A New Road For Crooks Into FI’s Systems

By Ray Birch

SAN DIEGO—Credit unions should assume each of their employees now working from home is a security risk to the organization.

Feature Corona Stickley low res

Security expert Jim Stickley is sharing that warning with credit unions because hackers are now quite aware the new road into FI’s systems is through the home PCs of employees now doing their jobs from outside the office during the coronavirus pandemic. And, as CUToday.info has reported, cybercriminals are increasing their attacks on home routers.

Stickley, CEO of Stickley on Security, is stressing the importance of limiting employees’ access to systems to the very minimum they need to do their work.

“The person working at home right now you have to assume is a risk to the organization. Folks are getting into the company system now with their home computers,” said Stickley.

With all the new work-from-home arrangements, it’s now essential CUs pay close attention to access control, he advises. (As CUToday.info reports separately here, security consultants have also issued warnings around the growing use of the videoconferencing solution Zoom.)

“Access control is everything now,” emphasized Stickley. “You want to say, ‘OK, you need to do your work from home, so I'm going to give you access to our corporate network.’ But there's a number of different ways you can do that. The most simple is you set up a VPN, and the home PCs have this tunnel directly to your corporate network. In a lot of organizations, just for simplicity and speed, that's what’s been done.”

The upside of the new scenario, acknowledged Stickley, is a worker gets on the system quickly and it’s a fast way to set up a remote workforce.

“The downside is you're now on the company's network from home,” said Stickley. “When someone is at the office and on the system, your IT team is right there. They’re monitoring everything, there are firewalls…With home PCs, you’re only as secure as whatever home network you employee is on. Generally speaking, you're not going to have quite the budget the financial institution has to secure the network.”

Security Strategies

With the increased risk of a breach, Stickley offered advice on what CUs need to do.

“Credit unions need to think, ‘OK, what does each employee really need access to do their jobs, and how am I controlling that access?’” Stickley said. “Now that security at the credit union is weaker than it’s ever been, credit unions need to control employee access. Maybe someone only needs access to an intranet server, or a web server that's on the internal database…They don’t need to touch the core.”

What that means is giving workers only access to part of the system they need to do their jobs and no more. That way, Stickley said, if crooks get into the network they can only get to a limited portion of the system.

“This, too, means controlling access down to the point of even time-based access,” said Stickley. “An employee doesn't need access to the corporate network, generally speaking, at midnight. So you want to have time-based controls that limit access to regular business hours for most of the staff. That eliminates a criminal getting on someone’s home PC, getting into the system, and poking around the network at night.”

Monitor Traffic

Another important step for the IT team to take now that workers are at home is to closely monitor system traffic.

“Watch for things like how many records are being accessed in a certain amount of time,” Stickley said. “If I'm a bad guy and I get access, I'm going to want to get as much data as possible as quickly as possible, so I will start firing through account after account.”

Stickley said that kind of activity is obviously not normal and the IT team should set limits for how many records an employee can access in an hour—activity above that automatically should shut down access.

“If a person should generally be looking at like 20 records in an hour, and suddenly they're looking at 2,000 records, that's a pretty big red flag and you need to jump in and shut that down,” he said. “These are things that can already be in place today, but they become so much more important to monitor now that people are working from home.”

The big issue, emphasized Stickley, is most financial institutions moved to a remote workforce quickly.

stickleyJim

Jim Stickley

“I talked to several banks and credit unions that had no choice because this pandemic came on so rapidly,” said Stickley. “So many are allowing people to use their home PCs. My recommendation is now that you moved quickly to this new working situation, once you get your head above water, move as fast as you can to solve any security issues, lock down systems. Focus on that now.”

A Complete Turnaround

Stickley pointed out that most organizations have experienced a complete turnaround, moving from having 95% of staff working in the office to 95% now working from home.

“You have the exact opposite working environment,” noted Stickley. “More organizations have been dabbling with a remote workforce, but very few were prepared for such an extreme switch. When you do something like this, you don’t do it fast, and security has to be a big part of the change. But speed became the big issue with this pandemic. Security becomes less important when you’re just trying to get everyone up and running to get their jobs done. This is a support issue too. So, IT guys now are probably pulling their hair out.”

Stickley advocates a particular type of computer be used by employees.

“Chromebooks are inexpensive and extremely secure,” said Stickley. “But there are limitations on what software you can load on them, so sometimes staff won’t be able to do what they need to do on them. But if you can use Chromebooks, start sending them out to your staff as fast as you can.”

A ‘Time Bomb’

Stickley further advised any organization in control of home laptops lock down what staff are able to install on those devices. He also recommended having the ability to quickly deliver security updates to home laptops and to be able to install security patches as needed.

“If you're not able to maintain the patches on these systems, you're just a time bomb waiting to go off,” he said. “And make sure the PCs your employees are using are only dedicated to work. Make sure other family members are locked out from using them—and be certain your employees understand that.”

Communication to staff about maintaining security and exercising good security practices, such as not clicking on links from unknown sources, is even more important with staff offsite. Stickley noted that when security threats occur, such as a new phishing scam, staff often hear about the threat from coworkers, in typical office conversations were previously taking place

“Those conversations are not happening today,” said Stickley. “You need to be focused on educating staff at home and keeping them aware of what's going on. Overall, you want to be very proactive with this remote work environment and not reactive. If you have to go to a reactive mode, you're already been hacked.”

For more advice from Stickley on how to stay safe with staff working at home, watch this video: Top Ten Security Tips for Working at Home.

Section: Standard
Word Count: 1553
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/A-New-Road-For-Crooks-Into-FI-s-Systems