Cyber risk is no longer merely an emerging concern for pension schemes; it is now a pressing and immediate risk requiring action. UK pension schemes hold vast quantities of sensitive personal and financial data, making them a target for cyber criminals. The scale of the threat was brought into sharp focus by the Capita cyber security breach in March 2023, during which a ransomware attack compromised the personal data of approximately 6.6 million individuals held across over 300 pension schemes. In October 2025, the ICO fined Capita a combined £14 million for failing to implement adequate security measures. Research has also revealed a staggering 4,000% increase in data breach reports to the ICO from UK pension schemes in 2022/23 compared with the previous year and an increase in cyber incidents affecting pension schemes from 3% in 2019 to 17% in 2025. Against this backdrop, and with the Government's Cyber Security and Resilience Bill expected to be introduced to Parliament later this year, the regulatory expectation on trustees and scheme managers to take proactive steps has become increasingly explicit.
What does TPR expect?
The Pensions Regulator (“TPR”) has set out detailed guidance on cyber security principles for pension schemes, originally published in 2018 and most recently updated in December 2023, alongside revised administration guidance published on 9 December 2025 which places renewed emphasis on cyber resilience. The core message from TPR is that trustees and scheme managers remain accountable for the security of scheme data and assets, even where day-to-day administration is delegated to third parties.
TPR's guidance identifies several key areas which trustees should address:
-
Understanding of cyber risk
Schemes must understand their cyber footprint, map the digital presence of all parties involved in the scheme, identify critical functions and data holders, and assess the potential operational, financial and reputational impact of any cyber incidents.
-
Supply chain collaboration
There must be effective collaboration across the supply chain, with administrators, suppliers and service providers all maintaining robust cyber controls. However, governing bodies are ultimately responsible for ensuring that they appoint third party service providers with security measures capable of protecting scheme data.
-
Internal controls
TPR expects schemes to put in place internal controls to protect core systems and personal data, including multi-factor authentication, access controls, encryption, regular vulnerability scanning and penetration testing.
-
Incident planning
Schemes must have a documented and tested incident response plan covering roles, escalation procedures and recovery priorities.
-
Reporting
TPR has asked schemes to report significant cyber incidents on a voluntary basis, in addition to existing obligations to report data breaches to the ICO without undue delay (in any case, within 72 hours).
For a detailed analysis of TPR's revised administration and cyber guidance, see our earlier blog: Updated Administration and Cyber Risk Guidance from TPR.
Practical steps for trustees
For a detailed analysis of TPR's revised administration and cyber guidance, see our earlier blog: Updated Administration and Cyber Risk Guidance from TPR.
- Assess and document cyber risk: Cyber risk should feature prominently on the scheme's risk register and be reviewed regularly (at least annually). Trustees should ensure they have clearly defined roles and responsibilities for identifying, managing and responding to cyber threats.
- Review third-party arrangements: Given that many pension schemes outsource administration to third parties, scrutinising the cyber security arrangements of administrators and other suppliers is essential. This includes reviewing information security certifications, requesting internal controls reports and, where appropriate, issuing security questionnaires. Trustees should also ensure that their contracts with third-party administrators adequately address cyber risk, business continuity and data protection obligations. Our blog Protecting Pension Data: Reminders following the Capita Hack provides further guidance on the contractual and data protection considerations that apply when outsourcing scheme administration.
- Implement and test incident response plans: Every scheme should have a cyber incident response plan that is documented, communicated to all relevant parties and regularly tested through tabletop exercises. The plan should cover liaison with insurers, engagement of specialist advisers (legal, forensic IT and communications), communication to members and reporting to TPR and the ICO.
- Invest in training and awareness: Trustees and staff should receive regular cyber security training, including awareness of phishing, secure device use and reporting procedures. TPR encourages larger schemes to align with the National Cyber Security Centre's (NCSC) 10 Steps to Cyber Security, while smaller schemes should as a minimum consider the NCSC's small business guide.
- Maintain robust business continuity planning: Disaster recovery and business continuity plans should be reviewed annually and tested against realistic disruption scenarios, including cyber incidents, system failures and supplier interruptions. For further discussion of the broader cyber risk landscape facing pension schemes, see our blog: Cyber Risk in Pension Schemes: What Do You Need to Know?.
Looking ahead
With TPR's detailed guidance and the ICO's willingness to impose significant penalties for security failings, pension scheme trustees can no longer treat cyber risk as a purely technical matter to be left to administrators. It is a governance issue that demands active trustee engagement, proper resourcing and ongoing vigilance. If you would like to discuss how your scheme can strengthen its approach to data and cyber risk, please get in touch with Juliet Bayne, Martin Sloan, or your usual Brodies contact.
Contributors
Partner
2nd Year Trainee