Skip to main content Scroll Top

Trustees: Here’s how to comply with the Joint Standard

  • Home
  • Cybercrime
  • Trustees: Here’s how to comply with the Joint Standard

Cybersecurity may seem overwhelming for the majority of retirement fund trustees, but understanding and applying the Joint Standard are essential for protecting members’ savings. While trustees don’t need to be technical experts, they must oversee compliance, ask the right questions, and ensure their service providers are equipped to guard and mitigate against cyber threats.

Addressing your fund’s cybersecurity can feel overwhelming. Even understanding the Joint Standard 2 of 2024: Cybersecurity and Cyber Resilience is a big task on its own.

But don’t worry, you’re not expected to become a cybersecurity expert. As a trustee, your job is to make sure your fund and its service providers are doing what’s required to keep members’ data and savings safe. Think of it as eating an elephant: you do it one bite at a time. So, let’s break your role down into manageable steps.

Step 1: Get your board ready

Not all trustee boards have the same level of computer knowledge. One of the first steps is to assess how comfortable each trustee is with computers and cybersecurity topics. Then, if needed, bring in an cybersecurity expert to help with training.

In order to understand the Joint Standard and what it requires of retirement fund trustees, it’s essential that every trustee:

  • has basic computer skills; and
  • understands what cybersecurity is.

Action points:

□ Read through the Joint Standard. Highlight and note any terms or concepts you don’t understand.

□ Assess your board’s level of computer and cybersecurity knowledge and invest in basic computer and cybersecurity training, if necessary.

□ Hire a qualified cybersecurity expert and legal advisor to help with Joint Standard compliance.

Step 2: Understand where the risks are

Most of the fund’s sensitive data lies with your administrator, not the trustees. This means the administrator is mainly responsible for putting cyber protections and safeguards in place. But trustees must still oversee and monitor that everything is being done properly by their administrator or any other service provider.

Key questions to ask:

□ Do your administrator and service providers comply with the Joint Standard?

□ Do they have a cybersecurity strategy?

□ How secure are their systems – do they have cybersecurity experts assisting them?

□ How much cybersecurity and awareness training have their employees undergone and is there ongoing training?

□ What steps do they take to protect and safeguard fund information?

Step 3: Control who has access

Different employees of an administrator have levels of access to different types of information. Some may see only members’ names and addresses, while others process retirement payouts. There must be clear access rules, proper controls to prevent fraud, and extra controls  for large transactions.

Key questions to ask:

□ Are strong, unique passwords used for fund accounts?

□ Is multi-factor authentication (MFA) in place?

□ Is access to data limited by job role?

□ Are user permissions reviewed regularly?

□ Do large transactions need a second or third person’s approval?

□ Are there limits in place for large fund transfers?

□ Are transactions monitored for suspicious activity?

□ Is the uploading of new members properly authenticated through different checks and balances?

□ Are there regular checks for ‘ghost members’ (persons who appear on the fund’s membership records but should not actually be there)?

What is Multi-Factor Authentication (MFA)?

MFA is like having extra locks on your account. Instead of just a password, you also need a second or third step or “factor”  (like a code sent to your phone or email address, your fingerprint, or facial recognition). Even if someone steals your password, he or she can’t get in without these extra “keys.”

Step 4: Check how data is stored

Your fund’s data is likely stored either on a server or in the cloud. The administrator must protect these systems and have backup plans in place if something goes wrong.

Key questions to ask:

□ Are the servers securely configured and is this verified regularly?

□ Is sensitive data encrypted when stored or sent?

□ Is data stored on secure, password-protected servers?

□ Are there secure, off-site backups?

□ Are access to and use of fund documents tightly controlled?

Step 5: Plan for when things go wrong

Even with the best defences, cyberattacks can happen. That’s why your fund needs a plan in place to respond quickly and effectively.

Work with your administrator to:

  • Develop a cyber incident response plan.
  • Test the plan and its effectiveness regularly.

Make sure everyone knows his or her role during a cyber crisis.

What is FraudGPT?

FraudGPT is an AI tool used by cybercriminals to create fake emails, documents, and messages. These scams look very real and can fool even smart people. FraudGPT can even create deepfake videos and automate phishing attacks. That’s why trustees must stay informed and alert.

Step 6: Secure Communication

Cybercriminals target everyone—trustees, members, and administrators. Make sure your board and members are trained to spot scams and know how to respond.

Steps to take:

□ Use official fund email addresses—not personal ones.

□ Be cautious of emails asking for financial or personal information.

□ Train trustees and members to spot phishing emails and scams.

□ Always confirm requests for money or data with a phone call or in person.

□ Keep your team updated on common fraud tactics.

□ Subscribe to a cyber threat alert or news service.

□ Make sure everyone understands their legal duties under POPIA, PAIA, PFA and other applicable legislation.

Fighting cybercrime is a team effort. As a trustee, you play a key oversight role. You don’t need to know everything about cybersecurity, but you do need to ask the right questions, insist on good practices, and keep learning. That’s how you protect members’ savings, and fulfil your duties with confidence.

To learn more about cybercrime, check out the Cybercrime Learning Lab. Or if you would like more in-depth knowledge, Atleha-edu and the ASISA Academy offer workshops on cybersecurity and other themes for South African trustees and members of retirement funds.

Sources

Moonstone: Two-pot retirement system: a new playground for cybercriminals as FraudGPT fuels the threat

Funded by

Hi there, we can't wait to share our content with you. Please help us send you information that is most relevant to you.