Cyber Prudence™ for Union Funds
When the DOL asks what your prudent process was, you should have it in hand.
Protecting Union Interests

Protecting Plan Assets and Participant Data

Fund offices are entrusted with participant data that deserves the highest level of protection. For plan fiduciaries, meeting EBSA’s expectations is not an IT preference — it is part of the duty of prudence. Cyber Prudence™ turns that duty into a documented process, and the documented process into something the Board can show.

Why Prudent Process Matters Now

On April 14, 2026, the DOL’s Employee Benefits Security Administration issued Field Assistance Bulletin 2026-01. Two points deserve every trustee’s attention.

“ERISA is a law of process and not results.”

When an enforcement action is based solely on prudence, EBSA says it must avoid cases that unfairly second-guess process-based fiduciary judgments.

EBSA also established investigation timeframes: routine matters should be completed within 18 months and more complex investigations within 30 months, absent exceptional circumstances.

No one accepts an unpaid, honorary trustee seat expecting to spend as long as two and a half years answering investigators, coordinating with counsel, and explaining the fund’s decisions to the members who elected them.

The time to assemble evidence of prudence is before that clock starts. A Proof of Prudence gives the Board a documented record of what it considered, decided, implemented, and independently verified.

Read Field Assistance Bulletin 2026-01

The DOL’s Twelve, Covered

The Department of Labor publishes twelve best practices. That is the checklist. Cyber Prudence™ is the process that produces them — and the record that proves it. Each one below maps to the layer that covers it, and to the document it leaves behind.

  • Why it matters: This is the first thing anyone asks for — an examiner, an auditor, a fiduciary liability carrier. Without a written program, every good thing the Fund already does is undocumented. And undocumented work is indistinguishable from work that never happened.
  • What Cyber Prudence does: Cyber Prudence™ builds and maintains the written program itself: the policies, procedures and plans that say what the Fund does, who owns it, and how often it gets reviewed. The Board approves it. We keep it current.
  • Your evidence: The written program, with version history and the date the Board last reviewed it.

  • Why it matters: You cannot govern what you have never measured. The annual assessment is what turns “we think we’re fine” into a ranked list the Board can act on — and a baseline you can show improvement against next year.
  • What Cyber Prudence does: We run the annual assessment, score it, and bring the Board a prioritized list of what needs attention. Not a technical report. A decision document.
  • Your evidence: The scored annual assessment, and the year-over-year comparison showing what moved.

  • Why it matters: A safeguard you checked yourself is a claim. A safeguard someone independent checked is proof. That distinction is the entire reason this practice exists.
  • What Cyber Prudence does: We do not perform this one — and that is the point. A provider auditing its own work is not independent. We help the Board select a qualified third-party auditor, assemble the evidence package they will ask for, sit for the audit alongside your staff, and track every finding through to closure.
  • Your evidence: The third-party auditor’s findings report, and the record of what was corrected in response.

  • Why it matters: When nobody is named, everybody assumes someone else has it. Naming who is responsible — at the Board, in the office, and at each vendor — is the cheapest safeguard the Fund will ever put in place.
  • What Cyber Prudence does: We document the assignments: which Trustee or committee owns oversight, who runs it day to day, and what each vendor is on the hook for.
  • Your evidence: The roles and responsibilities record, reviewed and reaffirmed each year.

  • Why it matters: Most incidents start with someone reaching an account they should not have. Who can get to participant data, and how they prove they are allowed to, is the highest-value safeguard a fund office has.
  • What Cyber Prudence does: Access is documented, reviewed and enforced — including what happens the day someone leaves the office or changes roles, which is where most access problems actually begin.
  • Your evidence: The access review: who can reach what, and when it was last checked.

  • Why it matters: Most of the Fund’s participant data does not live in the Fund’s office. It lives with the TPA, the recordkeeper, the carriers. Their exposure is the Fund’s exposure — and reviewing them is the Board’s duty, not the vendor’s favor.
  • What Cyber Prudence does: We maintain the inventory of who holds or touches Fund data and run the scheduled reviews, reporting what came back — including what didn’t. For the independent assessments DOL expects, we tell the Board which vendors need one, what to ask them for, and whether what came back actually answers the question.
  • Your evidence: The vendor review file: who was reviewed, which independent assessments or SOC reports they provided, and what remains outstanding.

