This document is about providing guidance and educational materials for ERISA plan fiduciaries on protecting personally identifiable information (PII) and implementing appropriate security measures. It discusses the challenges in providing concise, reliable, and regularly updated guidance due to the complex and rapidly changing legal and technological landscape. Instead, the document suggests the DOL focus on providing educational materials to make fiduciaries aware of the basic issues and the need to consult experts. It also recommends the DOL develop specific compliance categories within the NIST cybersecurity framework and sponsor an Information Sharing Advisory Council (ISAC) focused on this industry.