Pensions Pod: Cyber and AI Bytes – key takeaways from the mini series
This website will offer limited functionality in this browser. We only support the recent versions of major browsers like Chrome, Firefox, Safari, and Edge.
To kick off the new year, we released six mini podcast episodes as part of our Cyber and AI Bytes Podcast Series.
We invited some of our cyber and data protection experts from around the firm to speak on topical issues and to showcase how their expertise can help our pensions clients whether you are trustee, sponsor, provider or anyone else connected with UK pensions.
Here, we outline the topics covered in the six episodes and the key takeaways from each of them.
No. | Episode | Summary of topic covered | Key takeaways/action points | Speakers | Link to recording |
1 | Implications of the Data (Use and Access) Act 2025 for pension schemes | This episode covers:
| They key takeaways for trustees are to:
| Implications of the Data (Use and Access) Act 2025 for pension schemes | |
2 | Understanding legal privilege for trustees in a cyber context | This episode covers:
| Legal privilege is a powerful tool in managing cyber incidents. It protects trustees’ ability to investigate, strategies and respond without exposing sensitive discussions. By planning ahead and following practice, organisations can maximise their ability to rely on privilege, reducing legal risk and maintaining confidentiality throughout a crisis. In other words, trustees should consider in advance whether they want to instruct legal advisers as soon as they become aware of a potential cyber incident and, if so, whether their legal advisers have the required mix of cyber security and pensions expertise. | Understanding legal privilege for trustees in a cyber context | |
3 | Demystifying Data Subject Access Requests | This episode covers:
| The key takeaway for trustees is to remember that as data controllers you are responsible for reporting to DSARs, but that this will need to be done in practice in conjunction with your advisers who hold the relevant data (usually your scheme administrator), taking into account the tight timeframes to respond (usually 30 days max). | ||
4 | The evolving landscape of AI in Pensions | This episode covers:
| The key takeaways for trustees are:
| ||
5 | A Guide to Ransomware for Pension Trustees | This episode covers:
| They key takeaway for trustees is to engage with your scheme sponsor about this issue ahead of time where possible. What would their likely position be and who would the trustees be able to contact who could make this kind of decision within a short time frame if the worst were to happen? | ||
6 | Understanding the cyber risks of Pensions Dashboards | This episode covers:
| They key takeaways from the podcast episode are to put in place a DPIA for dashboards if your scheme does not already have one, to update your scheme’s privacy notice and to consider other relevant actions. Other relevant actions are discussed on the podcast and can also be found in this article: Pensions dashboards compliance: the cyber risk perspective - Burges Salmon Access to the Pensions Dashboards Toolkit and Connection Checklist mentioned on this episode can be requested here: Pensions Dashboards – Burges Salmon |
We hope you enjoyed listening to our podcast series. If you would like any more information regarding the cyber security, data protection and AI advice that we offer, please consult our dedicated webpage. If you have any questions, please feel free to get in contact with Chris Brown, Samantha Howell or your usual Burges Salmon contact.
Want more Burges Salmon content? Add us as a preferred source on Google to your favourites list for content and news you can trust.
Update your preferred sourcesBe sure to follow us on LinkedIn and stay up to date with all the latest from Burges Salmon.
Follow us