Cybertheft and the Defined Contribution Plan: The Recovery Gap, the DCCIC Proposal, and the Case for Recalibrated Fidelity Bond and Fiduciary Liability Programs to address 401(k) Cybertheft
The Department of Labor’s January 2026 statement of enforcement policy designated cybersecurity and data protection as its highest enforcement priority, a designation that formalizes what practitioners in the qualified plan space have observed for the better part of a decade: 401(k) cybertheft has made the defined contribution account balance among the most attractive targets in the American financial system. Unlike a defined benefit promise, which is backstopped by the Pension Benefit Guaranty Corporation, the participant-directed account carries no federal insurance. When a criminal actor drains a 401(k) account through credential compromise, fraudulent distribution requests, or an attack on recordkeeper infrastructure, the participant’s avenues of recovery are narrow, contingent, and frequently illusory.
A recent proposal for a Defined Contribution Cybersecurity Insurance Corporation (DCCIC) responds to this gap by recommending a self-funded federal agency, structurally analogous to the PBGC, to compensate participants where no party bears legal responsibility for the loss. This essay reports on that proposal, situates it within the existing liability architecture of the Employee Retirement Income Security Act of 1974 (ERISA), and offers recommendations concerning the ERISA fidelity bond and fiduciary liability insurance programs that plan sponsors and fiduciaries should maintain in the interim, because whatever the merits of the DCCIC concept, no federal backstop exists today.
The Recovery Gap Under Current Law
ERISA Section 409, 29 U.S.C. § 1109, renders a fiduciary personally liable to make good plan losses “resulting from” a breach of fiduciary duty. The causation element is decisive. The duty of prudence under Section 404(a)(1)(B) is measured against the circumstances then prevailing, and cybersecurity circumstances mutate faster than fiduciary process can be documented (29 U.S.C. § 1104(a)(1)(B)). A fiduciary who adopted and monitored a cybersecurity program consistent with the Employee Benefits Security Administration’s published best practices may nonetheless preside over a plan from which accounts are looted by a novel attack vector (U.S. Department of Labor 2021). Where the hypothetical prudent fiduciary’s safeguards would not have prevented the loss, the causal chain fails and Section 409 liability with it. The early case law confirms the difficulty. Courts have permitted claims to proceed where distribution processing failures were alleged, as in Leventhal v. MandMarblestone Group LLC, No. 18-cv-2727 (E.D. Pa. 2019), and Disberry v. Employee Relations Committee of the Colgate-Palmolive Co., 646 F. Supp. 3d 531 (S.D.N.Y. 2022), but have dismissed claims against sponsors lacking a sufficient connection to the theft, as in Bartnett v. Abbott Laboratories, 492 F. Supp. 3d 787 (N.D. Ill. 2020). Recovery is fact-bound, expensive to litigate, and unavailable where no fiduciary lapse can be proven.
The alternative remedies are thinner still. The Mandatory Victims Restitution Act, 18 U.S.C. § 3663A, conditions restitution on a federal conviction, an event that rarely materializes in cybercrime given attribution difficulties and the offshore location of most threat actors. State law negligence claims against non-fiduciary service providers confront unresolved ERISA preemption questions under 29 U.S.C. § 1144. The federal income tax system offers no meaningful relief either; a theft loss deduction is capped at the participant’s basis in the account, which for a traditional pretax 401(k) account is typically zero (Internal Revenue Service 2025, CCA 202511015). The pending Tax Court petition in Caputo v. Commissioner, filed June 3, 2026, challenging the denial of a theft loss deduction for an $800,000 IRA liquidation, illustrates both the stakes and the doctrinal resistance. The result is a category of loss for which, as the proposal candidly states, there may be no one available to blame.
The DCCIC Proposal
The DCCIC proposal recommends congressional authorization of an independent federal agency, governed by a presidentially appointed board including DOL and Treasury representation, to insure ERISA-covered defined contribution plans against cybercrime losses. The agency would be self-funded through risk-based premiums assessed on registered plan sponsors and service providers, with tiering calibrated to plan size, participant count, cybersecurity maturity, and incident history. Covered events would include unauthorized account access, fraudulent distributions, data breaches producing asset theft, and attacks on plan infrastructure. Critically, the DCCIC would function as a payor of last resort: coverage would be excluded or reduced where the loss resulted from participant negligence, where a proven fiduciary breach caused the loss, and ERISA litigation is available, or where MVRA restitution or a non-preempted state negligence claim would compensate the participant. The agency would retain subrogation rights against perpetrators and negligent third parties. The proposal draws an explicit analogy to state insurers of last resort for wildfire and hurricane risk, and it acknowledges that enabling legislation, a stakeholder convening process, and a voluntary pilot program would precede full implementation.
The design is sound in its recognition that cyber risk in the retirement system is partially uninsurable through liability mechanisms alone, because liability requires fault and cybertheft frequently occurs without actionable fault. The principal underwriting objections are moral hazard and adverse selection, both of which the proposal addresses through minimum cybersecurity standards as a condition of registration and premium differentiation rewarding control maturity. Whether Congress will act is another matter. Until it does, the burden of loss mitigation falls on the private insurance and suretyship instruments already embedded in ERISA practice.
