A single magenta key beside many dim account tiles on black, cybersecurity questions for 401k technology vendors
Due Diligence • 8 min read

Cybersecurity Questions for 401(k) Technology Vendors

Cybersecurity questions for 401(k) technology vendors start with the DOL's six hiring tips. Since Compliance Assistance Release 2024-01 they cover health and welfare plans too, and EBSA named cybersecurity a FY2026 national enforcement project.

Cybersecurity questions for 401(k) technology vendors start with one document: the Department of Labor's Tips for Hiring a Service Provider with Strong Cybersecurity Practices. It names six things a plan fiduciary is expected to ask a recordkeeper. Since Compliance Assistance Release 2024-01, that expectation covers health and welfare plans too, not just retirement.

I am Amelia S. Gagne, CEO of Kief Studio. This page is about the questions a plan sponsor asks a benefits technology vendor. The general version, for any software purchase, is what to ask your vendors about security. The hybrid-environment version is vendor security questions for mixed data environments.

A single magenta key beside many dim account tiles on black, cybersecurity questions for 401k technology vendors
EBSA named cybersecurity one of its national enforcement projects for fiscal year 2026. Vendor selection is where a fiduciary's file either exists or does not.

Why cybersecurity questions for 401(k) vendors are a fiduciary duty, not IT hygiene

A plan fiduciary owes a duty of prudence in selecting and monitoring service providers. When the service provider holds participant Social Security numbers, balances, and distribution instructions, prudence includes the security of that data. The DOL's position is that this is part of the existing duty, not a new one.

The practical consequence is a paperwork consequence. If you cannot show what you asked and what the vendor answered, you cannot show you were prudent. The questions below exist so the file exists.

Compliance Assistance Release 2024-01, issued September 2024, closed the loophole vendors had been using. Some service providers told fiduciaries and EBSA investigators that the 2021 guidance applied only to retirement plans. The release states it applies to all employee benefit plans, including health and welfare.

What are the six questions the DOL expects you to ask?

These follow the structure of the DOL tips. Ask them in writing. Keep the answers.

  1. What are your security standards, and who audits them against those standards? Ask which framework: SOC 2 Type 2, ISO 27001, NIST. Ask for the report, not the badge.
  2. How have you validated your practices, and can I see the most recent third-party audit? The DOL best practices specifically expect an annual independent audit with documented correction of findings. A report with open findings and no remediation record is a finding of its own.
  3. What is your track record? Past breaches, litigation, and insurance claims involving this service line.
  4. Have you had a breach, and what happened? Ask what changed afterward. The answer to "what did you fix" is more informative than the answer to "were you breached."
  5. What insurance do you carry, and does it cover losses caused by your own people? Cyber liability and fidelity coverage are different products. Internal-actor losses are frequently excluded.
  6. What does the contract actually promise? This is where most files go thin. Specifics below.
Magenta contract lines resolving out of dark paper, contract terms in cybersecurity questions for 401k technology vendors
The DOL tips flag contract provisions as a distinct fiduciary concern. A vendor's marketing security page is not a contractual commitment.

Which contract terms matter for a benefits technology vendor?

Breach notification with a clock. "Promptly" is not a clock. Name the hours, name who gets called, name whether the vendor or the plan notifies participants.

The right to audit, and the right to the audit someone else did. Most small plans will never send an auditor. The useful version is a contractual right to the current SOC 2 report each year.

Cooperation during an incident. Log access, forensic support, and preservation obligations. A vendor that controls the logs controls the story. That gap is the same one described in what happens when you get hacked.

Subcontractors named and constrained. Your recordkeeper's print-and-mail vendor touches participant statements. Their cloud host touches everything. The flow-down question is the sub-processor problem, and it is the term vendors most often leave vague.

Data return and deletion at termination. In a usable format, on a stated timeline, with written confirmation. Owning the stack is the version of this question for the company that runs its own infrastructure.

No limitation of liability that zeroes out the security promises. A cap set at three months of fees means the security clause is decorative.

What should you ask about participant accounts specifically?

Retirement plan fraud is usually account takeover, not a database breach. The attacker logs in as the participant and requests a distribution. So the questions are about the login and the payout, not just the perimeter.

  • Is multi-factor authentication on by default, or is it opt-in? Opt-in MFA on a participant portal is effectively off.
  • What happens on a distribution request from a new device, a new bank account, or after a recent address change? Is there a hold, a callback, an out-of-band confirmation?
  • Who can reset a participant's credentials, and what do they verify first? Call-center identity verification is the soft spot.
  • Does the vendor guarantee restoration of participant losses from unauthorized distributions, and under what conditions? Several large recordkeepers publish a guarantee with conditions attached, such as the participant having registered online and enabled MFA. Read the conditions.
  • Can a participant see their own login history?