  • Why it matters: Your staff are the ones being targeted, every day. Training is how a fund office turns its people from the most likely way in into the first line of defense — and it is one of the few practices that produces a completion record on its own.
  • What Cyber Prudence does: Scheduled staff training with tracked completion, reinforced by simulated phishing so the Board can see whether it worked rather than assume it did.
  • Your evidence: Training completion records and phishing test results, by person and by date.

  • Why it matters: Fund offices do not write software. Their vendors do. This practice reaches the Fund through the people who build and maintain the systems its data sits in — which makes it a vendor question, not an IT one.
  • What Cyber Prudence does: We ask your software vendors how they build and secure what they sell you, document what they say, and flag where the answers are thin.
  • Your evidence: Vendor development and security attestations, on file with their review dates.

  • Why it matters: Benefits do not stop because the office does. What matters is whether the Fund can keep paying claims and answering members while the problem is being fixed — and whether that plan was written before it was needed.
  • What Cyber Prudence does: We document the incident response, business continuity and disaster recovery plans, then rehearse them — so the first time anyone runs the plan is not the day it counts.
  • Your evidence: The three plans, plus the drill records showing they were tested and what the tests found.

  • Why it matters: Encryption is the safeguard that limits the damage when something else has already failed. It is also one of the first specifics an examiner asks about, because it is easy to verify and hard to fake.
  • What Cyber Prudence does: Participant data is encrypted where it sits and while it moves. We document where that is true — and where a vendor’s practice is the reason it isn’t.
  • Your evidence: The encryption inventory: what is covered, by what, and every exception.

  • Why it matters: This is where technology does its actual job — enforcing the policy the Board set. A password rule only means something when a system requires it, applies it, and produces a report proving it happened.
  • What Cyber Prudence does: We review the everyday safeguards against the CIS Controls that sit underneath the DOL’s guidance, document what is in place, and report where the Fund stands each quarter.
  • Your evidence: The quarterly controls report, with a green / yellow / red view of where each safeguard stands.

  • Why it matters: No Board is judged on whether something got through. They are judged on what happened next — how fast, how well documented, and whether the Fund learned anything from it.
  • What Cyber Prudence does: Incidents are logged, worked to a conclusion, and closed with a written record of what happened, what was done, and what changed as a result.
  • Your evidence: The incident record for each event, and the plan-of-action showing what was corrected.

Setting the Benchmark for Prudent Governance

Ulico
Ullico Casualty Group underscores that these practices are not optional in spirit, even where they are not codified as regulation. A Board that cannot show it reviewed them is a Board explaining itself — not to a regulator with a fine, but to the members who elected it. The financial exposure is insured. The standing that made the seat worth taking is not.

Comprehensive, Consistent, Cost-Effective

Cyber Prudence™ is built around the realities of fund administration — eligibility files, contribution processing, TPA and recordkeeper handoffs, and the annual audit. Five layers cover all twelve of the DOL’s best practices, reviewed quarterly, for a predictable monthly fee.

Five layers. One record.

Together, they create a tangible record of prudence.

01 Governance Who owns the project? 02 Controls What safeguards are in place? 03 Validation Have they been tested? 04 Response Is the fund prepared to act? 05 Evidence Can the fund prove it?
01GovernanceWho owns the project?
02ControlsWhat safeguards are in place?
03ValidationHave they been tested?
04ResponseIs the fund prepared to act?
05EvidenceCan the fund prove it?

Governance covers best practices 1, 4, 7 · Controls 5, 10, 11 · Validation 2, 3, 6, 8 · Response 9, 12 · Evidence, all twelve.

“What’s your prudent process?”
Here it is.

Unions photo

Trusted by Labor

Union logo
Union logo
Cement masons logo
Boilermakers logo
Ironworkers logo
Oip logo
Smart logo

Could your Board show its prudent process today?

Don’t leave your prudent process to chance. Reasonable safeguards, independently checked and documented — Cyber Prudence™ for union funds.

The Cyber Preparedness Assessment is a comprehensive 10-week review that gives fund leadership a clear, documented view of its preparedness and prudent process.

Comprehensive 10-Week Assessment

Scored, Board-Ready Report

Board Presentation of Findings and Priorities

Schedule Your Review
By clicking ‘Schedule Your Review’, you’ll take a step towards understanding the safeguards your Fund has in place and the process behind them.