Guess What's Being Overlooked As CUs Bolster Cyber Defenses?

image

MADISON, Wis.—As credit unions address cyber security defense this year, effective efforts begin with employee training, asserts CUNA Mutual Group.

“In today’s information-rich financial services industry, risks range from malware to employee dishonesty to ransomware to something as simple as a lost laptop. And the bad guys know that your employees are the weakest link,” said Ken Otsuka, senior consultant, risk management, business protection at CUNA Mutual Group.

A comprehensive approach to employee cyber security training is needed, said Otsuka. “The key is connecting your training insights to real-world relevance for your staff.”

Many breaches are fueled by lack of employee training, he said, which criminals take advantage of.

“As with any criminal, cyber crooks look for the path of least resistance. They find the easiest way to get in, take what they want, and get out,” Otsuka explained.

More Credential-Stealing Malware

Otsuka emphasized that compromises often don’t show up right after a system is breached. Reports show that in 2015 threat groups were able to go undetected on a victim’s network for a median 205 days, he added.

“While the hit-and-run or smash-and-grab methods—actively hacking into a system in minutes or hours—are still common occurrences, we expect to see an increase in credential-stealing malware that hides and persists over days, weeks or even months,” said Otsuka. “The longer it stays hidden on networks and systems, the more data it steals, and the larger the fire is to put out.”

A social engineering tactic—spear phishing—is also gaining momentum, having been tailored from targeting consumers to workers inside businesses, said Otsuka. This attack targets a select group of employees in organizations with an enticing message. Marketers might get an e-mail about effective advertising or tellers might see a message about counterfeit checks—and the perceived relevance makes a risky click more likely, noted Otsuka. “And it only takes one employee to ignite a cyber-fire.”

OtsukaKen

Ken Otsuka, CUNA Mutual

But annual employee training is not enough, emphasized Otsuka. Part of the solution must be an ongoing, robust employee awareness program. This proactive approach strengthens the credit union’s cybersecurity risk management posture, he said.

“Awareness training must go beyond telling employees to be wary of suspicious e-mail,” he said. “While there are financial risks associated with a data breach, including forensic investigations, member notifications and credit monitoring expenses, your reputation is also at stake.”

Training Steps

Staff awareness training should include the following topics:

  • IT security policies, procedures and practices—including a refresher on acceptable personal use of credit union-owned hardware.
  • Security for workstation computers/laptops/mobile devices—Require employees to sign off or use screensavers to lock computers when unattended; reinforce encryption of confidential member data whether it’s at-rest, in-transit, or in-use.
  • Passwords—Ensure use of strong passwords; send reminders for staff to periodically update and keep passwords safely hidden from public view.
  • Malware/phishing—Build awareness of how cyber thieves steal sensitive member data.
  • Physical security for data center—Restrict access to authorized personnel only.

When a breach is suspected or detected, NCUA’s rules and regulations require credit unions to follow a documented incident response plan (IRP), reminded Otsuka.

“Failing to adequately respond to a data breach could significantly increase the cost to recover from a breach. Not only should employees be trained on the credit union’s IRP, the credit union should also run fire drills by testing it at least annually.”

Section: Standard
Word Count: 762
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-boost/Guess-What-s-Being-Overlooked-As-CUs-Bolster-Cyber-Defenses