Pages

Thursday, October 28, 2010

Four Security Best Practices That All Advisors Should Implement

Common sense security will make your firm a tough target for hackers

Advisor One
October 1, 2010 | By Dan Skiles
When you think about the security around your technology systems and your firm's data, what level of confidence do you have? … Unfortunately, the bad guys are out there, and they are working overtime to find ways to break in and grab your precious information. … You might also be surprised at how unfamiliar your staff is with security threats related to technology. … We all get comfortable when we use technology every day, and we sometimes (if not often) forget or simply ignore important security best practices. Education in this area is critical, and it is important that everyone at your firm understands their role in protecting your technology systems and data.
It would be best for most advisors to hire an IT professional--someone who worries about data security 24/7--to be responsible for protecting your systems. … Whether you have an IT professional or not, there are a number of best practices that you and your staff should follow in order to better protect your systems and your client data. A number of the best practical steps you can take are simple and basically common sense, but they need to be adopted across an entire firm.
This is a screenshot of windows password unloc...Image via WikipediaOne of the more common security oversights with advisors and their associates is transmitting personally identifiable information through e-mail. Standard e-mail is not secure and the information transmitted can be intercepted by a hacker. This includes information in the body of an e-mail, as well as any attachments (Excel files, Word docs, PDFs, etc.). If you must send an e-mail with personally identifiable information, it is best to encrypt it and assign a password to the attached file. …[There] are a number of password recovery software programs available that essentially try different combinations over and over until the password is identified. In the very rare case that your e-mail is intercepted by a hacker, you certainly don't want to make it easy for them by creating a password that is simple and quick to identify. The word "password" is unfortunately probably the first word that they will try, because it is the most commonly used password.
[Read more about why you should enable passwords on your mobile devices.]
Another important security best practice is to have a strict policy that prohibits your staff from using computers that they do not own or control for accessing networks that contain confidential client information. For example, … a hotel's business center … computer could contain a malware program, specifically a "keystroke logger," that tracks every keystroke and page visited on the computer. With these programs, it is possible for a hacker to obtain your user name and password and the exact Web address that the credentials are used for. Of course, the hacker could then use this information and log in as you. This risk is magnified when you consider the number of accounts that you could have access to when using your log-in credentials on the sites that house your clients' account information. …
…[Do] you know the level of access each member of your firm has to your technology systems, as well as to the external technology systems used by your firm? … [The] security best practice is to only give each associate the level of access that they truly require for their position. …
It is worth the initial time to set up different access profiles in order to better control and further secure your firm's client information. Make sure that you have a well-defined process to disable an associate's access when they are no longer employed by the firm. This process should be implemented on the same day that the associate leaves the firm.
[Read about the benefits of using a server rack to protect your physical investments.]
Another key security practice for your firm revolves around understanding how your systems are protected from virus attacks. Everyone at your firm must understand what virus software is installed on the computers they use and how the software behaves. One of the easiest ways for a hacker to infect your systems is through a counterfeit "alert" message. What generally happens is this: While you are navigating the Internet a pop-up message appears on your screen and says, "Warning! Your computer is infected by a virus. Click here to correct." Then, when you click on the "OK" button, instead of solving the problem, you are actually downloading the virus. But if your staff is familiar with the way your virus software works, they will know that the fraudulent alert message is very different from the one they would receive from the real anti-virus program. … Anti-virus programs are constantly being updated, but the challenge is keeping up with the introduction of new viruses. Therefore, instruct your staff to be suspicious, and to become familiar with the anti-virus program operating on their computer, especially the alert messages.
Overall, following security best practices needs to be part of the DNA of your firm. It is important that your staff does not have the false impression that technology security is not one of their job responsibilities. … Therefore, you must make security procedures a part of your regular training, and practice them until they become habits. Security problems by themselves can create a tremendous amount of work, and of course they carry potential financial and reputational risk, as well. Therefore, it is worth the effort to ensure that your firm is doing everything possible to protect your clients and your overall business. …
Enhanced by Zemanta

Stress Makes Some Wary of Using Vacation

October 27, 2010 (PLANSPONSOR.com) – More than half of those in a new survey say they are too worried and busy to take all their vacation days.

