The board voted to authorize a one-time cybersecurity vendor assessment to evaluate plan vendors’ cybersecurity practices. Patrick Bone, introduced to the board to discuss the proposal, said the Department of Labor has a roughly 12-item set of cybersecurity best practices for vendors and recommended an outside survey. "Our CEO was willing to do it for 7,500, if that's something you guys were interested," Patrick said.
Staff clarified the assessment is a preventative review, not an insurance policy. "This is not insurance. This is a protection before you get to needing insurance," the staff member said, urging the board to consider cyber insurance separately. Trustees agreed to proceed with a single, thorough vendor review now and to decide later whether to repeat the check periodically or after vendor changes. The motion to proceed passed with board assent.