Company pension schemes: An over-looked cyber-risk that boards can no longer afford to ignore

Company pension schemes: An over-looked cyber-risk that boards can no longer afford to ignore

October is Cybersecurity Awareness Month. As cyberthreats intensify, company pension schemes have emerged as a critical vulnerability – often falling outside core cybersecurity frameworks and attracting increasing attention from fraudsters. With risk and regulatory scrutiny rising, robust cyber-resilience is now urgent for pension trustees and their sponsors. Colin Gray, Strategic Engagement Lead at Aon, suggests that C-suite leaders must proactively assess their pension scheme protections and ensure rapid response capabilities to safeguard both operational stability and reputation.

Recent cyberincidents – such as the ransomware attack that disrupted operations at Heathrow Airport, the data breach affecting customer information at Marks & Spencer and the service outage at The Co-operative – have highlighted not only the immediate operational fallout, but also the critical importance of timely, transparent communication. How these organisations responded in the aftermath shaped public trust and demonstrated the need for robust incident management strategies.

These events serve as a stark reminder that the ability to withstand, react to and recover from cyberattacks is now central to organisational stability and reputation. As cyber-risk continues to evolve, leaders must ensure that their organisations are prepared to meet these challenges head-on, safeguarding both critical assets and stakeholder confidence in an environment where digital resilience is no longer optional, but essential.

In this context, resilience, reputation and responsiveness have become deeply interconnected. They form a continuous lifecycle spanning preparation (building resilience), reaction (demonstrating responsiveness) and recovery (safeguarding reputation). How an organisation prepares for, responds to and recovers from cyberincidents can significantly influence both its operational stability and any subsequent impact on trust.

The interplay of opportunity and risk

According to Aon’s Client Trends Survey, 2025, technology adoption is one of a number of mega trends. This represents both an opportunity and a risk for businesses – driving efficiencies in supply chains and HR administration, but, at the same time, creating ever broader exposure to cyberattacks, data breaches, etc. The survey also found that many business leaders find themselves facing challenges in attracting and retaining talent, managing rising workforce costs and ensuring employee wellbeing and against this backdrop, cyber is an emergent risk. Workforce instability, rising costs and employee wellbeing issues amplify vulnerabilities and reduce organisational capacity to prevent, detect and respond to attacks. As businesses digitise more processes to cope with these challenges, their exposure to cyberthreats grows, making cyber-risk a critical concern.

The survey’s findings suggest that the interplay between tech adoption and workforce management is now a defining challenge for business leaders. While Digital Transformation can unlock new value, it requires a holistic approach – balancing innovation with robust cyber-risk management and a focus on people.

Company pension schemes: An often over-looked source of risk

Company pension schemes, in particular, represent an Achilles heel for many organisations. These schemes are frequently managed as separate legal entities, meaning that they may fall outside the direct scope of a business’s cybersecurity framework. As a result, pension schemes often receive less scrutiny and investment in cyberprotections, leaving them vulnerable to attack.

This vulnerability was starkly highlighted when, in early 2023, one of the UK’s largest pension administrators suffered a significant cyberbreach that exposed the sensitive personal and financial information of thousands of pension scheme members. The attack not only disrupted administrative operations but also raised serious concerns about data security and the adequacy of cyber-risk management in outsourced pension services.

As a result, cyber-resilience is now one of the most urgent challenges facing pension schemes. The highly sensitive personal and financial information these schemes hold about their members makes them an attractive target for cybercriminals seeking to commit fraud or identity theft. Recent news stories demonstrate an increase in the incidence of targeted attacks on pension funds, as criminals seek to exploit gaps in oversight and potentially outdated security measures.

Regulatory bodies have taken notice. The Pensions Regulator has explicitly highlighted cyber-risk as a priority, requiring trustees and sponsors to strengthen their defences and ensure robust incident response plans are in place. This regulatory focus reflects the growing recognition that a breach could have devastating consequences – not just for scheme members, but also for the sponsoring employer’s reputation and financial stability.

October is Cybersecurity Awareness Month – a global initiative dedicated to promoting best practices in cybersecurity – and now is the time for C-suite leaders to act. Senior executives should proactively engage with their pension scheme trustees and administrators, asking probing questions about existing cyberprotections, incident response procedures and areas of potential vulnerability. This is also an opportunity to identify and address other Achilles heels within the organisation’s broader risk landscape.
For example, asking where, in your outsourcing arrangements, does the reputational risk stay with you? In the context of outsourced pension scheme administration, the reputational risk inherent in doing so firmly stays with the business. Not only that, but there are layers to it. Firstly, if you choose a pensions administrator who gets hacked, it may reflect poorly on your judgment and oversight. Additionally, if you don’t have a backup plan to respond and reassure people in case of a hack, it might suggest your risk management processes are inadequate.

By taking these additional steps, leaders can gain confidence that their organisation is not only compliant with regulatory expectations, but also well-positioned to respond quickly and effectively to any cyberincident. In today’s threat environment, getting a head start on cyber-resilience isn’t just good practice – it’s essential for protecting both the organisation’s asset

Browse our latest issue

Intelligent CXO

View Magazine Archive