Taken by SimonP in August 2005Image via WikipediaA news release from Westin Hotels & Resorts about its vacation days poll said 58% of respondents feel they are in more need of vacation than last year, and 64% have canceled vacation due to work worries.
According to the news release, more than 67% feel healthier on vacation, while 64% sleep better while taking some time off. More than half feel taking vacation contributes to a stronger marriage. Forty-eight percent of respondents said they are happier in their workplaces after a vacation.
Thirty percent of respondents said that while on vacation they check in with work every day, and 25% said they check in every hour. More than two-fifths (41%) indicated they usually require three to four days to unwind on a vacation.
The Westin Hotel at Los Angeles International ...Image via WikipediaCommissioned by Westin Hotels & Resorts, the study is based on a survey conducted by STUDYLOGIC LLC via telephone of approximately 1,500 American adults who are professionally employed.
The hotel company said it has developed a Web site with more information about the advantages of using vacation time at http://www.travelandbewell.com/
Fred Schneyer
editors@plansponsor.com
Enhanced by Zemanta

Tuesday, October 26, 2010

Sixty-percent of workers miss out on their full lunch break

Employee Benefit News
Attendees break for lunch.Image via WikipediaIs lunch time a sort of "witching hour" to workplace wellness? Employers already have a hard time ensuring workers have access to healthy lunchtime meals and snacks. Now, a new poll shows many workers fail to take a full lunch break.
Like what you see? Click here to sign up for Employee Benefit News daily newsletter to get the latest news and important insight into trends in benefits management.
"Taking a lunch break is very important to keep healthy and refreshed," says Jeffrey Quinn, senior director, Monster Intelligence. "Our bodies and brains need fuel to operate and many workers actually find they are more productive after some time spent away from their desk. If people feel they are too busy, they should take stock of their workload and try to plan it into their day," he adds.
Monster, the job matching Web site, recently conducted a poll that showed 60% of workers do not take their full lunch break. Of those surveyed, 7% admitted they do not take a lunch break at all.
The online poll asked participants: “Do you take a lunch break while at work?” Here is a breakdown of the responses:
  • Yes, I always take my full lunch break – 40%
  • Sometimes, only if I’m not too busy – 32%
  • No, I always eat at my desk so I can get more work done – 21%
  • No, I don’t eat lunch - 7%
Lunch break (after Millet)Image via WikipediaWhen examining the numbers through an international lens, Monster found workers in the United States were least likely to take their full lunch break, compared to workers in other countries.
For example, Europeans were more likely to take their full lunch break (49%), with 58% of French workers reporting they use the entire time and 48% of Italian workers admitting the same. Forty-eight percent of Indian workers also said they take advantage of the full time, while 45% of Asian workers said the same, according to the survey.
No surprise here, but workers brought their lunches back to the office, with nearly 30% of U.S. workers reporting they eat lunch at their decks, followed by 26% of Canadians and Belgium workers doing the same.
Yet only 8% workers in Mexico and 9% in Italy said they eat lunch at their desks, according to the survey, which was conducted in June 2010 and involved 17,967 participants.
Enhanced by Zemanta