Recommendations: The ERISA Fidelity Bond
Every person who handles funds or other property of an ERISA plan must be bonded under ERISA Section 412, 29 U.S.C. § 1112, in an amount not less than ten percent of funds handled, subject to a $1,000 floor and a $500,000 ceiling per plan, increased to $1,000,000 for plans holding employer securities (U.S. Department of Labor 2008). Sponsors must understand what this instrument does and does not do. The Section 412 bond responds to loss caused by acts of fraud or dishonesty committed by bonded persons, meaning insiders who handle plan assets. It does not respond to theft by an external hacker who never occupied a handling role. Regulatory guidance in 29 C.F.R. Part 2580 and Field Assistance Bulletin 2008-04 confirms the bond’s insider dishonesty orientation (U.S. Department of Labor 2008).
Three recommendations follow. First, sponsors should bond well above the statutory minimum where funds handled justify it, and should confirm the bond is written on an ERISA-compliant form naming the plan as insured, with no deductible as to plan losses, as the regulations require. Second, and most importantly, sponsors should procure computer crime, funds transfer fraud, and social engineering fraud riders or a standalone commercial crime policy extending to the plan, because these coverages, not the statutory bond, respond to external cybertheft and fraudulent instruction losses. Third, sponsors should verify that recordkeepers, custodians, and third-party administrators carry their own crime and cyber coverage with limits proportionate to assets under administration, and should obtain contractual indemnification and evidence of coverage annually, consistent with EBSA’s hiring tips for service providers (U.S. Department of Labor 2021; U.S. Department of Labor 2024).
Recommendations: Fiduciary Liability Coverage
ERISA Section 410(a) voids exculpatory provisions, but Section 410(b) expressly permits the purchase of fiduciary liability insurance (29 U.S.C. § 1110). Given the litigation trajectory described above, fiduciary liability coverage is no longer optional prudence; it is the fiduciary’s principal personal asset protection against cyber-related breach claims. Sponsors and committees should insist on the following. The policy should contain an affirmative grant, or at a minimum no exclusion, for claims alleging imprudent selection or monitoring of service providers with respect to cybersecurity, and any cyber or invasion of privacy exclusion should be negotiated out or narrowed to preserve coverage for breach of fiduciary duty claims arising from a cyber event. Limits should be stress-tested against aggregate account balances rather than premium comfort; a plan with several hundred million dollars in participant assets is not adequately protected by a $5,000,000 tower. The policy should include coverage for DOL and other regulatory investigations, including pre-claim inquiry costs, given the Department’s announced enforcement posture, and voluntary compliance program expenditures. Where the plan pays the premium, the policy must permit recourse against the fiduciary, or the fiduciary should personally pay the additional premium for a non-recourse waiver, in conformity with Section 410(b)(1). Finally, the fiduciary tower should be coordinated with the sponsor’s cyber liability program so that first-party breach response, forensic, and notification costs, which fiduciary forms do not cover, are addressed without gaps or disputed other insurance provisions.
Our Take
The DCCIC proposal deserves serious legislative attention because it addresses the residual, no-fault stratum of cyber loss that neither ERISA litigation nor private insurance can reach. But federal backstops arrive slowly, if at all. In the interim, the prudent architecture is layered: a properly sized ERISA fidelity bond for insider dishonesty, crime and computer fraud coverage for external theft, contractually verified service provider coverage, and a carefully manuscripted fiduciary liability program insulating the individuals who bear personal liability under Section 409. Fiduciaries who document adherence to EBSA’s cybersecurity guidance and maintain this coverage stack will have done what current law permits to protect both participants and themselves. Learn more and keep abreast of all things “ERISA” on our blog.
~ C. Constantin Poindexter, MA, JD, CPCU, AFSB, ASLI, ARe, AINS, AIS, CPLP
Bibliography
- Employee Retirement Income Security Act of 1974, 29 U.S.C. §§ 1104, 1109, 1110, 1112, 1144.
- Internal Revenue Service. 2025. Chief Counsel Advice 202511015. Washington, DC: Internal Revenue Service.
- Mandatory Victims Restitution Act of 1996, 18 U.S.C. § 3663A.
- U.S. Department of Labor, Employee Benefits Security Administration. 2008. Field Assistance Bulletin No. 2008-04: ERISA Fidelity Bonding Requirements. Washington, DC: U.S. Department of Labor.
- U.S. Department of Labor, Employee Benefits Security Administration. 2021. Cybersecurity Program Best Practices; Tips for Hiring a Service Provider with Strong Cybersecurity Practices; Online Security Tips. Washington, DC: U.S. Department of Labor.
- U.S. Department of Labor, Employee Benefits Security Administration. 2024. Compliance Assistance Release No. 2024-01: Cybersecurity Guidance Update. Washington, DC: U.S. Department of Labor.
- 29 C.F.R. Part 2580 (Temporary Bonding Regulations).
- Bartnett v. Abbott Laboratories, 492 F. Supp. 3d 787 (N.D. Ill. 2020).
- Disberry v. Employee Relations Committee of the Colgate-Palmolive Co., 646 F. Supp. 3d 531 (S.D.N.Y. 2022).
- Leventhal v. MandMarblestone Group LLC, No. 18-cv-2727 (E.D. Pa. 2019).








