Time To Set High Standards For Third-Party Data Security

imge'

MILWAUKEE, Wis.—It’s time credit unions carefully consider how third-party relationships can impact their data security and ask vendors some tough questions, asserts La Macchia Group.

With the number of data breaches continuing to grow, Benjamin La Macchia, VP of planning and real estate at La Macchia Group, insisted credit unions must set high standards for third party-vendors.

“Data breaches continue to be a top-of-mind concern for credit unions,” said La Macchia, reminding that the issue has grown so large that CUNA Mutual Group now has a website (www.stopthedatabreaches.com) dedicated to fighting the problem. “While the failure of merchants to invest significantly in data security measures is receiving the primary focus, credit unions also need to keep top of mind that they leave themselves vulnerable when engaging with any third-party vendor.”

La Macchia stated concerns similar to those emphasized by NCUA as the agency has increased its attention to CU vendor due diligence. La Macchia noted that in the Home Depot and Target data breaches the supply chain side of these organizations is where the compromises occurred.

Unsecure Source

“For example, media outlets referenced a compromised HVAC vendor as the unsecure source for the Target data breach. Taking a closer look at the credentials of third-party vendors and vetting the processes they have in place to maintain network security is one way credit unions can take their data security to the next level,” he said.

La MacchiaBenjamin

Benjamin La Macchia

As credit unions get ready for 2017, La Macchia said they must invest the time, energy and due diligence necessary to ensure that any business consultants or partners supporting the credit union have security measures in place to protect confidential data.

La Macchia outlined key questions credit unions should ask regarding third-party vendors and their internal controls:

  • What vendor partners have access to credit union and member data?
  • Do these vendors have specific procedures or an action plan in place with safeguards that address security, availability, processing integrity, confidentiality and privacy?
  • Do these vendors have their systems tested by an outside consultant that specializes in data security?
  • Can these vendors provide a Service Organization Controls report?
  • Do these vendors subcontract work that will make their own data controls vulnerable?

“Credit unions make protecting members’ data a top priority and hold themselves to high standards, so they should have high expectations of their third-party vendors,” said La Macchia. “To stop data breaches, different levels of vulnerabilities need to be addressed. Your third-party vendors represent one level of data security. When looking to 2017 and beyond, make it a priority to ensure that your business partners are working in the best interest of your credit union and your members. Choose to work with companies that have invested in the safeguards necessary to guarantee your information is protected.”

Section: Standard
Word Count: 657
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-boost/Time-To-Set-High-Standards-For-Third-Party-Data-Security