M

Important Notice about Protecting Your SURS Account

SURS would like to alert members to a rise in sophisticated scam attempts targeting pension systems and financial institutions. – Read Article

Closed Session: Audit & Risk Committee Meeting Minutes

Meeting: September 8, 2023 | Posted: June 8, 2026 | SURS Board of Trustees Meeting Minutes

The meeting of the Audit & Risk Committee of the Board of Trustees of the State Universities Retirement System (SURS) convened on Friday, September 8, 2023, at 10:00 a.m.

The following trustees were present: Dr. Andriy Bodnaruk (via zoom); Dr. Fred Giertz, chair; Mr. Scott Hendrie; Dr. Steven Rock; Mr. Richard Figueroa (via zoom); Ms. Jamie-Clare Flaherty (via zoom; Mr. John Lyons; Mr. Antonio Vasquez; and Mr. Mitch Vogel.

Others present: Ms. Suzanne Mayer, Executive Director; Mr. Douglas Wesley, Chief Investment Officer (CIO); Ms. Ellen Hung, Deputy CIO; Ms. Jackie Hohn, Chief Internal Auditor; Mr. Alex Deal, Internal Auditor; Ms. Lorraine Gui, Internal Auditor; Mr. Jefferey Saiger, Chief Technology Officer; Ms. Tara Myers, Chief Financial Officer; Ms. Nichole Hemming, Chief Human Resources Officer; Ms. Bianca Green, General Counsel; Ms. Kristen Houch, Head of Legislative Affairs; Ms. Alicia Route, Legislative Analyst; Mr. Albert Lee, Associate General Counsel; Ms. Anna Dempsey, Investment Counsel; Mr. Harold Keagle, Information Security Manager; Ms. Kelly Carson, Ms. Chelsea McCarty and Ms. Annette Ackerman, Executive Assistants; and Mr. Michael Calabrese of Foley.

The SURS Audit & Risk Committee went into closed session at 10:30 a.m.

Information Systems Security Update

Third Party Cyber Security Issue

Mr. Jefferey Saiger informed the Board of a new ransomware gang known as CLOP who compromised a new popular file sharing tool known as MOVEit, wreaking havoc across both the financial and public sector industries. Unfortunately, SURS staff members were impacted by the breach that occurred with the Illinois Department of Innovation (DoIT) that provides mandatory electronic training. Approximately 3,500 SURS members in the Defined Contribution Plan may have been affected as well due to a MOVEit breach that occurred with a TIAA vendor (PBI). Jefferey reported the steps that were taken as a result of these breaches. Bianca Green further
reported that all employees and impacted SURS members have been properly notified by DoIT and by TIAA. SURS notified its cybersecurity insurance company and worked with them to make sure that appropriate legal notifications were issued to staff and members by DoIT and TIAA so they closed their file regarding this security matter. Jefferey and Bianca Green answered any additional questions posed by the trustees.

Annual IS Security Report

Mr. Saiger presented the fiscal year 2023 Annual Information Security Update. He highlighted how SURS IT focused on twelve key areas which are listed in greater detail in the report he provided to the board. Mr. Saiger and Mr. Harold Keagle highlighted on a few of the security accomplishments that were noteworthy from the previous year, which included the formalization of the IT GRC Program, Implementation of privileged account management, improvement to the cybersecurity awareness program and the business impact analysis.

Return to Open Session

The open meeting resumed at 11:05 a.m.

Respectfully submitted,

Suzanne Mayer Signature

Ms. Suzanne Mayer
Executive Director and Secretary, SURS Board of Trustees