PASA issues new guidance on strengthening data management and cyber resilience
The Pensions Administration Standards Association (PASA) has published new guidance, ‘Securing Tomorrow: Essential Steps for Trustees and Pension Providers to Protect Member Data’, designed to reinforce data security and governance within pensions administration. The guidance covers areas such as cyber resilience, third-party oversight, secure communications, and responsible AI usage, offering practical recommendations for trustees and providers to counteract rising digital risks, including the implementation of role-based access controls and multi-factor authentication. The new guidance advocates for regular security reviews, the formulation of incident response plans, and proactive preparation for risks associated with emerging technologies such as AI. It aims to provide a vital toolkit for strengthening data management at a time of growing digital risk. The guidance is aligned with the Pensions Regulator's cyber security guidance and the National Cyber Security Centre's10 Steps to Cyber Security; all aimed at strengthening cyber resilience and data security practices across the pensions sector.