This document is about the testimony provided by Timothy Rouse of the SPARK Institute to the ERISA Advisory Council regarding cybersecurity insurance and its impact on retirement plans and recordkeepers. Rouse discusses the common misunderstandings about what cybersecurity insurance policies cover, the increasing challenges around ransomware attacks, and the difficulties recordkeepers face in obtaining adequate fraud insurance coverage. The document highlights the industry best practices developed by the SPARK Institute's Data Security Oversight Board to address cybersecurity and fraud risks facing retirement plans and participants.