When the infamous thief Willie Sutton was asked why he robbed banks, he famously replied, “Because that’s where the money is.” While times have changed, the motivation remains the same—financial institutions, especially credit unions, are still prime targets for thieves. Today’s criminals don’t need a mask and a getaway car; they use sophisticated cyberattacks, constantly evolving their methods to breach defenses.
The National Credit Union Administration issued a significant directive urging all federally insured credit unions to prioritize cybersecurity as a core aspect of their oversight and governance. With the increasing sophistication of cyber threats, particularly those targeting Credit Unions, it is imperative for IT leaders at credit unions to ensure compliance with these updated standards.
Among these emerging threats, malvertising has become a potent tool for bad actors. By injecting malicious code into digital ads, cybercriminals can infect systems without a single click, exploiting vulnerabilities in web browsers and other software.
This is just one example of how attackers adapt and innovate, making it critical for Credit Unions to stay one step ahead of their members. This article will guide you through the key areas outlined by the NCUA, focusing on proactive measures to safeguard your organization and how Amplix can support your cybersecurity efforts.
Understanding the NCUA’s Updated Cybersecurity Standards
Chairman of the NCUA, Todd Harper’s, recent letter highlights the importance and urgency of taking action. From September 2023 through August 2024, 1,072 cyber incidents were reported by federally insured Credit Unions, with 70% of those involving a third-party vendor.
Some steps to be taken immediately would be:
- Developing a comprehensive Information Security Program (per Part 748 regulations)
- Strengthening third-party due diligence
- Embedding cybersecurity into organizational culture
- Enhancing incident response planning and operational resilience
The Emerging Threat Of Malvertising
One of the threats highlighted by the NCUA is malvertising. This sophisticated attack injects malicious code into digital advertisements, enabling cybercriminals to compromise systems even if the user does not click on the ad. Given its stealthy nature, malvertising has been responsible for a growing number of security incidents, including a recent ransomware attack on a credit union.
While cyberattacks are becoming more sophisticated, the same cybersecurity practices that have held up over time remain effective. Highlighting the “why” behind all of these practices is critical to creating buy-in amongst the leadership team and other stakeholders.
How to Combat Malvertising:
- Standardize and Secure Web Browsers: Implement strict browser configurations across all endpoints. Restrict unauthorized extensions and regularly update browsers to patch vulnerabilities.
- Deploy Ad Blocking Solutions: Utilize ad blockers to prevent malicious ads from being displayed, reducing the risk of accidental exposure to malvertising.
- Leverage Threat Intelligence: Stay informed about the latest trends and tactics used in malvertising. Regularly consult threat intelligence feeds to anticipate and counteract new threats.
- Employee Awareness Training: Educate staff on recognizing potential threats, ensuring they understand the risks of visiting untrusted websites and downloading unapproved software.
Key Areas of Focus for IT Leaders
While boards play an essential oversight role, the practical implementation of cybersecurity measures falls to IT leaders and teams. Here are the critical areas of focus:
Developing a Strong Information Security Program
Ensure your program is comprehensive and meets the requirements of Part 748, including:
- Risk assessments tailored to your credit union’s size and operations
- Technical controls like encryption, access controls, and secure data disposal
- Regular audits and adjustments based on new threats and technologies
Third-Party Due Diligence
- Establish strict protocols for assessing vendors’ security practices.
- Contracts are required to include clauses for incident notification and data protection.
- Continuously monitor third-party performance to ensure ongoing compliance.
Operational Resilience and Incident Response
- Create a detailed incident response plan that outlines steps to take in the event of a breach, including communication strategies for internal and external stakeholders.
- Develop backup strategies to safeguard member data, with regular testing to ensure swift recovery from incidents such as ransomware attacks.
- Conduct regular tabletop exercises to simulate potential cyber incidents, helping teams prepare and refine their response protocols.
Promoting a Security-Minded Culture
- Regularly train staff at all levels on cybersecurity best practices, ensuring they understand how to protect member data.
- Use awareness campaigns to reinforce the importance of security and proper data handling.
How Amplix Can Help Credit Unions Stay Secure and Compliant
Navigating the complexities of cybersecurity regulations can be challenging, especially for credit unions that are constantly facing new threats. Amplix offers a range of services designed to help credit unions remain compliant, secure, and prepared:
- Risk Assessment and Security Program Development: Amplix’s team of experts can help craft an information security program that aligns with NCUA standards, from initial risk assessment to ongoing management.
- Malvertising Defense Solutions: Amplix provides comprehensive tools to detect, block, and mitigate the impact of malvertising, ensuring your credit union’s systems are protected from this and other emerging threats.
- Third-Party Risk Management: Amplix helps manage the complexities of vendor security, offering solutions to streamline due diligence and continuously monitor third-party compliance.
- Ongoing Support and Education: From regular training sessions to updates on the latest threats, Amplix ensures your teams stay informed and prepared.
The recent NCUA directive is a call to action for IT leaders at credit unions. Addressing the key areas of cybersecurity, from securing third-party relationships to defending against emerging threats like malvertising, is crucial for safeguarding member information and maintaining regulatory compliance. Contact Amplix today to see how we can help credit unions every step of the way, ensuring that your cybersecurity posture is strong, proactive, and ready to face the future.