
Fund offices are entrusted with participant data that deserves the highest level of protection. For plan fiduciaries, meeting EBSA’s expectations is not an IT preference — it is part of the duty of prudence. Cyber Prudence™ turns that duty into a documented process, and the documented process into something the Board can show.
On April 14, 2026, the DOL’s Employee Benefits Security Administration issued Field Assistance Bulletin 2026-01. Two points deserve every trustee’s attention.
“ERISA is a law of process and not results.”
When an enforcement action is based solely on prudence, EBSA says it must avoid cases that unfairly second-guess process-based fiduciary judgments.
EBSA also established investigation timeframes: routine matters should be completed within 18 months and more complex investigations within 30 months, absent exceptional circumstances.
No one accepts an unpaid, honorary trustee seat expecting to spend as long as two and a half years answering investigators, coordinating with counsel, and explaining the fund’s decisions to the members who elected them.
The time to assemble evidence of prudence is before that clock starts. A Proof of Prudence gives the Board a documented record of what it considered, decided, implemented, and independently verified.
The Department of Labor publishes twelve best practices. That is the checklist. Cyber Prudence™ is the process that produces them — and the record that proves it. Each one below maps to the layer that covers it, and to the document it leaves behind.
Cyber Prudence™ is built around the realities of fund administration — eligibility files, contribution processing, TPA and recordkeeper handoffs, and the annual audit. Five layers cover all twelve of the DOL’s best practices, reviewed quarterly, for a predictable monthly fee.
Five layers. One record.
Together, they create a tangible record of prudence.
Governance covers best practices 1, 4, 7 · Controls 5, 10, 11 · Validation 2, 3, 6, 8 · Response 9, 12 · Evidence, all twelve.
“What’s your prudent process?”
Here it is.








The Cyber Preparedness Assessment is a comprehensive 10-week review that gives fund leadership a clear, documented view of its preparedness and prudent process.
Comprehensive 10-Week Assessment
Scored, Board-Ready Report
Board Presentation of Findings and Priorities