This document is about the cyber-threats facing employee benefit plans and measures that can be taken to mitigate the associated risks. It emphasizes that there is no risk elimination, only risk mitigation, and discusses the growing sophistication and low cost of cyber-attacks. The document proposes a "cyber HMO" insurance model that promotes healthy cyber behavior, as well as the concept of creating cyber "pools" of insurance through risk pooling mechanisms. It also highlights the importance of including appropriate cybersecurity obligations in agreements with third-party service providers.