By Ray Birch
BROOKFIELD, Wis.—Just how well can small CUs defend against growing cyberattacks, which one expert terms a “tidal wave” of trouble headed their way?
And is the price for reasonable defense getting outside many small shops’ financial means?
Some analysts say many small CUs face those issues today, especially with crooks looking for an easy doorway into the financial system to spread their attacks—a big concern with regulators. They say that the table stakes for protecting the FI—top-notch firewalls, infrastructure and more—have gotten bigger no matter the size of the institution, and that may be exceeding the reach of small budgets.
Experts also contend that wallet size is not just the issue, it’s human resources—including being able to attract and retain skilled cyber-defense experts to stay on top of emerging threats.
“One of the biggest fears in the industry is the crooks will find the small guys as the back door into the financial system. I think that is something NCUA is concerned about, as well as the other financial institution governing bodies,” said Barbara Lowman, SVP, account processing solutions at Fiserv.
Perfect Example
Jim Stickley, CEO of Stickley on Security, said the “perfect example” of how this concern is justified is the Target breach.
“Target, so to speak, is where it all started,” said Stickley. “And it happened because a third-party vendor had a VPN into Target’s network. As we know, it was not Target that actually made the mistake. A third-party vendor let the thieves in.”
Noting the increasing interconnectedness of credit unions, not only through payments systems but with the expansion of CUSOs and more resource sharing, Stickley said, “All it takes is one mistake. The weakest link is your weakest link, and that can be the small credit union.”
One data systems expert at a large CU, asking for anonymity, agrees that crooks are eyeing small credit unions.
“Some small credit unions are just paying someone to manage their firewall, but they lack expertise in-house. So they don’t know what security parameters to tell the vendor to set, what websites to block, for example. This is what hackers are looking for—the easy hits.”
NCUA is making a concerted effort to protect the CU system. In addition to making cybersecurity a focus this year, the agency is also working with Congress to gain third-party vendor authority.
Some insist that NCUA may not mind that the additional cybersecurity compliance and cost burdens could prompt more small shops to merge, as that would reduce the fraud risk to the entire CU system.
Targeting Smaller CUs
Experts say that cyber-thieves are paying more attention to smaller financial institutions today, not only because they may have weaker defenses, but because the crooks are casting a wider net.
“They are taking more of a shotgun approach, a lot of it through e-mail,” said Stickley.
Chris Silveira, manager of fraud intelligence for Guardian Analytics, Mountain View, Calif., noted that crooks are now “trying to target the widest audience possible.”
Rajiv Motwani, director of security research for Websense Security Labs in Austin, Texas, said that attackers getting smarter and much more sophisticated is rapidly ramping up the costs for cyber-defense. “They are forcing companies to raise the bar.”
Motwani reminded while there is never “perfect security,” the first 80% of cyber-security costs may be manageable for those wrestling with budget. But the last 20%, to address all the new attacks, is what can lead to a great deal of expense, he said. “Clearly, the small credit union is at risk.”
Outside of costs, experts have concerns about the ability of small CUs to attract and retain skilled resources to defend member data, and to have enough people focused on cyber-defense.
Employee Education Needed
“The problem is a lot of the smaller credit unions are not able to keep up with the latest information and educate their employees about proper cyber-security, so they fall victim—not because the bad guys are necessarily targeting them, but because they are more susceptible to the breach,” said Stickley.
Stickley added that small credit unions are lucky to have one or two people in IT.
“So one to two people to protect an entire organization is extremely difficult, if not almost impossible,” he said. “New breaches and new threats happen every day. These are the same IT guys also responsible for keeping all the computers running, the printers working and personnel doing their jobs. They have so many hats and security officer is generally not one of them.”
Stickley said that with cyber-crime growing, IT staff are having to put aside more of their day-to-day roles to focus on security. “I don’t know how they could possibly do it. I feel bad for them.”
Hard To Attract Talent
Lowman said that small credit unions are also are challenged to attract the best talent, due to smaller salaries and less sophisticated data infrastructure.
And if the CU does not have the necessary talent not only to manage external defenses but strong internal security practices, as well, they are in trouble, contended Tony Busseri, CEO of security firm Route1, Washington.
“The large majority of data breaches are triggered by the fault of a human being—whether that be a lost laptop or flash drive or an e-mail mistake,” he said.
Higher Table Stakes
The table stakes for cybersecurity are also being raised by regulators, explained several sources who acknowledged that asset size may not matter when the examiner addresses security requirements.
“From a data security perspective, it does not matter the size of the credit union,” said Lowman. “Member data has to be protected. The requirements are the same, and small credit unions struggle unbelievably with this due to their scale.”
Shelley McDade, CEO of Sunshine Coast CU in Gibsons, B.C., concurs, adding there are steps small credit unions can take to address the issue. She said her CU saw the increasing need for strong cyber-security coming, and outsourced its IT function.
“We realized this cyber-security problem will only continue to grow and would require more people, and more talented people—as well as more hardware and software,” she said. “So we moved our entire network out to a third party,” McDade said. “We came to the conclusion that at our size we could not attract and retain the talent we would need to stay on top of this issue.”
Fiserv emphasized the service bureau approach to IT being an answer, saying the data processor has introduced a new service specifically for small CUs.
“The answer can be to find supplemental resources and not always relying on resources on the payroll,” said Lowman. “We recognize the need for stronger data security among small credit unions.”
On the West Coast, Jon Hernandez, CEO of three California CUs—the $64-million CalCom FCU and the $28-million Mattel FCU, both in Los Angeles, and the $68-million Nikkei CU in Gardena—explained he has hired two independent third-party intrusion companies to regularly try to hack his CUs’ systems to learn where vulnerabilities lie.
No Guarantee
“This is no guarantee criminals won’t get through, but if we can identify our weaknesses we can certainly stop some attacks before they happen,” said Hernandez, who acknowledged the approach is not cheap.
But the price is worth it, insisted Hernandez, who said it is time for small credit unions to look at doing away with services that are not being used to channel money toward cyber-security.
Busseri thinks all the costs and additional compliance burden coming small CUs way from growing cyber-threats will certainly force mergers. “Unfortunately the table stakes are lot higher today and could force some consolidation.”
Stickley said small CUs now face a data security “tidal wave” coming over them, and agreed that many more may throw in the towel. “How do you possibly fend that off? Small credit unions are in a tough position, and I hate to see that, because I love small credit unions.”
