Pensionsage Third-Party Cyber Risks Alarm DB Pension Trustees
Article Content
- •70% of DB pension trustees identify third-party vulnerabilities as major cyber risks.
- •Less than half of trustees regularly test their incident response plans.
- •78% of trustees are on track for the 2026 Pensions Dashboard deadline, but 16% may struggle.
A recent survey by Howden Retirement reveals that 70% of Defined Benefit (DB) pension trustees consider third-party vulnerabilities as significant cyber risks. Half of the trustees also express concerns about the security of member data. While 70% of trustees regularly assess third-party cyber risks, less than half (44%) test their incident response plans through simulations. The report indicates that as the 2026 Pensions Dashboard deadline approaches, cybersecurity vulnerabilities are increasingly coming to light. Although 78% of trustees believe they are on track to meet the deadline, 16% warn they may struggle. Alex Pocock, Managing Director of Howden Retirement, emphasized the need for confidence in both internal and external cybersecurity measures to protect member data and minimize disruptions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Common questions
What are the main concerns for DB pension trustees?
How prepared are trustees for cyber incidents?
What is the significance of the 2026 Pensions Dashboard deadline?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…