Password reuse is the mechanism behind most account takeover. That is why a password manager is a reasonable thing for a plan sponsor to recommend to participants alongside the vendor's own controls.

One magenta doorway lit among identical dark doors, participant account takeover in 401k vendor security
The DOL publishes Online Security Tips aimed at participants directly. Distributing them is cheap and it is documentable.

What the DOL expects of the vendor's own program

The companion document, Cybersecurity Program Best Practices, is written for recordkeepers. You can read it as an answer key. It expects a formal documented program, senior management ownership, annual third-party audits with penetration testing, annual awareness training for all personnel, a secure development lifecycle, encryption in transit and at rest, and independent assessment of anything the vendor has placed with a cloud or third-party provider.

That last item is the one to press on. A recordkeeper running on a major cloud has inherited a shared responsibility boundary, and the questions that boundary raises are the same ones in self-hosted versus cloud. Ask which controls the vendor owns and which they assume their host handles.

How much of this does a 40-person company actually do?

Less than a Fortune 500 plan committee, and that is fine. Prudence is judged against the circumstances. A reasonable small-plan process looks like this:

  1. Send the six questions in writing during selection. Keep the responses.
  2. Get the current SOC 2 Type 2 and read the exceptions section, which is where the useful information is.
  3. Confirm MFA default, distribution controls, and the restoration guarantee's conditions.
  4. Read the four contract terms above. Negotiate notification timing and subcontractor flow-down at minimum.
  5. Put the review on a calendar annually. Monitoring is a continuing duty, not a one-time act.
  6. Distribute the DOL's participant-facing Online Security Tips and record that you did.

Six steps, one folder. The folder is the deliverable. This is the same discipline as due diligence on technology vendors, applied to a context where someone may later ask you to produce it.

One magenta folder lit among dim shelving on black, the documented file a 401k vendor security review produces
Prudence is judged on process, not outcome. An unasked question leaves nothing to show; a documented refusal is still a record.

Where the software supply chain fits

A benefits portal is an application, and applications are assembled from dependencies. kief.dev publishes Vekt, a lockfile scanner, because the dependency file is where a lot of unexamined risk sits. We also keep our package audit tooling public at ks-aur-scanner. If you want the longer version of why that matters, it is your lockfile is a threat surface and software supply chain risk is a people problem.

Brian Gagne handles security architecture at Kief Studio and has for the fourteen years we have worked together. When the question is control design rather than vendor paperwork, briansgagne.com is the deeper read. When the question is who runs the stack day to day, that model is at ltfi.ai.

Related reading

Frequently Asked Questions

What cybersecurity questions should a plan sponsor ask a 401(k) vendor?

Ask the six from the DOL's hiring tips: security standards, third-party validation, track record, breach history, insurance, and contract terms. Then add participant-account questions about default MFA, distribution holds, and the conditions on any restoration guarantee.

Does the DOL cybersecurity guidance apply to health plans?

Yes. Compliance Assistance Release 2024-01, issued September 2024, confirmed the 2021 guidance applies to all ERISA-covered employee benefit plans, including health and welfare plans, not only retirement plans.

Is asking these questions actually required?

The guidance is not a regulation. The underlying duty of prudence in selecting and monitoring service providers is statutory. EBSA has named cybersecurity a fiscal year 2026 national enforcement project, so the practical answer is to build the file.

What if the vendor will not share its SOC 2 report?

Ask for it under NDA, which is normal. If the answer is still no, document the refusal. A refusal is information, and a documented refusal is a better file than an unasked question.

How often should a plan sponsor re-review the vendor?

Annually is the common cadence, matching the vendor's audit cycle. Monitoring is a continuing duty, so a single review at selection does not satisfy it.

Cybersecurity Sep 15, 2026 7 min

Vendor Security Questions for Mixed Data Environments

Vendor security protocol questions for mixed data environments come down to who owns each control across your estate and theirs. CSA added Shared Security Responsibility Model columns to CAIQ v4 because unassigned controls are a leading source of cloud risk.

Operations Sep 17, 2026 8 min

Questions to Ask Vendors About Protecting Proprietary Data

Questions to ask vendors about protecting proprietary data in collaborative scenarios cover ownership, retention, isolation, subcontractors, and model training. IBM's 2026 study found supply chain compromise added about $227,250 above the average breach cost.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe