Broker Check
BENEFIT PLAN INSIDER

BENEFIT PLAN INSIDER

September 08, 2026

BENEFIT PLAN INSIDER

Ideas & Insights for Retirement Plan Fiduciaries

September 2026 | Approximately 6-minute read

In This Issue

Why cybersecurity belongs on the retirement plan committee agenda, how a consistent service model can help organize 2027 priorities, and a book recommendation that came from a successful business owner after the sale of his company.

A Note From Our Team

Approximately 80 words | Less than 1 minute

Benefit Plan Insider is designed to provide practical education for retirement plan sponsors, committee members, business owners, executives, and HR professionals.

We'll cover investments and fees, but we also want to explore the broader issues that help determine whether a retirement plan is working: fiduciary governance, participant outcomes, cybersecurity, plan design, regulation, employee education, and benefits strategy.

If your committee is facing a question or topic you'd like us to explore in a future edition, please send it our way.


Cyber Risk Is Now a Retirement Plan Committee Issue

You Don't Have to Be a Technology Expert to Ask Good Questions

Approximately 500 words | 2½-minute read

Cybersecurity was once viewed primarily as an IT department responsibility.

That world has changed.

Retirement plans may hold substantial assets while their administrators and service providers maintain sensitive participant information, including Social Security numbers, addresses, dates of birth, beneficiary information, payroll data, account balances, and potentially bank information used for distributions.

As more financial activity and personal information have moved online, cybercrime has become an important financial, operational, and governance risk.

Artificial intelligence may further complicate the environment by making fraudulent communications and impersonation attempts increasingly sophisticated.

What Does This Have to Do With the Retirement Plan Committee?

Committee members aren't expected to become cybersecurity engineers.

However, prudent plan governance increasingly includes understanding how the plan and its service providers protect participant information and assets.

The U.S. Department of Labor has published cybersecurity guidance for plan sponsors, fiduciaries, recordkeepers, and participants addressing areas such as cybersecurity programs, risk assessments, security reviews, access controls, multifactor authentication, employee training, service-provider oversight, and incident-response procedures.

The practical question isn't:

"Do we understand every technical aspect of cybersecurity?"

It's:

"Do we have a reasonable process for understanding how our plan and its participants are being protected?"

Five Questions Worth Asking Your Providers

  1. Is multifactor authentication available or required?
  2. How are participant accounts monitored for suspicious activity?
  3. How frequently are cybersecurity controls independently assessed or audited?
  4. What happens following a suspected cybersecurity incident, and how would our organization be notified?
  5. How do you evaluate subcontractors and other third parties that have access to plan information?

The answers will vary among providers.

The important part is having a process for asking, evaluating, following up when necessary, and documenting the committee's review.

Don't Forget the Employer's Own Processes

The recordkeeper is only one part of the system.

Employers should also periodically consider their own procedures surrounding payroll files, employee banking changes, access to HR and benefit systems, employee cybersecurity training, passwords and authentication, and unusual financial requests.

A sophisticated security system can still be vulnerable when someone is successfully convinced to voluntarily provide access.

Why It Matters

Cybersecurity doesn't need to consume every committee meeting, and committee members don't need to become technology experts.

They do need a prudent process for asking good questions.

Consider incorporating a periodic cybersecurity and service-provider review into the committee's governance process and documenting that review.


Is Your Retirement Plan Ready for 2027?

A Look at the Issues Every Committee Should Have on Its Radar

Approximately 500 words | 2½-minute read

A strong retirement plan committee shouldn't have to reinvent its agenda every quarter.

EIP's service model is designed to provide a consistent framework throughout the year while allowing each committee to spend additional time on the issues most important to its particular organization, plan, and employees.

As 2027 approaches, here are several areas committees should have on their radar.

Investments & Plan Costs

Investment performance matters, but oversight goes beyond performance.

Committees should maintain a process for reviewing investments, watch-list funds, relevant benchmarks, the Investment Policy Statement, and overall plan costs.

The objective isn't simply finding the cheapest option. It's evaluating whether costs and services remain reasonable for the value being provided.

Plan Operations

Some of the least exciting retirement plan issues can also be among the most important.

Annual testing, participant loans and distributions, required minimum distributions, beneficiary procedures, plan documents, service-provider responsibilities, and outstanding administrative issues all deserve appropriate attention.

Participant Outcomes & Education

A plan can have excellent investments and competitive fees and still fall short if employees aren't using it effectively.

Participation matters, but so do savings rates, employer match utilization, investment behavior, retirement readiness, and the effectiveness of participant education.

Instead of only asking:

"How is our plan performing?"

also ask:

"How well is our plan working for our employees?"

Plan Design & Benefits Strategy

Workforces change. Organizations change. Retirement plans should be periodically evaluated as well.

Depending on the organization, this may include employer contributions, automatic features, Roth, emergency savings, retirement-income considerations, recruiting and retention, and coordination with the broader benefits program.

Not every feature belongs in every plan.

The point is to periodically ask whether the plan still supports the organization's objectives and its employees' needs.

Fiduciary Governance

Fiduciary education, regulatory developments, committee roles, meeting documentation, cybersecurity, service-provider oversight, and outstanding action items should all have a place in the governance process.

Some deeper subjects may be more appropriate on a rotating two- or three-year schedule rather than every year.

Organizations with ESOPs, cash balance plans, frozen pension plans, nonqualified deferred compensation plans, or other specialized programs may also need to incorporate those programs into the broader retirement and benefits discussion.

Why It Matters

The purpose of a service model isn't to create more meetings or more paperwork.

It's to make the committee's limited time more intentional.

Some issues require immediate action. Others require monitoring. Still others deserve a deeper review every few years.

A consistent process helps committees know the difference.


Worth a Read

10x Is Easier Than 2x

By Dan Sullivan and Dr. Benjamin Hardy

Approximately 140 words | Less than 1 minute

Recently, I had a conversation with a successful business owner who had sold his company in a very significant transaction.

I asked him a simple question:

"What books were most helpful to you along the way?"

One of the books he recommended was 10x Is Easier Than 2x by Dan Sullivan and Dr. Benjamin Hardy.

I subsequently read it and understood why he recommended it.

The central idea is counterintuitive: transformational growth doesn't necessarily come from doing dramatically more work. It can come from becoming much more selective about where you spend your time, eliminating or delegating lower-value activities, and concentrating on the relatively small number of activities where you can create the greatest impact.

For business owners, executives, HR professionals, and committee members constantly balancing competing priorities, it's a thought-provoking read.


Have a plan question, committee concern, or idea for a future issue? We'd love to hear it.

Be well,

Mike Romig, Kyle Veverka, Bilal Abdulkadir & Dayle Scheinman
Elevated Investment Partners