This document outlines the scope and objectives for the 2016 ERISA Advisory Council's study on cybersecurity considerations for employee benefit plans. The Council aimed to review the types of cybersecurity risks that benefit plans face, the steps and controls being taken to address these risks, and develop materials to help plan sponsors establish scalable cyber risk management strategies and incorporate cybersecurity in vendor selection and monitoring.