Capita have to keep the trustees updated in relation to cyber incidents27 Apr 2023 02:10
The latest on the Capita cyber incident: what does it mean for pension schemes?
By Burges Salmon LLP - 26th April 2023
What does this mean for pension schemes?
We are aware that the Pensions Regulator (tPR) is writing to pension schemes who have Capita as their administrator, asking the trustees of those schemes to provide tPR with information on what steps they have taken to ensure that their obligations as data controller have been met in order to protect members’ data.
In these communications, tPR reiterates the importance of having robust cyber security and business continuity policies in place, highlighting their guidance on cyber security principles, as well as the Information Commissioner’s Office’s guidance on IT security.
Many schemes have Capita as their administrator, and trustees might be wondering what the next steps are in terms of how they can gain assurance that the data processed by their pension administrator is secure, while ensuring that members’ interests are protected. We would recommend that, to the extent they have not already done so, trustees who are affected contact their advisers as soon as possible, invoke their incident response plans and check their administration contracts to see what (if any) contractual obligations Capita have to keep the trustees updated in relation to cyber incidents.
This incident highlights the gravity of cybercrime, and the hard-hitting reality that schemes need to be prepared for “when”, rather than “if” a cyber incident occurs, as has been the mantra of tPR for some time now. It is particularly interesting to see tPR taking such a proactive approach to contacting trustees about what steps they are taking – underlining the priority that tPR is giving to cyber security for pension schemes.
Whether or not Capita is their scheme’s administrator, trustees need to be asking themselves this: if our scheme’s administrator was affected, would we be in a position to give the response that tPR would want to hear?
Read the full free article here below.
https://www.lexology.com/library/detail.aspx?g=146119a1-89e3-464e-b127-511c0fcea45c