ability to direct or diversify their accounts for more than three consecutive business days, that is a blackout period under 29 CFR 2520.101-3, and it does not stop being one because it was unplanned.

The general rule is 30 days advance notice, which is obviously impossible here. The regulation anticipates that: the advance-notice requirement does not apply where the inability to give it is “due to events that were unforeseeable or circumstances beyond the reasonable control of the plan administrator.” That relieves the timing, not the notice. You must still furnish it as soon as reasonably possible, and the notice itself must state that federal law generally requires 30 days advance notice and explain why 30 days could not be given.

As a matter of practice rather than law, document the determination that the exception applied, and the date you reached it.

Loan repayments and the cure period

If payroll-deducted loan repayments cannot be posted, participants' loans can drift toward deemed distribution under Internal Revenue Code section 72(p) — a taxable event for the participant caused by an administrative failure that was not theirs. The cure period under Treasury Regulation 1.72(p)-1 runs to the last day of the calendar quarter following the quarter in which the payment was due. Track the affected loans and the quarter-end dates explicitly; this deadline arrives quietly.

A note on 404(c). Section 404(c) relief depends on participants having the opportunity to give investment instructions. During a window where they demonstrably could not, do not assume that protection is available to you. Assume the opposite and document what you did to shorten the window.

Communicating With Participants

Participants will hear about this whether or not you tell them, and silence from the plan sponsor is read as indifference. Communicate early, in writing, and repeatedly, even when the update is that there is no update.

Cover four things:

  • What is affected and what is not — specifically, whether their balances are safe.
  • What they cannot currently do, and what to do if they have an urgent need.
  • What you are doing about it, and when they will next hear from you.
  • A phishing warning. Criminals follow breach headlines with convincing emails and calls about the exact incident. Tell participants how you will and will not contact them, and that you will never ask for credentials.

Keep a log of participants who report an out-of-pocket loss or a missed transaction. That list drives your correction work later, and its absence is conspicuous.

After: Reconciliation, Correction, and the Record

When systems come back, the work is not over — it changes shape. Restoration is when errors surface.

  • Reconcile against your own logs, not the provider's restored data alone. Contributions, loan repayments, distributions and elections, transaction by transaction, against the parallel record you kept.
  • Price the delay. Participants who were out of the market, or whose contributions posted late, may be owed lost earnings. Late deferrals go through VFCP; operational failures generally correct through the IRS's EPCRS. Neither is self-executing.
  • Confirm the notices. Blackout notice furnished and retained. Any state data-breach notification obligations met — those run on their own clocks and are frequently missed in the focus on plan mechanics.
  • Tell the auditor early. If your plan files as a large plan, your auditor will need the provider's SOC 1 report covering the incident period, and may need to expand testing. Surprising them in month nine helps nobody.

Re-Underwriting the Vendor

The final fiduciary act is the hardest, because it is a judgment rather than a task: was this provider's response adequate, and do you keep them?

The honest answer is often yes. Incidents happen to competent organisations, a strong response can be evidence of a well-run firm, and moving recordkeepers is disruptive and expensive. But the decision has to be made, on the record, against real criteria: how quickly they told you, how candid they were, whether they met their own continuity commitments, whether they made participants whole, and what has changed since.

Document the decision either way. A fiduciary who considered the question and reasonably decided to stay stands on very different ground from one who never asked. And use the renewal to fix what the incident exposed — notification windows, recovery time commitments, indemnification, and insurance.

This is also the moment to check the other half of the value equation. If you are reassessing whether a provider is worth keeping, you should know what you are paying them, and whether that number is competitive for the service you actually receive. Reasonableness is a comparison, and a provider relationship under review is exactly when to run one.

The File the DOL Would Ask For

If this ends in an examination or a claim, the question will not be whether the incident happened. It will be what you did. Four categories of document answer it:

  • Communications and timeline — provider notices, emails, support tickets and call notes, dated and timestamped.
  • Contributions and loan repayments — payroll registers, transmission dates, error messages, and funding confirmations.
  • Participant transactions — requests with their dates, statuses, and how each was resolved.
  • Provider contracts and assurances — the service agreement, SOC reports, business continuity commitments, and cyber insurance.

Taken together, that file should show that you identified the risks, acted prudently, protected participant information, and corrected affected plan activity as promptly as practicable. That is the standard. It is achievable, but only if the documentation starts on day one rather than being assembled afterwards.

The Uncomfortable Summary

A cyberattack on your recordkeeper is not an IT problem you outsourced. It is a monitoring problem you own. The plan assets may well be safe, as they were in the 2026 incident — and your participants may still be harmed, your deadlines may still be missed, and your file may still be empty.

