EOIPA’s view of cyber risk in the pensions industry

This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
In February this year (2024), the European Insurance and Occupational Pensions Authority (EIOPA) released their first risk dashboard on the Institutions for Occupational Retirement Provisions (the “Dashboard”). The Dashboard “summarises the main risks and vulnerabilities” within the EEA for both DC and DB occupational pension schemes.
The Dashboard covers several topics, including credit risks, liquidity risks, the funding of DB schemes, and ESG related risks. In this post, we delve into the Dashboard’s summary of the risk relating to “Digitalisation and cyber risks”.
Digitalisation and cyber risks
To note, the EIOPA define this topic as “risks from a digital operational resilience perspective (i.e. cyber security risks)”, which they link to the increase in digitalisation of the pensions industry generally.
To summarise the risk posed by cyber security:
Our comment
We would note that the Dashboard is focused on European pension schemes. Therefore, it doesn’t cover factors specific to the UK. For example:
Potentially these factors would result in a UK-focused dashboard concluding that cyber risk is ‘high’ (rather than ‘medium’), and they are certainly relevant factors for schemes to consider (specific to the UK) when allocating risk in their scheme-specific risk registers. On the topic of risk registers, Trustees should ensure to factor in characteristics specific to their scheme (such as the value of the data they hold) when assigning the level of risk to cyber.
How we can help
Burges Salmon can assist pension schemes in building their cyber resilience. Our Cyber Security Package offering is designed to meet the cyber security expectations for trustees under TPR’s Cyber Principles and the General Code. Some information about this can be found here: Cyber Security for Pension Schemes legal advice | Burges Salmon Pensions lawyers (burges-salmon.com).
If you are interested in finding out more about our Cyber Security Package offering or anything else cyber security related, please contact Richard Pettit or Samantha Howell.
This post was written by Callum Duckmanton and Samantha Howell.
https://www.eiopa.europa.eu/sites/default/files/site-logo-overrides/EWPPA_EIOPA_logo.svg
https://www.eiopa.europa.eu/tools-and-data/occupational-pensions-risk-dashboard_en