WASHINGTON–Your credit union has backed up its data, but who really has it? It may not be who you believe it is, credit union leaders here were warned during a sobering update on the cyber-threats they face.
Speaking to NAFCU’s Congressional Caucus, Bill Evanina, who served as director of the United States National Counterintelligence and Security Center (NCSC) until January 2021, and who is now on the Advisory Board of Peraton, a national security technology company, outlined the threats to credit unions, challenged CU leaders to take a number of steps, and offered some recommendations.
While still in his role at the NCSC, Evanina shared how he brought together a broad coalition of private and public security experts to develop the U.S. Counterintelligence Strategy, which was released in 2020 and which is built upon five pillars:
- Protecting The Critical Infrastructure, including telecommunications, infrastructure and financial services as the big three
- Protecting The Supply Chain
- Malign Foreign Influence, which he said effects on everyday life of ecosystem of Americans. “We often don’t pay attention to this at the local level,” Evanina said.
- All Things Cyber. That includes the self-inflicted wound of credentialing, he said. “Why do we still have name-based credentials? Our doors and windows are wide open even though we spend billions of dollars on cyber-defenses every year.”
- Protecting the Economic Security. “Economic security is national security,” said Evanina.
The Real Costs
For those who don’t think data breaches and other security issues aren’t costing Americans, Evanina said it costs the country $500 billion a year in theft from “communist China” alone, or about $4,000 per year to the average family of four after taxes.
Given that scenario, Evanina called the recently passed CHIPS Act “one of the most seminal pieces of legislation we have had in this country in 40 years.”
“I am a big believer in a public private partnership. The CHIPS Act is going to test that,” he said. “China is the existential long-term threat to our nation. In China, the government, big business, the Communist party are all the same thing. They are doing all the hard work for their intelligence services. It would be like if the CIA or NSA gave all the information they collect every day to Google and said, ‘Condition all this data and give it back to us so we can use it against our adversaries’.”
The Internal Threat: Apathy
While the China threat is obvious, Evanina said it’s much more localized threats that are hurting many American institutions and businesses large and small.
The importance of cyber-hygiene education can be difficult to make clear in an environment in which there is so much discussion around cyberthreats, Evanina said.
“We get numb to breaches. Over 90% of breaches don’t emanate from your company, they emanate from a contractor that is servicing your company. By the time that malware comes to you, it’s too late,” he said.
The reason for those breaches is often misunderstood, according to Evanina, who pointed to the huge Equifax breach and the compromise of information on 147-million Americans as a good example.
“It was about more than theft of our personally indefinable information (PII) by China,” Evanina said. “They have all of our data. That’s not what they’re after. That wasn’t the objective. The intent was to identify the algorithm and business processes Equifax uses to contact and communicate not just with lenders, but customers. They want that science, the business model, so they can duplicate and replicate it in China. They don’t do their own research and development. The fact they got the data was gravy. It’s important to know the context of why adversaries are going after us.”
The Other Hill Message
For credit unions at Congressional Caucus going on Hill hikes, Evanina urged his audience to also demand that the government do more and provide more information.
“It has to be actionable, real-time data,” said Evanina. “You have to ask, ‘Are we getting what we need every day?’ As a leader you need to ask your CISO or CTO, ‘Are you getting what you need every day from the government?’ You need to ask what other organizations are getting.”
The New Global ‘Gold’
Evanina said he continues to see CTOs who are unwilling to do functional benchmarking, but those that do find massive gaps in the information they need.
“Ask yourselves, who in our organizations should go out and benchmark with our peers?” he advised. “And it’s not just asking other credit unions, but also the big banks. You may not be able to replicate all their answers, but you will get an idea of what’s going on out there.
“Data is the new global commodity beyond gold,” he continued. “When you go back, as leaders ask some really specific questions about your data. Do you have backups? Do you have resiliency? Do you have metrics around attempted penetrations? Who else has your data? It matters for all the obvious reasons, but also because the Chinese strategy is to come to the U.S. market and provide cheap secondary data storage for you. U.S. companies are falling for that right now and are backing up data with Chinese-owned companies. It’s not just resiliency; know where you are backing up that data.”
The Ransomware Threat
While many credit unions and other organizations believe they are prepared for a potential ransomware attack and its aftermath, Evanina said, “No one is prepared.”
“It means having a plan, understanding where your data is, so that when that ransomware message pops up on-screen you know if they have all your data,” he said. “CEOs should already know that. The next 20 minutes in the crisis is catastrophic for a company if you are not prepared and don’t have the right leadership skills in place to assign authorities, including human resources. You should have an established plan in place, and share that with your insurance company, because you will get better rates. When you are a leader your constituencies quadruple when you have a crisis. Everyone is looking to you for answers.”
While a credit union may have a policy in place on whether it will pay or not pay the ransom, Evanina said no organization knows what it will do until it is faced with the dilemma.
“If it happens to you, make sure you are in contact with the FBI. They are going to tell you not to pay it, wink, wink,” he said. “My experience is if you pay it, there is no guarantee you are going to get your data back.”
Recommendations Made
Evanina offered a number of other cybersecurity-related recommendations, including:
- Have regulator tabletop exercises before any plan is completed. “And go to someone else’s tabletop exercise and learn from them,” he said. “When you tabletop every six months, in addition to having the CEO, CFO, CTO, CISO, and general counsel present, you need human resources and your head of procurement and acquisition. Your number-one resource beyond data is your people and you have to have a communications policy in place.”
- Have a back to the basics campaign with employees that stresses not clicking on links or committing self-inflicted wounds.
- For CEOs, “Be a leader. Tell people you are going to do this stuff. Bring in speakers to manifest the threats. Ask the board what they will expect from you. You have to manage up and down.”
- Define a media strategy.
Never More Vulnerable
“I have never seen a time when we were more vulnerable than we are right now as a nation,” said Evanina. “You are part of the number-one piece of critical infrastructure in America. Be prepared. Don’t be stuck with empty hands when a crisis hits.”
