The Pensions Research Accountants Group (PRAG) is warning that pension funds are at high risk of attack from cyber criminals as they have access to extensive personal identity data including addresses, financial records and banking details, which can be sold, or used to compromise or steal from other victims
Responding to growing concerns about the cyber threat to pension funds, PRAG has issued guidance for trustees of pension schemes and their advisers highlighting the risks of cybercrime and ways to protect pension funds from attack
The PRAG report highlights some recent cybercrime attacks around the world where hackers infiltrated pension funds, such as an instance at Capita where an employee siphoned off around £400,000 to personal accounts disguised as bereavement payments.
An attack on The Pension Regulator used ransomware to try to access data. In this attack, albeit unsuccessful, a single computer was infected with ransomware which reportedly did not result in any data loss, although this was not the first such attack against the Regulator, which has blocked over 40,000 attack attempts in the last three years.
Fraud and cybercrime account for more than half (54%) of the most common criminal offences, with Office for National Statistics showing that 5.8m cyber and fraud offences took place in the 12 months up to June 2017.
The guidance has been put together by PRAG’s data protection and cyber security working group and includes useful questions and information on what to look out for and how to create a stronger security infrastructure to protect vital data.
It builds on The Pensions Regulator’s recent guidance stating that trustees and scheme managers need to take steps to protect members and assets against cyber risk. Attacks come in many different guises, including data and firewall breaches, malware, ransomware and virus attacks, as well as more traditional crime such as theft of hard drives and data files.
Jim Gee, a member of the PRAG data protection and cyber security working group, said: ‘Cybercrime is a continuously evolving phenomenon, akin to a clinical virus, and is undertaken by sophisticated criminal enterprises.
‘Pension schemes have rich seams of data which beneficiaries expect will be properly protected. This guide describes how they can assess their vulnerability and put in place proportionate protection.’
Tara Wooton, chair of the PRAG working group added: ‘Pension schemes and their third party providers need holistic protection to reduce the impact that an attack would have.
‘The key is to be as secure as possible but also to plan for a cybercrime attack happening and to be ready to manage and mitigate any damage.’
PRAG is the body responsible for the accounting rules for the pension sector and is designated by the Financial Reporting Council (FRC) to produce accounting guidance for pensions through the Pensions Statement of Recommended Practice (SORP), which is due to be updated this June.
PRAG: An overview of the effects of Cybercrime on pension schemes is available from PRAG, released 18 April 2018
Report by Sara White