A] Prelude
For more information on pension systems, risk and coverage, feel free to visit our dedicated webpages:
- https://expatpensionholland.nl/global-pillars-systems
- https://expatpensionholland.nl/global-investments-risks-0
- https://expatpensionholland.nl/global-social-security-coverage
For even more information about this topic feel free to visit the following external sites:
- https://www.thepensionsregulator.gov.uk/en/document-library/corporate-information/ai-plan
- https://www.pensions-pmi.org.uk/resources/cyber-security-helping-pension-schemes-go-beyond-the-tick-box/
B] The Issue
As a potentially high impact risk that should be monitored on an ongoing basis, cyber security and business continuity is an area that the UK Pensions Regulator (TPR) regularly refers to in its updates, statements and guidance. This trend has continued in the recent publication of TPR’s Annual Funding Statement 2026 and Annual Report and Accounts.
C] The Details
Cyber risk was a key area of focus for TPR following its Annual Report and Accounts 2024/25. In last year’s Report and Accounts, one of the few areas where TPR recognised that it needed to further enhance its processes was cyber security, with last year’s report stating that cyber risks and pensions technology in the pensions sector was the only “KPI target missed by [a] significant degree” at that time.
This year’s Annual Report and Accounts (2025 to 2026) demonstrate that progress has been made, with zero KPI targets missed by a significant degree this year. With regards to embracing data, digital and technology, the Report states that TPR has “made progress in modernising [its] internal systems through the development of platform teams supporting case management and data services, alongside improvements in data governance, cyber resilience, access management, AI and master data management.”
With regards to improving system hygiene, TPR “has modernised core systems, strengthened cyber resilience, and positioned TPR for more efficient and sustainable delivery in 2026-27 and beyond.”
D] Enterprise Risks
TPR recognises the following enterprise risks relevant to cyber security in the Report:
I. That is that it is unable to use its core systems because of a cyber-attack. An update on this risk including details of key mitigations is “TPR operates in an environment of heightened and evolving cyber threat, primarily driven by sophisticated threat actors, increasing complexity and emerging technologies.
A diverse set of controls has been implemented, following international standards and best practice. While this risk remains outside appetite, good progress has been made in strengthening our controls with further improvements to be delivered next year.”
II. That members suffer financial losses or disruption in payments due to cyber-attack in the sector. An update on this risk including details of key mitigations is “We continue to assess the risks of cyber-attack for schemes and are working with experts to understand the risks to members as well as closely monitoring how we align with other government bodies and industry partners. The prevailing heightened cyber risk environment means this risk remains outside appetite.”
Here, as in so many areas, TPR leads by example - cyber risk is an area that should be on risk registers for all pension schemes and regularly monitored. The key to building cyber resilience is progress, not perfection.
This is more relevant than ever in light of the increased risk of AI-enhanced cyber-attacks. This update from Aon refers to CrowdStrike analysis which found that AI-enhanced phishing emails have shown click-through rates of 54%, compared with a 12% click-through rate for traditional phishing attacks. A rather alarming increase!
E] TPR Annual Funding Statement 2026
TPR also recently released its Annual Funding Statement 2026. Whilst it only mentions cyber once, the update from TPR is an interesting one, reading: “The potential impacts from cyber incidents, have become an area of increasing concern for trustees and employers. These issues can materially impact the employer covenant through impacts on their business activities, operations and supply chains. We expect trustees to monitor these risks, with the frequency and depth of monitoring proportionate to the circumstances of the employer and the scheme.”
Interestingly, TPR highlights cyber incidents as a covenant issue. Many trustees have been focussing on assessment of their third-party suppliers, which is necessary as supply chain risk is a key risk area for pension schemes. However, trustees should not forget to look closer to home and ask questions of their sponsor to understand their cyber resilience position as well.
It is absolutely the case that if a scheme sponsor suffers a serious cyber incident then, as we have seen from various examples in the press over the last few years, that can have hugely significant ramifications on a sponsor’s business, which could in turn have implications for the strength of the pension scheme’s employer covenant.
F] Key Takeaways
Both of these TPR publications indicate a continued need for pension schemes, trustees and pensions professionals to consider cyber resilience on an ongoing basis.
Key takeaways include:
- Cyber risk is an area that should be on risk registers for all pension schemes and regularly monitored. The key to building cyber resilience is progress, not perfection.
- TPR highlights cyber incidents as a covenant issue. Trustees should not forget to ask questions of their sponsor to understand their cyber resilience position. It is absolutely the case that if a scheme sponsor suffers a serious cyber incident then that can have hugely significant ramifications on a sponsor’s business, which could in turn have implications for the strength of the pension scheme’s employer covenant.
G] EIOPA’s Policy
As EPH we are always interested to see what the EU’s regulatory pension and insurance authority called EIOPA has to say about an issue and what their policy is.
Regarding Pensions & Cyber Risk, feel free to check their following links:
- https://www.eiopa.europa.eu/eiopa-insurance-risk-dashboard-shows-broadly-stable-risk-environment-even-cyber-and-geopolitical-2026-07-30_en
- https://www.eiopa.europa.eu/eiopas-risk-dashboard-occupational-pension-funds-highlights-persistent-market-risks-amid-2026-07-30_en
(Sources: Burges Salmon/EPH/EIOPA)
