PLANADVISER - Winter 2023 - 27

Grimes proposed that firms have a
plan in place in case a cybersecurity
incident were to hit. He recommended
to the virtual audience that they know
whom to reach out to.
" You don't want to make those sorts
of decisions in the midst of the crisis, "
he said. " It's nice to have a thoughtful
plan, ahead of time. If the worst
happens, you can approach it in the
best way. "
Grimes said institutional investors,
plan sponsors and advisers should, as
preventative measures:
* Be cautious of social engineering
such as fake emails and websites;
* Mend unpatched software;
* Regularly update software,
firmware
and routers; and
* Use multifactor authentication
and different passwords for every site.
" Those four things, " he said. " If you
can do them, it will probably mean
that you're very unlikely to get compromised. "
-Natalie Lin
Vetting Providers'
Cybersecurity Processes
How can asset owners, sponsors and
plan advisers
scope out
the bona
fides among cybersecurity vendors,
whose expertise is key to protecting
networks and other digital assets
from breaches?
Cybersecurity
A panel at the " Vetting Providers'
Processes "
session
offered safety tips for protection from
the legions of hackers. It was moderated
by Glenn Davis, deputy director of
the Council of Institutional Investors.
One vital tool, according to the
panelists, is audits of third-party
providers done under the auspices of
the Service Organization Control Type
2-aka SOC 2-compliance framework.
The framework was established by the
American Institute of Certified Public
Accountants and is designed to ensure
the security of client data that thirdparty
administrators handle. It does
this by specifying how organizations
should manage customer data.
Further, speakers said, the SOC 2
Type 2 report outlines a company's
internal controls and details how well it
safeguards customer data, specifically
for cloud service providers. A thirdparty
audit can reveal whether security
protocols are safe and effective.
" This
drives
confidence
and
removes speculation " in the screening
procedures of providers, advised Jon
Atchison, senior lead of governance,
risk and compliance at investment
adviser firm CAPTRUST.
To cite an example of what can go
wrong, Atchison, a speaker on the
livestream, pointed to a recent, large
cybersecurity failure: the breach of
MOVEit
file transfer software, which
exposed sensitive personal data from
governments and businesses internationally
and potentially involved
millions of people. " MOVEit wasn't the
first and won't be the last, " he said.
SPEAKERS
Nick Brezinski,
director of information
security and network,
CAPTRUST
Larry Clinton,
president and CEO,
internet security,
Alliance
Roger A. Grimes,
data-driven defense
evangelist, KnowBe4
" It's always
good for any
organization
to think about
what the rules
are that apply
to you ... "
One task for providers is to guard
against threats from employees and
other insiders, said panelist Allison
Itami, a principal in Groom Law Group,
whose Employee Retirement
Income
Security Act practice focuses on data
privacy and data security. These
in-house folks can pose a risk of theft
or fraud, Itami said. " As long as humans
are involved, " cyber vulnerabilities will
be around, and a lot is at stake, she said.
" If you lose money or have a data breach,
trust is eroded. "
What is vexing is that no absolute
shield exists to foil cyber mischief. " No
one can be 100% safe, " said panelist
Mario Paez, national cyber risk leader at
Marsh McLennan Agency, which sells
insurance to organizations to protect
against breach liabilities.
Some think that other business
insurance, not tailored to digital crime,
will be sufficient-and they are wrong,
Paez said. Certainly, specialized cybersecurity
policies are complex, " and the
devil is in the details, " he stressed. For
that reason, he continued, it pays to get
a cybersecurity-savvy insurance broker
to advise on what is best for a company's
particular needs.
Insurance, he said, must cover
a range of necessities that can be
created by a breach, including: extortion
coverage in case of a ransomware
attack; business losses; the
costs of notification to people affected
by a breach; and forensic probes of
how and why an incident occurred.
-Larry Light
Percy Lee,
associate, Ivins,
Phillips & Barker
Thank you, Marsh McLennan Agency, for supporting the event.
Plan Management | Winter 2023 | planadviser.com 27
http://www.planadviser.com

