DATA & SECURITY
Cybersecurity for retirement plans
Every plan runs on a chain of vendors touching the same participant data. See where the exposure actually sits, and how standardized data exchange closes the gaps.
THE ASTERI COLLECTIVE PERSPECTIVE
Most cyber risk in the retirement industry is structural. Manual file transfers, redundant data entry, handoffs that depend on someone remembering to encrypt an attachment. The SPARK Institute’s API framework replaces those handoffs with standardized, encrypted, real-time exchange.
“You set the schedule, you define what data is needed, and it moves securely and instantly.” – Joe Burt, Chair, SPARK Technology & API Committee
The SPARK API guidelines provide a framework for secure, standardized data exchange between recordkeepers, payroll providers, plan sponsors, advisors, and RPCs.
The practical effect for advisors and recordkeepers is fewer points where data sits exposed in transit. For RPCs, it means less manual reconciliation work and a materially smaller opportunity for something to go wrong on your watch. As of mid-2025, SPARK’s Census API is live, with Loan and Distribution and Participant Balance APIs rolling out next.
REDUCING CYBER RISK
For recordkeepers and payroll providers, standardizing data exchange pays for itself. Every manual file transfer, every one-off reconciliation step, is a task that depends on a person doing it right every time. In 2025, the FBI’s Internet Crime Complaint Center reported that Americans 60 and older lost $7.7 billion to internet crime*. Retirement accounts are a frequent target because verification still often runs through manual, phone-based processes.
One widely reported case saw over $750,000 pulled from a single 401(k) account after an impostor bypassed security protocols with a handful of personal details. This is the kind of manual gap that automated, API-based authentication is built to close.
Asteri member firms are at the forefront of The SPARK Institute’s API standards adoption for exactly this reason: fewer manual handoffs to manage, less reconciliation work wasting employee hours, and a measurably smaller opportunity for fraud, ransomware, and human error.
$7.7 billion lost to internet crime*
What the expectations are currently
The Department of Labor’s cybersecurity guidance for retirement plans covers three areas:
Plan sponsors carry ultimate fiduciary responsibility for vendor selection and oversight, even when a breach originates with a third party. For advisors, explaining that exposure clearly helps plan sponsors appreciate the need for an RPC whose cyber policies and standards are exemplary (like all Asteri members are).
RELATIONSHIP ROI
Reducing manual entries
Census and deduction data often move through manual uploads or one-off exports. Standardized automation removes the chance for errors and reduces vulnerability.
Exposure compounds per partner
Every integration is a separate authentication point. Standardized APIs replace bespoke connections with one common protocol.
We hold the most sensitive data
Census files, loans, balances, held in multiple systems transferring key pieces of information across vendors and client systems.
Fiduciary responsibility rests here
Plan sponsors carry responsibility for vendor security across the entire chain, even for a breach several steps removed from their own systems.