The Pensions Regulator’s General Code of Practice comes into force today, consolidating ten earlier codes into a single, modular code.
As part of an “effective system of governance”, governing bodies of pension schemes must ensure that cyber risk is assessed and controlled. Expectations include:
- Clear roles and responsibilities for cyber risk.
- Assessing the vulnerability of key functions, systems and assets, including those of administrators and other suppliers.
- Appropriate controls and an incident response plan.
- Regular testing and review.
Trustees should expect to seek assurance from administrators and other providers, and suppliers to pension schemes should be ready to evidence their controls.
Source: General Code of Practice (The Pensions Regulator)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.