List of UK pension funds that are not secure by default
This is one of several posts of the topic of security of websites. Inspired by my initial post on the security of UK banks.
The reason for splitting this data into multiple posts is to make it more manageable. So that data on one institution is not mixed with data on another type of institution.
I thought it would be interesting to look at each bank in the UK to see if when you visit their company homepage, is that secure by default? That is, is the page loaded by HTTPS? There are more tests than this that you could do, but that’s the baseline. If they can’t meet that then the other tests are meaningless.
Some banks provide the website in both http and https versions. This is bad practice. If someone visits the website as http then the customer should be served the https version of the page.
Also please note, these test results are for a desktop computer visiting the website. A mobile phone may well get a different experience. In other words desktop visitors may get a secure site, but mobile visitors might not. Or vice versa.
The following key is used for the secure status:
Yes | The site is secure, loaded via https |
Dual | The site can be loaded via http, or via https. |
Invalid | The site loads via https, but the security certificate is invalid and thus the site is insecure. |
Partial | The site loads via https, but loads some parts of the page without https. The site is insecure. |
No | The site is loaded via http, not via https. |
Fixed | The site is loaded via https, but at the time of first writing it was loaded via http. |
?? | We could not find a website to evaluate. |
We tested 28 pension funds. We found 8 pension funds that did not have a secure home page (not https or did have https with an invalid security certificate). That is 29% of UK pension funds have security vulnerabilities.
Some of the websites shown below no longer have active links. For those websites we have listed the URL but removed the non-working link.
Pension Fund | Secure | Home Page |
---|---|---|
Aviva Staff Pension Scheme | No | http://www.avivastaffpensions.co.uk/retired/default.aspx |
BAE Systems Pension Scheme | Yes | https://www.baesystemspensions.com/ |
Barclays Bank UK Retirement Fund | Yes | https://epa.towerswatson.com/accounts/barclays/ |
BBC Pension Trust Ltd | No | http://www.bbc.co.uk/mypension/join |
BP Pension Fund | Yes | https://pensionline.bp.com/Homepage |
British Airways Pension Scheme | Yes | https://www.mybapension.com/ |
British Coal Staff Superannuation Scheme | Yes | https://www.bcsss-pension.org.uk/ |
British Steel Pension Scheme | Yes | https://www.bspensions.com/ |
BT Pension Scheme | Yes | https://www.btpensions.net/ |
Co-operative Group Pension Scheme (Pace) | Yes | https://pensions.coop.co.uk/ |
Electricity Supply Pension Scheme | Yes | https://megtpensions.com/contact-us/ |
Greater Manchester Pension Fund | Yes | https://www.gmpf.org.uk/ |
HBOS Final Salary Pension Scheme | Yes | https://www.lloydsbankinggrouppensions.com/ |
HSBC Bank UK Pension Scheme | No | http://www.futurefocus.staff.hsbc.co.uk/ |
ICI Pension Fund | No | http://www.icipensionfund.org.uk/ |
Lloyds TSB Group Pension Scheme | Yes | https://www.lloydsbankinggrouppensions.com/ |
Mineworkers Pension Scheme | Yes | https://www.mps-pension.org.uk/ |
National Grid UK Pension Scheme | Yes | https://www.nationalgridpensions.com/362/1320/welcome-to-the-national-grid-uk-pension-scheme-website |
Railways Pension Scheme | Yes | https://www.railwayspensions.co.uk/ |
RBS Group Pension Fund | Yes | https://rbs.tbs.aon.com/ |
RBS Group Pensioner’s Association | No | http://rbsgpa.org.uk/ |
Rolls-Royce Pension Fund | Yes | https://www.rolls-roycepensions.com/Homepage |
Royal Mail Pension Plan | Yes | https://www.royalmailpensionplan.co.uk/ |
Shell Contributory Pension Fund | No | http://pensions.shell.co.uk/scpf.html |
Strathclyde Pension Fund | Yes | https://www.spfo.org.uk/ |
Universities Superannuation Scheme | Yes | https://www.uss.co.uk/ |
West Midlands Pension Fund | No | http://www.wmpfonline.com/ |
West Yorkshire Pension Scheme | No | http://www.wypf.org.uk/ |
Commentary
It is surprising to see the pension funds of some banks are insecure, even though the banking website for it’s customers are secure.
While I find it very worrying that some banks and wealth managers etc are not secure, people whose funds are in a pension, that is often their only form of income, thus if access to the pension fund become compromised for a particular person, that could be all their future income being erased. This is not a pleasing prospect. As with banks, wealth managers, etc, these pension funds should manage their security with greater care and diligence.
Guest posts
No, we’re not interested in having a guest post about finance related topics. These articles are about security, not finance.