The sponsors who come through these events well are not the ones with the best vendors. They are the ones who asked the questions early, kept their own copy of their own data, and started writing things down on the first day.

Reviewing a provider relationship?

If an incident has you reassessing your recordkeeper, fees are half the picture. Run a free benchmark to see what you are paying against what comparable plans pay — and keep the report for your fiduciary file.

Run a Free Fee Benchmark →

Free, no credit card. Takes about five minutes.

Frequently Asked Questions

Is a cybersecurity incident at my 401(k) recordkeeper a fiduciary breach by me?
Not on its own. A provider being attacked is not itself evidence that the plan sponsor failed. What creates exposure is the conduct around it: whether you selected and monitored the provider prudently, whether you responded reasonably once you knew, and whether you can show it. The Department of Labor's position is that a third-party outage does not suspend your responsibility to oversee plan operations, so the question a regulator asks is not whether the incident happened but what you did about it and whether you documented it.
Do I still have to deposit participant deferrals on time if the recordkeeper cannot accept them?
Yes. Under 29 CFR 2510.3-102, amounts withheld from pay become plan assets as of the earliest date they can reasonably be segregated from the employer's general assets, and plans with fewer than 100 participants have an optional seven-business-day safe harbor. The commonly cited fifteenth business day of the following month is an outer limit, not a safe harbor. A vendor outage does not extend these. Where you can, segregate the funds into the plan trust even if they cannot yet be allocated to individual accounts, and record the date. Late deferrals are a prohibited transaction and are corrected through the DOL's Voluntary Fiduciary Correction Program, with lost earnings owed to participants.
Does a recordkeeper outage trigger a blackout notice?
It can. Under 29 CFR 2520.101-3, a blackout period is any period of more than three consecutive business days during which participants' ability to direct or diversify their accounts is suspended, limited, or restricted. An unplanned outage that meets that description is a blackout. The usual 30-day advance notice requirement does not apply where the inability to give advance notice is due to events that were unforeseeable or circumstances beyond the reasonable control of the plan administrator, but the notice itself is still required as soon as reasonably possible, and it must state that federal law generally requires 30 days notice and explain why that was not possible.
What happens to participant loan repayments during an outage?
If payroll-deducted repayments cannot be posted, affected loans can move toward deemed distribution under Internal Revenue Code section 72(p), which creates a taxable event for a participant through no fault of their own. Treasury Regulation 1.72(p)-1 permits a cure period running to the last day of the calendar quarter following the quarter in which the required payment was due. As a practical matter, identify affected loans immediately and calendar the relevant quarter-end dates, because this deadline tends to arrive without prompting.
Can I rely on ERISA 404(c) protection during a period when participants could not trade?
You should not assume so. Section 404(c) relief is premised on participants having the opportunity to give investment instructions over their accounts. During a window in which they demonstrably could not, the basis for that relief is weak. The prudent posture is to assume 404(c) is unavailable for the affected period, take reasonable steps to shorten it, and document both the steps and the reasoning.
What should I ask my recordkeeper about cybersecurity before an incident?
The DOL's Tips for Hiring a Service Provider with Strong Cybersecurity Practices sets out the core questions: whether the provider has experienced past security breaches and what resulted; what its information security standards, practices, policies and audit results are; how it validates those practices; and whether it carries insurance covering cybersecurity losses and breaches. Beyond that, obtain the SOC 1 or SOC 2 Type 2 report and read the complementary user entity controls, which describe what the auditor assumed you would be doing on your side, along with any exceptions noted.
Should I change recordkeepers after a cyber incident?
Frequently the answer is no, and that can be the correct fiduciary decision. Incidents occur at well-run organisations, and a candid, competent response is itself evidence of operational quality, while a conversion is disruptive and costly. What matters is that the question is actually asked and answered on the record, against criteria such as how quickly and openly you were told, whether the provider met its own business continuity commitments, whether participants were made whole, and what has changed since. A fiduciary who considered the question and reasonably decided to stay is in a far stronger position than one who never considered it.
How long should I keep the documentation from a provider cyber incident?
Treat it as part of the plan's fiduciary record rather than as incident correspondence. ERISA section 107 requires records supporting plan filings to be retained for at least six years, and fiduciary decision records are conventionally kept longer because a claim can arrive years later. In practice, retain the incident file, the reconciliation, the notices furnished, and the committee minutes recording your decisions for the life of the plan relationship and at least six years beyond it.

Ready to benchmark your plan's fees?

Create a free account and run your first fee benchmark in under 10 minutes. No credit card required.

This article is for informational purposes only and does not constitute legal, investment, or fiduciary advice. Consult qualified ERISA counsel for advice specific to your plan. Full ERISA Disclaimer →