Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
Pension board approves $10,000 vendor cybersecurity assessment
Summary
Edgewater Firefighter Pension Board approved a one-time cybersecurity vendor risk assessment using FoxPoint-style questionnaires to document vendor diligence and reduce fiduciary exposure; the quoted initial cost was $10,000 and staff will report back when vendors respond (estimated 45–60 days).
Get email alerts on the Cybersecurity topic
No spam. Unsubscribe anytime.
The Edgewater Firefighter Pension Board voted to approve a cybersecurity support program designed to assess and document the cyber hygiene of the plan’s service providers.
Doug Lowesen, an actuary introduced by Foster & Foster, told trustees the recommended survey mirrors an annual exercise used by private Taft‑Hartley plans and would interview vendors across about a dozen categories, roughly 30 questions in total. “We recently acquired an actuarial firm of about 50 actuaries…Taft Hartley plans have to go through and exercise annually regarding cyber insurance because the Department of Labor says you have to,” Lowesen said, arguing the assessment would put trustees in a stronger fiduciary position if a breach occurred.
Lowesen said the board’s consultant had sourced FoxPoint Solutions to deliver the questionnaire and compile a report. He said the firm quoted $10,000 as the lowest feasible fee for the initial assessment and that fee covers follow-up work with vendors if areas of concern are found. “You would get this report back from FoxPoint…Ideally, everybody’s green, but to the extent there’s yellows or reds of some concern, you would be asking FoxPoint how can we ask this vendor to fix things up,” Lowesen said.
Trustees asked about budget impacts and timing. Staff reported there is budget capacity and that any needed budget amendment could be handled at the next meeting. Lowesen estimated vendor response and report assembly would likely take 45–60 days and said the board could reasonably expect results by December or possibly before the next meeting in September.
A trustee moved to approve the cybersecurity support program “as presented”; the motion was seconded and the board approved the measure by voice vote.
The board also discussed related insurance coverage and staff follow‑up: Jones Walker counsel advised that cyber liability commonly appears as a rider to fiduciary liability policies and that a separate cyber policy can be obtained at relatively low additional cost. Staff said they will circulate a sample report from the vendor for trustees to review and will keep the board informed on timing and next steps.
