NASCUS Coverage: An 'Extra Layer Of Security'

ORLANDO—In the event of a catastrophic cyber attack, one expert hopes that smaller institutions, like credit unions, have more than just their existing backup plans to ensure business continuity.

Feature NASCUS Plan C

At the NASCUS Summit here, Trey Maust discussed the benefits of a new cyber resilience initiative, Sheltered Harbor, that provides its members with an extra layer of security. If a catastrophic cyber attack brings down a member financial institution’s data, including backups, another FI takes over. Essentially there’s a financial institution and a backup financial institution, explained Maust, who is CEO of the organization.

Sheltered Harbor is a not-for-profit subsidiary of FS-ISAC founded by 34 financial institutions, clearing houses, core processors and industry associations. Sheltered Harbor began to be formed following the massive Sony attack. Maust told the meeting that several large banks and industry experts gathered to look for a new way to further protect the financial system than just the current data recovery plans and backup systems in place at each financial institution.

DSC_0391

Trey Maust

‘You Wake Up One Morning And…’

“Cyber attacks are always at the top of the list of things that keep financial institution CEOs up at night,” Maust said. “You wake up one morning and you find the credit union has been hit by a destructive cyber attack. It takes all of your primary and secondary systems down and you have no way to bring the network back online, at least in some form and not in any kind of speedy fashion.”

Maust said that would likely lead to weeks or even months of downtime.

“Meanwhile what do your members do?” said Maust. “They need to check their accounts, get cash, there would be panic.”

One Big Concern

What concerns Maust is that currently large institutions are the ones participating in Sheltered Harbor.

“We have about 70% of all U.S. deposits in Sheltered Harbor,” he said. “But this represents 1.5% of U.S. financial institutions, and I don’t want to see the largest FIs as the only ones protected. I don’t want to see that in two to three years the largest banks are protected but the medium and small institutions are not.”

Maust emphasized that Sheltered Harbor is not something an institution simply joins. He said it takes time for an institution to work through the three steps of the Sheltered Harbor process—data vaulting, resiliency planning and certification.

All participating institutions, on a regular basis, make a copy of their consumer account data in a standard format, which enables the restoration of accounts by the partnering FI in the event of a major outage. The account data is archived in a secure data vault that is protected from alteration or deletion.

‘Take This Seriously’

“Banks and credit unions that want to participate should start the process as soon as possible,” said Maust, who noted that the program will formally launch in the fourth quarter of 2018 and that a large number of additional FIs are expected to join in August. Fees are based on the size of the institution. Until late last year, Sheltered Harbor had been operating quietly to get its standards complete and to get early adopters testing the process, Maust said.

“Financial institutions should take this seriously,” insisted Maust, referring again to how crippling the attack on Sony was. “We now live in a world in which a destructive cyber attack on the financial system is a concern, and I don’t want the small institutions to be the ones who are the biggest victims of that.”

Section: Standard
Word Count: 773
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/NASCUS-Coverage-An-Extra-Layer-Of-Security