All articles
Five Years After DOL Guidance, Many Benefit Plans Still Have No Security Program
Julie Tracy, principal at Withum's cybersecurity advisory practice, explains why Taft-Hartley funds that outsource every operation to third parties keep treating vendor assessment as optional, and why the long voluntary stretch on the DOL's guidance won't end gently.

Make The Security Digest one of your go-to sources on Google
I'm still running into Taft-Hartley plans, ERISA plans, that don't have any kind of cybersecurity program in place and have never assessed their vendors.
The Department of Labor published its cybersecurity expectations for benefit plans in April 2021, then confirmed in a 2024 release that they cover every ERISA plan, health and welfare included. Five years on, many of the funds holding workers' pensions and medical benefits are still starting from zero. And they hand every operational function to outside vendors.
Julie Tracy is a principal in the cybersecurity advisory practice at Withum, an advisory, tax, and accounting firm whose cyber team handles assessments, pen testing, and third-party risk for benefit funds. She spent twelve years as CISO of an Indiana community bank under full FDIC supervision, holds CISSP and CCSP certifications, and teaches trustees through the International Foundation of Employee Benefit Plans. Since moving from banking to Taft-Hartley work in 2022, the gap between those worlds keeps surprising her. "I'm still running into Taft-Hartley plans, ERISA plans, that don't have any kind of cybersecurity program in place and have never assessed their vendors," Tracy says.
No grace period after the grace period
Banking taught her what enforced looks like. "My first day on the job was literally sitting across from an FDIC examiner, asking me about the information security program at the bank," she says. It shapes how she reads the current stretch of soft enforcement, and she labels the prediction as her own.
"This is your opportunity to get the program you should have in place and implemented. Because there's been such a large voluntary compliance period, there will be no grace period once it becomes effective. That's my opinion; I haven't heard that from the DOL, but I often see it in banking," Tracy says. "I've had an exam thirty days after a regulation became effective. I was expected to have that control in place."
Periodic means annual
The guidance reads closer to baseline practice than to a stringent rulebook, and the sticking point is cadence, not content. "The language in the guidance around vendor assessments says periodic. There was a question asked of the DOL at a conference in 2024, and the DOL emphatically said periodic is annual," she says. Trustees hear something else. "I'm still running into trustees who think, if I just do this once, I've checked the box, I'm done."
Some hear a sales pitch. "Some folks say, well, it's just a way for you guys to make money," Tracy says. Her answer comes from the exam room. "In banking, if we did not assess our vendors every year, that was 100% a finding." The exposure justifies the cadence. Most funds have no staff running anything. "They're relying 100% on third parties for every aspect of the day-to-day operations of the plan. The risk associated with that is enormous, and you have to have your hands around all of your vendors." Only two items on the DOL's list must leave the building: the independent audit of program effectiveness and external pen testing, but few funds can execute the rest in-house.
Written but not executed
Funds that do have programs often have them on paper only. When Withum drafts policies, Tracy sets one rule. "If you can't execute this, we need to not put it in policy. It's worse to have it in policy and not be doing it than to not have it in policy." A documented control nobody runs becomes evidence against the fund after a breach, where the policy-practice gap reads as knowing neglect.
MFA is her recurring example. "We see a lot of instances where it's turned on, but the end user has the ability to say, I don't want to use MFA," she says. Pen testing surfaces the difference fast. "Users are going to take the path of least resistance every single time."
Where a fund with nothing starts
Her on-ramp is deliberately small. A written information security program comes first, the playbook covering the policies the DOL's first item expects. Then a controls walkthrough with the fund's IT provider on the call, where eight-character passwords and daily admin-account use get their reckoning. One client that started with vulnerability scanning four years ago now runs full internal and external pen testing and is adding vendor assessments. "We love seeing how much harder the pen testers have to work to find things," Tracy says.
The newest item in her starter kit predates any DOL requirement. "Even if you're not using AI, you should have a policy that states we are not using it. If you don't have a policy that says you can't use it, I'll guarantee you employees are." She expects the guidance to absorb AI eventually, and the threat side won't wait for the paperwork. "This is not a one-and-done thing," she says. "Ask your vendors how they're using AI, and how they're using it without participant data."