Friday, October 22, 2010

DoL Broadens Fiduciary Net

The seal of the United States Department of Labor.Image via WikipediaOctober 21, 2010 (PLANSPONSOR.com) – For the first time in a generation, the Labor Department has taken another crack at the definition of a fiduciary under the Employee Retirement Income Security Act (ERISA).
The proposed rule was unveiled today by the Department of Labor (DoL), which noted that its adoption “would protect beneficiaries of pension plans and individual retirement accounts by more broadly defining the circumstances under which a person is considered to be a ‘fiduciary’ by reason of giving investment advice to an employee benefit plan or a plan’s participants.”
The proposed rule is designed to “take account of significant changes” in both the financial industry and what was described as “the expectations of plan officials and participants who receive investment advice,” as well as to protect participants from “conflicts of interest and self-dealing.”
Testing, Tested
Logo of the United States Department of LaborImage via WikipediaIn explaining the proposal, the Labor Department noted that while Section 3(21)(A) of ERISA provided a “simple two-part test for determining fiduciary status,” a subsequent (1975) regulation served to “significantly narrow” the “plain language” of the legislation; effectively replacing the two-part test that would impose fiduciary status when a person renders investment advice with respect to any moneys or other property of a plan, or has any authority or responsibility to do so and receives payment (direct or indirect) for that advice, with a 5-part test that included conditions that: the advice regarding plan investments be rendered “on a regular basis,” that the advice would serve as a primary basis for investment decisions with respect to plan assets, that the recommendations are individualized for the plan, that the party making the recommendations receives a fee for such advice, and that it be pursuant to a mutual understanding of the parties. Moreover, the Labor Department noted that it further limited the definition of “investment advice” in a 1976 advisory opinion, when it concluded that the valuation of closely-held employer securities in an employee stock ownership plan (ESOP) relied on in purchasing those securities would not constitute investment advice.
…[The] Labor Department noted that the financial marketplace and the types and complexity of services have expanded dramatically. The proposal notes that although professionals such as consultants, advisers, and appraisers “…significantly influence the decisions of plan fiduciaries, and have a considerable impact on plan investments,” if they are not deemed fiduciaries under ERISA “…they may operate with conflicts of interest that they need not disclose to the plan fiduciaries who expect impartiality and often must rely on their expertise, and have limited liability under ERISA for the advice they provide.”
In essence, the Labor Department now says that ERISA does not compel it to apply its own five-part test, and that new facts and circumstances mean it is now time to update the investment advice definition. Specifically cited is that the proposal no longer requires that the advice be provided on a “regular” basis, not does it require that there be a mutual understanding that the advice will serve as a primary basis for plan investment decisions. [emphasis added']
Advice Description
As for what constitutes advice, the proposal now includes the provision of appraisals and fairness opinions as a type of advice [emphasis added], noting that the incorrect valuation of employer securities was a “common problem” identified in the DoL’s recent national enforcement project, including cases where plan fiduciaries have “reasonably relied on faulty valuations prepared by professional appraisers.” The proposal also makes specific reference to advice and recommendations as to the management of securities and other property, including such things as voting proxies or recommendations regarding the selection of persons to manage plan investments.
Finally, in what was described as reflecting “the Department’s longstanding interpretation of the current regulation,” the proposal makes clear that fiduciary status “may result from the provision of advice or recommendations not only to a plan fiduciary, but also to a plan participant or beneficiary.” [emphasis added]
Distribution Advice
The proposal notes that while the DoL has previously taken the position that a recommendation to a plan participant to take a permissible plan distribution would not constitute investment advice, even when combined with a recommendation as to how the distribution should be invested, “[c]oncerns have been expressed that, as a result of this position, plan participants may not be adequately protected from advisers who provide distribution recommendations that subordinate participants’ interests to the advisers’ own interests.” As a result, the Labor Department is now seeking comment “on whether and to what extent the final regulation should define the provision of investment advice to encompass recommendations related to taking a plan distribution.” [emphasis added] The proposal notes that the agency is specifically interested in:
  • information on other laws that apply to the provision of these types of recommendations,
  • whether and how those laws safeguard the interests of plan participants,
  • the costs and benefits associated with extending the regulation to these types of recommendations.
The proposal says that the definition of advice does not include “the preparation of a general report or statement that merely reflects the value of an investment of a plan or a participant or beneficiary, provided for purposes of compliance with the reporting and disclosure requirements,…unless such report involves assets for which there is not a generally recognized market and serves as a basis on which a plan may make distributions to plan participants and beneficiaries.” [emphasis added]
Other Points
The proposal says that the DoL believes that explicitly claiming ERISA fiduciary status, orally or in writing, is sufficient to result in fiduciary status, if provided for a fee (in that it “enhances the adviser’s influence, and gives the advice recipient a reasonable expectation that the advice will be impartial and prudent”).
Consistent with existing regulations, the proposal acknowledges that the provision of investment education materials (plan information, general financial and investment information, asset allocation models, and interactive materials) would not be deemed advice.
The proposal notes that the “marketing or making available” investments or an investment menu (e.g., through a platform or similar mechanism) “without regard to the individualized needs of the plan, its participants, or beneficiaries…will not, by itself, be treated as the rendering of investment advice within the meaning of section 3(21)(A)(ii) of ERISA”—if the person making those investments available “discloses in writing to the plan fiduciary that the person is not undertaking to provide impartial investment advice.” Additionally, the provision of information and data to assist a plan fiduciary’s selection or monitoring of investments isn’t deemed to be rendering advice “if the person providing such information or data discloses in writing to the plan fiduciary that the person is not undertaking to provide impartial investment advice.”
The proposal does set aside some limitations, exempting from the fiduciary umbrella persons that can demonstrate that the advice recipient “knows or, under the circumstances, reasonably should know, that the person is providing the advice or making the recommendation in its capacity as a purchaser or seller of a security or other property, or as an agent of, or appraiser for, such a purchaser or seller, whose interests are adverse to the interests of the plan or its participants or beneficiaries, and that the person is not undertaking to provide impartial investment advice.” [emphasis added]
Finally, noting that a necessary element of fiduciary status is that the advice be rendered for a fee or other compensation, the proposal states that that includes, but is not limited to, “brokerage, mutual fund sales, and insurance sales commissions,” [emphasis added] and that it includes fees and commissions based on multiple transactions involving different parties.
Effective Dates
The proposal is set to take effect 180 days after publication in the Federal Register tomorrow, but the Labor Department is first seeking comments on the proposal. The comment period for the proposed regulations will end 90 days after publication of the proposed rule in the Federal Register. That means that the comment period will end January 20, 2011. Comments can be submitted electronically by e-mail to e-ORI@dol.gov (enter into subject line: Definition of Fiduciary Proposed Rule) or by using the Federal eRulemaking portal at http://www.regulations.gov/.
The DoL notes that persons submitting comments electronically are encouraged not to submit paper copies. More information on paper submissions is available (along with the proposal itself) at http://www.ofr.gov/OFRUpload/OFRData/2010-26236_PI.pdf
Judy Ward
editors@plansponsor.com
Enhanced by Zemanta

