Cyber Insurance for TPAs: What Carriers Require in 2026
Underwriters stopped taking your word for it. Here is what your next renewal will actually test—and why it looks a lot like your DOL file.
The short answer: carriers now treat phishing-resistant MFA, endpoint detection and response, tested backups, and a written incident response plan as baseline requirements—and the underwriting question has shifted from do you have this control to can you prove it was enforced everywhere. For a TPA, that is the same evidence DOL examiners and plan sponsors ask for. Build it once; use it three times.
Three Parties Now Ask a TPA the Same Question
In the space of about eighteen months, retirement-plan administrators went from occasional security questionnaires to sustained scrutiny from three directions at once. The questions differ in framing but converge on the same artifacts.
| Who | What they ask | Evidence they accept |
|---|---|---|
| EBSA investigators | Can you show a documented cybersecurity program and its operation? | Policies, risk assessments, audit reports, access reviews, training records, IR plan (full checklist) |
| Plan sponsors & advisors | Is our participant data safe with you? | SOC 2 Type II or equivalent, security questionnaire responses, attestations (SOC 2 explained) |
| Cyber carriers | Are the controls you attested to actually enforced? | Configuration proof, coverage reports, backup test results, IR tabletop records |
The practical implication is efficiency: a TPA that assembles one well-maintained evidence file satisfies all three audiences. A TPA that assembles nothing faces all three unprepared—usually in the same year.
What Changed in Underwriting
The cyber market’s hard lesson from several years of ransomware losses was that application questionnaires are weak signals. Industry guidance published through 2026 consistently describes the same tightening: carriers moving from self-attestation toward verified controls (opens in new tab), with MFA coverage on email and remote access treated as a baseline expectation rather than a differentiator, and growing carrier interest in phishing-resistant methods rather than SMS codes.
Two consequences matter for TPAs. First, partial deployment is now a finding: MFA on email but not on the VPN, or EDR on workstations but not servers, reads to an underwriter as an unenforced control. Second, the attestation itself carries weight—representations made on an application can be examined closely after a claim, which is precisely why the gap between what a firm believes it has and what it can demonstrate deserves attention before renewal.
The TPA-Specific Wrinkles
Generic guidance misses several things about retirement-plan administration that underwriters increasingly probe:
- Funds actually move. A TPA touching distributions faces social-engineering and fraudulent-transfer exposure that a typical professional-services firm does not. The Transamerica incident—impersonation through a call center leading to unauthorized distributions—is the pattern carriers have in mind. Expect questions about identity verification and callback procedures for distribution requests, not just IT controls.
- Your vendors are your perimeter. Recordkeeper integrations, payroll bridges, and document vendors all touch participant data. The PBI MOVEit breach propagated through exactly this path. Vendor inventories and security reviews are underwriting material now, not just DOL practice #6.
- Seasonality is a risk factor. Compliance-testing season and Form 5500 deadlines concentrate operational pressure—the conditions under which staff click things they shouldn’t and recovery-time expectations become unforgiving. Firms that can articulate seasonal risk and staffing present better.
- Aggregation exposure. A single TPA can hold PII for tens of thousands of participants across hundreds of plans. Underwriters price that concentration, which makes documented encryption, segmentation, and immutable backups disproportionately valuable to your submission.
A Pre-Renewal Checklist
Roughly ninety days before renewal, work through this with whoever runs your IT—and be honest about the difference between deployed and enforced:
| Control | What “enforced” looks like | Proof to have on hand |
|---|---|---|
| Phishing-resistant MFA | Every account, every internet-exposed system—email, VPN, remote desktop, cloud admin, file shares | Coverage report showing enrolled accounts vs. total; exception list with justification |
| EDR / MDR | Every endpoint and server, actively monitored, alerts triaged by someone | Deployment coverage %, sample alert-to-response timeline |
| Backups | Immutable or offline copy, and a restore you have actually performed | Dated restore-test results with RTO/RPO achieved |
| Incident response plan | Written, current, exercised—with carrier notification steps in it | Plan document plus tabletop exercise notes from the last 12 months |
| Access management | Least privilege, quarterly reviews, prompt deprovisioning | Most recent access review; termination-to-deprovision timestamps |
| Security awareness training | All staff, with phishing simulation and remediation for failures | Completion rates and simulation results by quarter |
| Vendor oversight | Inventory of everyone touching participant data, with security review | Vendor register with SOC reports or attestations attached |
The Overlap Dividend
Every row above appears in DOL’s 12 cybersecurity best practices, and most appear in plan-sponsor due-diligence questionnaires. That is the strategic point: the work is not three separate compliance exercises but one operational discipline with three audiences. TPAIT builds and maintains this evidence continuously for clients—so renewal season is a document-retrieval task, not a fire drill. Score your current position with our DOL readiness checklist; the gaps it surfaces are, with few exceptions, the same gaps your underwriter will find.
One caveat worth stating plainly: coverage terms, exclusions, and application representations are legal and insurance questions specific to your policy. Your broker and counsel should review what your firm has attested—this article describes market conditions, not advice about your policy.
Common Questions
What do cyber insurance carriers require from TPAs in 2026?
Carriers now treat a baseline set of controls as non-negotiable: phishing-resistant multi-factor authentication across all email and remote access, endpoint detection and response, tested and segregated backups, and a written, exercised incident response plan. The significant change is evidentiary — underwriters increasingly want proof of enforcement across every account, not a checked box on a questionnaire.
Does DOL cybersecurity compliance help with cyber insurance renewal?
Substantially. The controls DOL's 12 best practices call for — documented security program, annual risk assessment, MFA and access controls, vendor reviews, training, encryption, tested business resiliency, and incident response — map closely onto what carriers underwrite. TPAs that build the DOL evidence file once can reuse it for renewals and for plan-sponsor due diligence.
What happens if a TPA can't prove a control it attested to?
It creates two exposures. Coverage disputes can arise when a carrier finds a control was not enforced as represented on the application, and misrepresentation on an application can jeopardize a claim. TPAs should confirm what was attested on their most recent application and verify it reflects reality — that review belongs with your broker and counsel.
Walk Into Renewal With Proof
A free assessment shows exactly which controls you can evidence today—and which ones would fail an underwriter’s follow-up question.
Book Free IT & Cyber Assessment (opens in new tab)