Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Voya tells St. Mary's County committee how it detects account fraud, urges longer passphrases and multifactor
Summary
Voya representatives outlined the company’s layered cybersecurity program, participant-facing safeguards and fraud‑detection tools, and recommended account hygiene steps for plan participants.
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Charles Griffin, a member of Voya’s cybersecurity unit, told the St. Mary's County governance committee on Feb. 27 that Voya separates enterprise cybersecurity work from account‑level fraud monitoring and uses machine learning to detect suspicious transactions. “We have another team of people using a lot of the same data from the same tools, but in a different way, solely dedicated to watching transactions to participants' accounts, looking for indicators of fraud, and intercepting that,” Griffin said.
The presentation, given to the governance committee by Voya representatives identified in the meeting as Sarla (Voya presenter) and Charles Griffin (cybersecurity unit), framed protection in three layers: an enterprise security program, participant education and account‑level transaction monitoring. Griffin summarized industry and agency guidance cited in the presentation, saying the U.S. Department of Labor issued guidance for retirement recordkeepers on April 21, 2021, and Voya has mapped its program to those recommended components.
Griffin described common attack vectors and practical steps participants should take. He said phishing remains the leading cause of enterprise compromises, citing an industry statistic: “phishing is still the number 1 attack vector of any enterprise,” and noted that Voya monitors click‑through rates on test phishes and encourages reporting of suspicious messages. He recommended three participant practices: use a unique username that is not a personal email address, adopt a long passphrase (he cited guidance that longer passwords are preferable), and register a mobile phone number for multifactor authentication because personal email accounts can be exposed on the dark web.
On detection and response, Griffin described Voya’s fraud‑detection system, which scores transactions using geolocation, IP and routing data, keystroke timing and behavioral signals. He gave an example of a flagged transaction: a participant who attempted to move a bank account 1,200 miles away and who logged in at an unusual hour would generate a high risk score and trigger a human review. “These people have backgrounds in things like law enforcement, banking, AI, of course, mathematics, and they will lock the account if they believe it's been a compromise and they'll reach out to the participant,” Griffin said.
Griffin also described enterprise controls: Voya maintains SOC 1 and SOC 2 attestations and ISO 27001 certification, runs phishing campaigns across its employee population, and maintains immutable backups to mitigate ransomware. He discussed use of machine learning in anti‑fraud systems and in customer‑facing chatbots that handle routine inquiries.
Committee members asked clarifying questions and praised the practical tips. Catherine Pratsen, director of human resources, said she was taking notes for internal employee communications. The presentation concluded without formal action; Voya staff provided slides to committee members via the board packet.
Why it matters: retirement plan account compromises can directly harm participants’ finances and the county’s fiduciary standing. The committee received both technical explanation of Voya’s detection tools and specific, participant‑level recommendations the county can pass along to employees.
Looking ahead: Voya offered materials and said it can target communications to participants who have not registered accounts so the county can encourage the security steps recommended in the presentation.

