Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

U.K. Pensions Regulator updates cyber-risk guidance

U.K. pension trustees should be vigilant about cybersecurity and report significant events, The Pensions Regulator said in updated guidance released Dec. 11.

“Pension schemes are at risk of being targeted by cyber-attacks because of the large amounts of personal data and assets they hold,” TPR said in a release, saying the guidance will help trustees and plan managers as well as suppliers and advisers.

The latest guidance calls on trustees and providers to report significant cyber incidents to help it build a better picture of cyber-risks faced by the pension industry. Louise Davey, interim director of regulatory policy, analysis and advice for TPR, said in the release that the evolving nature of cyber-risk “requires a dynamic response. It’s a very real threat as we have seen from events this year.”

Trustees and providers do not need to fully investigate incidents before reporting to TPR, but reporting does not replace existing legal requirements to report data breaches to the Information Commissioner’s Office, TPR said. Trustees are legally required to report breaches that are likely to be of material significance, including from a cyber incident, if it impedes core transactions such as benefit payments.

Simon Kew, head of market engagement at independent consultancy Broadstone, welcomed TPR taking a proactive role, as cyberattacks increase. “Collaborating as an industry through actions like reporting on threats and attacks can help drive us towards a secure future that protects the pensions of members,” Kew said in an emailed statement.

 

 

Read more @pionline