PLANADVISER - Winter 2023

Table of Contents for the Digital Edition of PLANADVISER - Winter 2023

Publisher’s Note
Just the Facts
On the Move
Nuts & Bolts
What’s Next?
Best Foot Forward
2023 PLANADVISER National Conference
Cybersecurity Conference
Let It Ride
Cultivating Connections
The Risks of Custom TDFs
Managed Account Services
People-Savvy
Be Sure They Get the Message
End Paper
PLANADVISER - Winter 2023 - Cover1
PLANADVISER - Winter 2023 - FC1
PLANADVISER - Winter 2023 - FC2
PLANADVISER - Winter 2023 - Cover2
PLANADVISER - Winter 2023 - 1
PLANADVISER - Winter 2023 - Publisher’s Note
PLANADVISER - Winter 2023 - 3
PLANADVISER - Winter 2023 - Just the Facts
PLANADVISER - Winter 2023 - 5
PLANADVISER - Winter 2023 - 6
PLANADVISER - Winter 2023 - 7
PLANADVISER - Winter 2023 - On the Move
PLANADVISER - Winter 2023 - 9
PLANADVISER - Winter 2023 - 10
PLANADVISER - Winter 2023 - 11
PLANADVISER - Winter 2023 - Nuts & Bolts
PLANADVISER - Winter 2023 - 13
PLANADVISER - Winter 2023 - What’s Next?
PLANADVISER - Winter 2023 - 15
PLANADVISER - Winter 2023 - 16
PLANADVISER - Winter 2023 - 17
PLANADVISER - Winter 2023 - 18
PLANADVISER - Winter 2023 - Best Foot Forward
PLANADVISER - Winter 2023 - 20
PLANADVISER - Winter 2023 - 21
PLANADVISER - Winter 2023 - 2023 PLANADVISER National Conference
PLANADVISER - Winter 2023 - 23
PLANADVISER - Winter 2023 - 24
PLANADVISER - Winter 2023 - 25
PLANADVISER - Winter 2023 - Cybersecurity Conference
PLANADVISER - Winter 2023 - 27
PLANADVISER - Winter 2023 - Let It Ride
PLANADVISER - Winter 2023 - 29
PLANADVISER - Winter 2023 - 30
PLANADVISER - Winter 2023 - 31
PLANADVISER - Winter 2023 - Cultivating Connections
PLANADVISER - Winter 2023 - 33
PLANADVISER - Winter 2023 - The Risks of Custom TDFs
PLANADVISER - Winter 2023 - 35
PLANADVISER - Winter 2023 - Managed Account Services
PLANADVISER - Winter 2023 - 37
PLANADVISER - Winter 2023 - People-Savvy
PLANADVISER - Winter 2023 - Be Sure They Get the Message
PLANADVISER - Winter 2023 - End Paper
PLANADVISER - Winter 2023 - Cover3
PLANADVISER - Winter 2023 - Cover4
https://www.planadviserdigital.com/planadviser/winter_2023
https://www.planadviserdigital.com/planadviser/fall_2023
https://www.planadviserdigital.com/planadviser/summer_2023
https://www.planadviserdigital.com/planadviser/industryleader_2023
https://www.planadviserdigital.com/planadviser/spring_2023
https://www.planadviserdigital.com/planadviser/november_december_2022
https://www.planadviserdigital.com/planadviser/september_october_2022
https://www.planadviserdigital.com/planadviser/july_august_2022
https://www.planadviserdigital.com/planadviser/may_june_2022
https://www.planadviserdigital.com/planadviser/industry_leader_awards_2022
https://www.planadviserdigital.com/planadviser/march_april_2022
https://www.planadviserdigital.com/planadviser/january_february_2022
https://www.planadviserdigital.com/planadviser/november_december_2021
https://www.planadviserdigital.com/planadviser/september_october_2021
https://www.planadviserdigital.com/planadviser/july_august_2021
https://www.planadviserdigital.com/planadviser/may_june_2021
https://www.planadviserdigital.com/planadviser/march_april_2021
https://www.planadviserdigital.com/planadviser/january_february_2021
https://www.planadviserdigital.com/planadviser/november_december_2020
https://www.planadviserdigital.com/planadviser/september_october_2020
https://www.planadviserdigital.com/planadviser/july_august_2020
https://www.planadviserdigital.com/planadviser/may_june_2020
https://www.planadviserdigital.com/planadviser/march_april_2020
https://www.planadviserdigital.com/planadviser/january_february_2020
https://www.planadviserdigital.com/planadviser/november_december_2019
https://www.planadviserdigital.com/planadviser/september_october_2019
https://www.planadviserdigital.com/planadviser/july_august_2019
https://www.planadviserdigital.com/planadviser/may_june_2019
https://www.planadviserdigital.com/planadviser/march_april_2019
https://www.planadviserdigital.com/planadviser/january_february_2019
https://www.planadviserdigital.com/planadviser/november_december_2018
https://www.planadviserdigital.com/planadviser/september_october_2018
https://www.planadviserdigital.com/planadviser/july_august_2018
https://www.planadviserdigital.com/planadviser/may_june_2018
https://www.planadviserdigital.com/planadviser/march_april_2018
https://www.planadviserdigital.com/planadviser/january_february_2018
https://www.planadviserdigital.com/planadviser/november_december_2017
https://www.planadviserdigital.com/planadviser/september_october_2017
https://www.planadviserdigital.com/planadviser/july_august_2017
https://www.nxtbookmedia.com