Series

Blogs

Five steps for managing cyber risk for pension scheme trustees

Article|
13 March 2026

Share this:

Cyber attacks are a real and growing problem – and pension schemes are particularly in the firing line, given the large amounts of personal data and assets they hold. So what should trustees be doing about it, and what happens if the worst occurs?

What is cyber risk?

The Pensions Regulator defines "cyber risk" as the risk of loss, disruption, or damage to a scheme or its members because of the failure of its information technology systems and processes. It covers risks to both data and assets, and includes both internal threats (such as from staff) and external ones (such as hacking).

The stakes are high. Perhaps the best-known example in the pensions world is the 2023 Capita data breach, in which there was unauthorised access to data held by one of the UK's largest pension administrators – one that administers over 450 pension schemes. The breach cost Capita an estimated £25 million and was a stark reminder that no scheme is immune.

Who is responsible?

In practice, most trustees will delegate tasks like data handling and technology management to third parties such as administrators. But trustees remain responsible for the security of scheme information and assets, and for complying with data protection legislation. That means trustees need to verify their administrator's security measures, monitor them on an ongoing basis, and clearly define who is responsible for identifying and responding to cyber incidents.

Five steps every trustee board should take

There are five key steps that all trustees should take to assess and manage cyber risk: