By Ray Birch
BROOKFIELD, Wis.–Firewalls and other defenses aimed at keeping crooks from penetrating the CU are no longer enough, according to one expert, who said the most skilled organizations now recognize penetrations will occur and they must also be prepared to stop hackers once they are past the firewall.
Bill Johnson, VP of Sentry Cyber Security at Fiserv, explained that many large companies today know hackers will penetrate their systems—a situation that challenges the futures of many small credit unions.
“In my opinion, endpoint protection, such as legacy antivirus software, is no longer adequate. We have to get to the point where we are also assessing behavior and behavior patterns, and then quickly react and prevent a fraud attempt based on these analyses,” said Johnson. “The best thing a bank or credit union can do is get into a next-generation solution that is looking at behaviors and blocking suspicious activities.”
Johnson acknowledged that over the years the focus has been on a layered approach to cyber defense to keep fraudsters outside the organization’s systems. While he said those approaches—such antivirus software, endpoint protection, firewall monitoring—are still important, he also said more needs to be done.
Already Inside
“Anymore it’s a given that unwanted people are inside your environment, and as I said, it’s now about preventing them from getting the information they’re after,” Johnson said. “This goes beyond the financial services sector. There are a lot of organizations, even government entities, that now don’t focus as much on attempting to keep crooks out of their network. They pay a great deal of attention to monitoring the data that’s flowing out of their networks.”
Johnson said these organizations are watching their data for processes or a series of actions that are anomalous in some way.
“For example, it would not be uncommon for you to open your Windows File Explorer and do some file cleanup. But if another process on your system does that, Notepad, for example, and enumerates your file system, elevates privileges, deletes some backup files and now says, ‘I will encrypt some files’…I can look at that series of behaviors and say this does not smell right. This looks like ransomware and I am going to prevent it.”
But this shift in fraud fighting comes with a higher price tag, both for the solutions, which can involve artificial intelligence (AI), and skilled staff to address findings and manage the solutions. Johnson acknowledged that adopting such a cyber defense is challenging for small credit unions.
“There just is an escalating cost in protecting the credit union,” he said.
Johnson explained that not only can the price tag for the behavioral analytics solutions be higher than typical defenses to keep criminals outside the system, smaller credit unions are challenged to employ skilled staff to manage and effectively use the new solutions. He said that many small credit unions are in rural areas, which means a small talent pool of cyber defense experts to draw from.
“And if the small credit union is in an area in which the talent pool is larger, the credit union won’t likely be able to match the salaries offered by the larger FIs in the market,” he said.
In Demand
Johnson noted, too, that cyber defense experts are in high demand, and that there are not enough skilled people to fill the roles that are needed today—an issue CUToday.info has previously reported.
But if small credit unions think they can avoid making changes to their defense approach because they are tiny and overlooked by cyber thieves, Johnson said that’s a big mistake.
“A lot of crooks look at small credit unions as prime targets, because they are perceived as not making the investments in cyber defense that larger organizations are,” said Johnson. “The concept of security by obscurity is definitely no longer valid.”
Johnson said he often speaks with small credit unions that say they are coming under attack on a regular basis. Johnson said they are seeing sophisticated phishing attempts and ransomware attacks.
“Ransomware is the big thing,” he said. “I know of two credit unions that recently paid ransoms to cyber thieves.”
Bottom line, said Johnson, is that small credit unions must address the rising cost of cyber defense—costs for both human resources and infrastructure and software.
“Some small credit unions are just choosing to merge out, to gain the scale needed by joining a larger organization,” said Johnson. “It’s really about partnering, and that often means working with a third-party provider.”
Avoid Upfront Investments
Johnson said Fiserv has an endpoint detection response offering that credit unions can subscribe to and avoid the upfront investments.
“We have already made these investments in skilled staff, infrastructure and software and have the ability to scale those services and make them available to smaller credit unions at an affordable monthly price,” he said.
Fiserv also sees a very large volume of security incidents each day, which a small credit union does not, which helps the company effectively monitor, measure and evaluate potential cyber attacks.
“A small credit union does not see a statistically relevant sample,” said Johnson. “Anymore, it’s very difficult for them to go it alone.”
