Helping to keep your plan secure
Keeping retirement plan and participant data secure is a mission-critical priority at John Hancock. As the threats to cybersecurity become more sophisticated, so do our efforts to keep your plans safe.
We're committed to adhering to recognized international technology and security standards.
-
PSI DSS compliant
-
ISO 27001 certified company compliant
-
Sarbanes-Oxley compliant
-
AICPA SOC 1 Type 2 and SOC 2 Type 2 compliant
Multi-tiered approach
Timeline
-
1
Our technology has multiple layers of security protocols and systems.
-
2
At the global level, Manulife Financial provides risk execution, which focuses on network intrusion detection and prevention, domain-level access provisioning, firewall configuration, and management at the perimeter.
-
3
John Hancock risk management provides a divisional risk profile that examines policies and procedures, vendor risk management, and risk assessment.
-
4
At John Hancock, we focus on application management, cybersecurity, identity access management, regulatory compliance, and participant behavior.
Technology infrastructure
Secure, resilient, and redundant
Our infrastructure is in the Microsoft Azure cloud, giving us the benefit of the measures it takes for security, data integrity, and platform resiliency.
-
Round-the-clock physical security
-
Encryption of all data in transit between Azure's data center and John Hancock
-
Layered firewalls
-
Application logging and monitoring
-
Automated backup controls
-
Load balancing
-
Currency patching
-
Disaster recovery site outside the geographic region
Front-end security
Measures to help protect data at the front line
At the John Hancock level, we have additional safeguards through application management, cybersecurity measures, identity access management, regulatory compliance, and encouraging safe participant online behavior. Our enterprise information security program has comprehensive round-the-clock business resiliency and disaster recovery, and we monitor web traffic for fraudulent third-party access and the presence of certain malicious software.
-
At the front end of a web transaction: multifactor authentication and risk scores
We use multifactor, risk-based account authentication that analyzes more than 100 factors in real time and assigns a risk score determined by device and behavior profiling.
- Device profiling analyzes the device being used to access our website or mobile application.
- Behavior profiling looks at the record of typical activity for a user.
-
At the front end of a phone call: phoneprinting
Before we answer a call, Pindrop analyzes 147 factors in real time and assigns a risk score. Phoneprinting looks at factors that include:
- Geographic location
- Call type (e.g., landline or mobile)
- Unique phone
- Noise clarity, background noise, and packet loss
Operational safeguards
Supporting technology with process
Technology solutions aren’t enough—we’ve also implemented processes and procedures that help to secure our network and data.
-
Daily monitoring of participant accounts for suspicious activity
-
Temporary hold on participant accounts when suspected fraudulent activity is detected
As part of our efforts to keep participant accounts safe and secure, John Hancock offers a Cybersecurity Guarantee
Under the Cybersecurity Guarantee, John Hancock will, subject to certain conditions, compensate participants for unauthorized transfers of cash out of covered accounts1 occurring through no fault of their own by reimbursing the amount of any cash included in such an unauthorized transfer.
Cybersecurity trends and threats webinar
You'll learn about leading cybersecurity trends and industry threats, including a recent SEC warning on increased cyberattacks on financial professionals. Find out what you can do to protect yourself, your clients, and your business from Assistant Vice President and Cyber Officer Thom Shola, John Hancock.
Learn more about our open-architecture platform
-
Learn how we help build your plan
Building your plan
With five decades of retirement plan experience, we consult with you to help you navigate the opportunities, risks, and complexities of plan sponsorship.
-
Learn about how we manage your plan
Managing your plan
We'll make your job as an administrator and fiduciary easier, including accepting fiduciary responsibility for certain administrative tasks.
-
Learn about our open-architecture investment platform
Selecting and monitoring investments
Our open-architecture platform makes thousands of funds available as you select your plan's investment lineup, with services available if you'd like some help.
-
Get to know our participant experience
Engaging your participants in the power of their plan
We provide participants with personalized guidance to help them create a plan to meet their unique financial and retirement goals.
1 Covered accounts include your retirement accounts with John Hancock, such as a 401(k) or profit-sharing plan, for which John Hancock is the recordkeeper.