Citizen Portal

Board hears cybersecurity briefing emphasizing member‑service risks and trustee responsibilities

5731945 · September 7, 2025

Summary

Linea Secure delivered a cybersecurity briefing for trustees and staff highlighting phishing, business email compromise, third‑party risk, and the need for trustee and staff training and incident playbooks.

Trustees received a cybersecurity briefing from Linea Secure designed to frame cyber risk as a governance issue that requires board oversight, not just IT operations.

Peter Zuer, president of Linea Secure, and Jake Long, senior consultant, reviewed common attack vectors—phishing and social engineering, ransomware, business email compromise and insider risks—and stressed how pension funds’ sensitive member data and large financial transfers make them attractive targets. They noted recent cases (anecdotal) in which threat actors compromised member mailboxes and attempted to redirect benefit payments and reiterated that attackers now routinely use AI to craft more convincing impersonation attempts.

Linea recommended trustees and staff adopt a layered approach: identify and catalog sensitive data and critical systems; protect with multi‑factor authentication, approved devices and safe networks; detect anomalous activity; maintain and exercise an incident response plan; and recover with clear communications to members and stakeholders. Presenters emphasized role‑based and frontline training (member services, call center staff) and suggested targeted simulations and data‑loss prevention tools for staff handling PII.

Trustees asked whether San Jose’s operating environment differs from other plans; presenters said ORS faces familiar risks (hybrid work, third‑party hosting of PensionGold and member portals) and recommended tailored governance and third‑party due diligence. Trustees also asked about cyber insurance trends; presenters said premiums have stabilized but underwriting rewards demonstrable security controls.

Staff and trustees discussed operational coordination with the City’s central IT and the city chief information security officer; presenters advised clarifying roles and having a documented incident playbook that covers emergency meeting protocols and interaction with city IT for large incidents.

Linea offered follow‑up assessments and targeted trustee training and recommended the board consider tabletop incident exercises and heightened third‑party due diligence for custodians and system vendors.

AI generated

The text on this page is AI generated. Summaries, highlights, analysis, and video transcripts are all produced from the original source material.

AI can make mistakes, so if you spot one, and we will fix it for everyone.

Note: the source content is unaltered by us. Any content source we link to, be it a video, an audio recording, or a document, is presented exactly as its publisher released it. That publisher is usually a government body, sometimes an individual official or another organisation.

Source