Thursday, October 21, 2010

Just Out of Reish - Too Safe Is Too Bad

PLANSPONSOR.com

Safe investments may not be safe…for fiduciaries
…For fiduciaries, safe means that they are protected from lawsuits either because they complied with the law or because they have a legal safe harbor. Safe—for most participants—means an investment that has very little, if any, volatility. In the investment world, volatility measures how much the value of an investment fluctuates. For example, stable value or money market accounts are intended to have a fixed principal that does not fluctuate in value.
Another important definition is time frame. When the market is highly volatile, …people tend to measure their investment results in weeks or months. However, that is inconsistent with ERISA’s approach, which would measure investment results over years, or decades, or working careers.
With that in mind, how can safe be risky for 401(k) fiduciaries, and vice versa, particularly for default investments?
Risky can be safe for 401(k) fiduciaries when selecting qualified default investment alternatives, or QDIAs. …QDIAs are the investments that can be used for participants who …fail to direct their investments, as a fiduciary safe harbor under ERISA section 404(c)(5). While there are three categories of QDIAs, this column discusses only target-date funds, or TDFs.
By legal definition—and common application—QDIAs, and therefore target-date funds that qualify as QDIAs, must have a material allocation to publicly traded stocks and, therefore, are volatile when compared with, for example, stable value investments.
The first step of our analysis is that risky or volatile investments in equities are safe for fiduciaries when used in QDIAs even though they seem less safe—or more volatile—to participants.
Seal of the United States Department of the Tr...Image via WikipediaHowever, what about the use of safe investments, such as stable value and money markets, as default investments? In that case, what feels safe for participants is risky for fiduciaries. …Succinctly stated, the DoL viewed the riskiness of inadequate benefits at the end of a working career as being more important than the riskiness of stock and bond market volatility in the short term.
If you accept the DoL’s view on this issue, or if you want the fiduciary safe harbor protections for QDIAs, the prudent course of action is to invest default money for the long term. Based on conventional investment thinking, that means that fiduciaries should place defaulting participants in diversified portfolios consisting of, at the least, stocks, bonds, and cash.
In some recent papers, researchers argue that ...Image via WikipediaYet, what if an employer wants to avoid possible employee criticism for investment losses? Isn’t that permissible?
It may be permissible based on the demographics of a particular work force, but only after the fiduciary has engaged in a prudent process and reached an informed and reasoned decision that a long-term investment in stable value or money market vehicles is likely to produce equivalent or superior retirement benefits. However, in that case, the fiduciaries have lost the safe harbor and, as a practical matter, the burden will be on the fiduciaries to prove their case—that is, to overcome the common belief that is expressed in the DoL language.
Even there, is it possible that there could be a lawsuit where participants have small gains, but no losses?
Yes, it is. In 1986, the DoL filed a lawsuit against a union pension trust and subsequently entered into a settlement of that lawsuit. In the press release regarding the settlement, the DoL stated, “The department has charged that the trustees caused the plan to sustain financial losses by investing virtually all of its assets in ordinary savings accounts during the period of time covered in the suit.” To help you understand the quote, ERISA considers insufficient gains to be losses. So, there you are. Risky is safe and safe is risky.

Fred Reish is Managing Director and Partner of the Los Angeles-based law firm of Reish & Reicher. A nationally recognized expert in employee benefits law, he has written four books and many articles on ERISA, IRS and DoL audits, and pension plan disputes. Fred has been awarded the Institutional Investor Lifetime Achievement Award and the PLANSPONSOR Lifetime Achievement Award. He is also one of the 15 individuals named by PLANSPONSOR magazine as “Legends of the Retirement Industry.”
PLANSPONSOR staff
Enhanced by Zemanta