Pension scheme cyber risk – a covenant issue?
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
As a potentially high impact risk that should be monitored on an ongoing basis, cyber security and business continuity is an area that the Pensions Regulator (TPR) regularly refers to in its updates, statements and guidance.
This trend has continued in the recent publication of TPR’s Annual Funding Statement 2026 and Annual Report and Accounts (2025 to 2026).
TPR Annual Report and Accounts 2025/26
Cyber risk was a key area of focus for TPR following its Annual Report and Accounts 2024/25. In last year’s Report and Accounts, one of the few areas where TPR recognised that it needed to further enhance its processes was cyber security, with last year’s report stating that cyber risks and pensions technology in the pensions sector was the only “KPI target missed by [a] significant degree” at that time.
This year’s Annual Report and Accounts (2025 to 2026) demonstrate that progress has been made, with zero KPI targets missed by a significant degree this year.
With regards to embracing data, digital and technology, the Report states that TPR has “made progress in modernising [its] internal systems through the development of platform teams supporting case management and data services, alongside improvements in data governance, cyber resilience, access management, AI and master data management.” With regards to improving system hygiene, TPR “has modernised core systems, strengthened cyber resilience, and positioned TPR for more efficient and sustainable delivery in 2026-27 and beyond.”
TPR recognises the following enterprise risks relevant to cyber security in the Report:
Here, as in so many areas, TPR leads by example - cyber risk is an area that should be on risk registers for all pension schemes and regularly monitored. The key to building cyber resilience is progress, not perfection.
This is more relevant than ever in light of the increased risk of AI-enhanced cyber-attacks. This update from Aon refers to CrowdStrike analysis which found that AI-enhanced phishing emails have shown click-through rates of 54%, compared with a 12% click-through rate for traditional phishing attacks.
TPR Annual Funding Statement 2026
TPR also recently released its Annual Funding Statement 2026. Whilst it only mentions cyber once, the update from TPR is an interesting one, reading: “The potential impacts from cyber incidents, have become an area of increasing concern for trustees and employers. These issues can materially impact the employer covenant through impacts on their business activities, operations and supply chains. We expect trustees to monitor these risks, with the frequency and depth of monitoring proportionate to the circumstances of the employer and the scheme.”
Interestingly, TPR highlights cyber incidents as a covenant issue. Many trustees have been focussing on assessment of their third-party suppliers, which is necessary as supply chain risk is a key risk area for pension schemes. However, trustees should not forget to look closer to home and ask questions of their sponsor to understand their cyber resilience position as well. It is absolutely the case that if a scheme sponsor suffers a serious cyber incident then, as we have seen from various examples in the press over the last few years, that can have hugely significant ramifications on a sponsor’s business, which could in turn have implications for the strength of the pension scheme’s employer covenant.
Key takeaways
Both of these TPR publications indicate a continued need for pension schemes, trustees and pensions professionals to consider cyber resilience on an ongoing basis. Key takeaways include:
We will continue to monitor any developments from TPR in the cyber security space with interest.
If you have any questions, please contact Samantha Howell, Richard Pettit or your usual Burges Salmon contact.
This article was written by Samantha Howell and Christian Wade.
The potential impacts from cyber incidents, have become an area of increasing concern for trustees and employers. These issues can materially impact the employer covenant through impacts on their business activities, operations and supply chains. We expect trustees to monitor these risks, with the frequency and depth of monitoring proportionate to the circumstances of the employer and the scheme.
https://www.thepensionsregulator.gov.uk/en/document-library/statements/annual-funding-statement-2026
Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.
Update your preferred sourcesBe sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.
Follow us