RANCHO CUCAMONGA, Calif.—It’s time to bolster cyber defenses, as crimeware as a service (CaaS) is making it easier for a lot more criminals to attack the credit union.
Paul Love, chief information security officer at CO-OP Financial Services, said credit unions should direct any available extra budget 2018 funds to cyber defense now, instead of waiting until next year.
“ROI in this arena is often difficult to ascertain,” said Love. “There are so many unknowns when it comes to the threat level a particular financial institution faces. Especially for smaller credit unions, it’s not hard to consider that their cooperative is far enough off the radar of cybercrooks to delay investing in deterring them.”
What changes that equation, however, is the growing crimeware as a service (CaaS) industry.
“Legitimate business is not the only one undergoing digital transformation. Black hat developers, too, have recognized that with a shift in business model, they can satisfy the changing demands of their digital consumers—cybercrooks,” said Love. “Just as above-board software vendors have found service models to be profitable, malicious technology providers see the potential for big-bucks in providing subscription-based malware and botnets.”
Sophisticated Malicious Tech
CaaS has been made possible by the “democratization” of some very sophisticated malicious technology, and it’s scaling exponentially, Love explained.
“Available across the dark web in exceedingly convenient subscription-based models, even low-level criminals can pull off some pretty high-level cybercrime. Worse, they can automate the crime, directing bots or configuring ransomware distribution kits to continuously scan the environment for financial institutions that have left their cyber doors open.”
What wedges those doors open–even just a crack–are changes by the day, sometimes by the hour, said Love.
“New threats to our connected systems come from all over—for example, that refurbished iPhone your teller brought into the credit union this morning or the wireless router sitting on your CEO’s desk,” said Love. “As Marc Goodman, author of Future Crimes and a speaker at a CO-OP Financial Services client event last year, said, ‘We consistently underestimate what criminals can do.’”
Love insists that when the discussion turns to ROI it must include the potential for data breaches as an event that is likely to happen.
“A well-designed and well-implemented security program will almost always cost far less than even one breach,” said Love. “That’s because credit unions that are breached once often become even bigger targets of opportunistic crooks and artificial intelligence tools that place a high value on organizations with a track record of vulnerability. We have to also consider the costs of incident response, including removing the attacker from the network and shoring up the security that failed.”
AI As Defense
CO-OP is putting artificial intelligence to work in the defense of credit unions against cyberfraud.
“Our team is developing a machine learning platform that unifies transaction data across all our systems and applications,” said Love. “Initially the platform will work side by side with advanced neural network technology. Over time, we may switch to machine learning entirely or keep both systems in place as the ultimate safeguard.”
Perhaps the most unnerving fact, said Love, is that credit unions aren’t the only ones who appreciate ROI. Cybercriminals, too, want to make the most of their investments. The average ROI of a botnet operation, data show, is between 400% and 600%, Love said.
“Credit union members trust their information is safe and secure when it’s in the care of their financial cooperatives. There’s no doubt cybercrooks are targeting credit unions–small and large,” Love said. “Investing now in keeping the digital doors closed to them not only makes sense, it’s every credit union’s duty to members.”
