Best Practices
NAPEO’s Cybersecurity Task Force has developed best practices and checklists of key issues to be aware of as you address cybersecurity needs. This series of best practices will expand and evolve, so be sure to check back periodically to see what has been added.
Guides & Checklists
Key Items for PEOs to Manage Data and Cyber Risks
Obtain executive support, assign responsibility, know your business …
Cyber Underwriting Best Practices
This document is designed to provide the reader with the IT security underwriting requirements of insurance underwriters in order to obtain a cybersecurity insurance policy.
Business Continuity for PEOs
For small businesses that use a PEO, there is a high level of trust required to make the relationship successful. If a disaster occurs, or even just a small system or network outage, PEO clients expect that things will continue without interruption.
Disaster Recovery for PEOs
Disasters are inevitable, and their timing is unpredictable. Preparing your company and employees before disaster strikes can make the difference between a catastrophe or an inconvenience.
Sample Vendor Assessment Questionnaire
The vendor management questionnaire (VMQ) is an effective tool for PEOs to assess capabilities and risks associated with third-party vendors.
Sample Spear Fishing Tabletop Exercise
Players are personnel who have an active role in discussing or performing their regular roles and responsibilities during the exercise. Players discuss or initiate actions in response to the simulated emergency.
What to Do in Addition to Tabletop Exercises
Imagine a timeline depicting the events leading up to a cybersecurity incident impacting your company and draw a vertical line at the point when you first become aware of the situation.
Artificial Intelligence (AI) and PEOs
AI technology is widely used in various sectors, such as healthcare, finance, education, transportation, and more, for applications like automated customer service, data analysis, predictive maintenance, etc. The ongoing research and development in AI continually leads to new breakthroughs and discoveries.
Webinars
NAPEO’s six-part Cybersecurity Webinar Series focused on providing a holistic approach to cybersecurity since an effective, sound cybersecurity policy is about more than data protection and privacy. These six webinars covered all aspects of cybersecurity, including business continuity planning, crisis communications, and legal issues.
Six-part Series
Reports, Articles & Presentations
NAPEO Reports
The Pillars of Cybersecurity for PEOs
Prepared in 2018, The Pillars of Cybersecurity for PEOs guides NAPEO member companies through several steps to ensure data security. The report concentrates on four main areas: prevent, comply, react, protect. The report is intended to provide NAPEO members with useful information and insight so that each organization can establish critical safeguards to fend off data breaches and cyber-attacks.
Presentations and Events
Lessons Learned for Your Financial & Payroll Departments During a Cyber Attack
Drawing on recent industry and other real-world examples, this session covers how finance and payroll departments can prepare and respond to cyber attacks and ensure operations remain relatively unaffected.
Ethics Session: Cybersecurity & Privacy in a Remote Workforce World
Because of the COVID-19 pandemic, remote work has become more ubiquitous and PEOs and their clients must have the appropriate cybersecurity and privacy policies in place. In this session, you’ll learn best practices, general principles to adhere to when crafting cybersecurity and privacy policies, and how to address cyber and/or privacy incidents.
Aon Cyber Risk Management Presentation
Aon Cyber Solutions specializes in holistic cyber risk management and proposes a multi-phase solution for identifying, prioritizing, and mitigating cyber exposure.
Articles
MFA: A critical cybersecurity tool, but not all companies get it right
(Insurance Business and Amwins, September 2022)
Key Resources
The following resources from NAPEO associate members and others sources provide additional tools, guidance, and information on cybersecurity for PEOs.
Additional tools and guidance
PEO Defender’s Artificial Intelligence Ethics Policy
Artificial Intelligence (AI) is an emerging field that holds immense potential to shape the future. However, the development of AI tools must be done with caution and ethical considerations in mind.
Theresa Payton Tips, Global Outlook, Predictions, and Resources
There are endless possibilities if we implement Web 3.0 technologies, for example blockchain and cryptocurrency, correctly! Web 3.0 could provide access to customers of every demographic; the creation of new types of frameworks for liquidity and capital through tokenization of current, traditional assets; and new back office optimization through extended reality meetings, smart contracts, micro payments, trusted clearing, and more.
Mullberri.io Cyber Threats Feed
Mulberri has developed a unique program that insures and helps small-medium businesses with Cyber Protection and Monitoring.
PEO Defender
HCM Defender is an organization that is tasked with helping all participants (service suppliers and HCMs) with tools, resources, and information that will lower security risks. This industry alliance will be overseen by volunteer leaders from organizations in the industry and will act much like NATO was designed (an attack against one is an attack against all).
Aon Cyber Solutions
Cyber threats are evolving rapidly and risk mitigation is an ongoing challenge. The decisions an organization makes will prove critical to its cyber resilience.