'Problematic' Cyber Defense Issues Among CUs

By Ray Birch

BOSTON—In a rare instance in which being a small credit union has its advantages over being large, one cybersecurity study reveals small shops may be doing a better job at protecting member data than the big boys—but all credit unions continue to have vulnerabilities.

Feature black Kite  Low

“When you look at the cyber security grade level of smaller credit unions, they tend to be a little higher than their larger counterparts,” said Bob Maley, chief security officer at Black Kite. “This is often because they have fewer exposed points—they don't have the amount of assets the larger organizations do, so there are fewer avenues they have to lock down.”

Overall, the new Black Kite report gives credit unions and their vendors a “B” grade for their state of security, meaning cyber-breaches would require the skills of persistent, highly experienced hackers. The cybersecurity vulnerabilities among credit unions and vendors are included in the report titled “2021 Third-Party Risk Pulse: Credit Unions and Vendor Ecosystems.”

“B is a fairly good grade level,” said Maley. “It would require a sophisticated attacker to succeed. Obviously a nation-state could compromise anybody.”

Consistent Vulnerabilities

While credit unions are doing well with their cyber defenses, Maley said the report nonetheless reveals some consistent issues among credit unions with their fraud protections, processes and habits.

“We did notice there were a few areas in the report that were problematic for credit unions,” Maley said. “Across the board, and we also see this with many other types of organizations--patching is an issue.”

Maley explained sometimes credit unions fall into the trap of thinking the installation of a new security patch means they are now secure.  

“However, as time goes on, and if your systems get older, the complexity of those patches can cause vulnerabilities,” he said. “And, some of the systems we see are so old, there aren't any patches available.”

Similarly, credit unions with older data processing systems are the most vulnerable, Maley said, adding fraudsters know this.

“The bad actors won’t always test an organization’s system to see if a patch has been implemented; sometimes they just look at the age of the system,” he said. “The older the operating system the more likely it will be targeted by criminals and they will likely find a way in.”

Behind on Phishing, Spoofing

Phishing

Another area in which credit unions are trailing many other types of organizations, according to Maley, is in warding off phishing and email spoofing efforts.

Maley explained there are ways to protect an organization from these types of criminal assaults. He said employing DMARC (Domain-based Message Authentication Reporting and Conformance) is the best approach. DMARC is an email validation system designed to protect a company’s email domain from being used for email spoofing, phishing scams and other cybercrimes. DMARC leverages the existing email authentication techniques SPF (Sender Policy Framework) and DKIM (Domain Keys Identified Mail).

Maley explained DMARC ensures staff will only see emails that are legitimately from other employees, preventing others from sending emails using the CU’s domain.

“DMARK is very effective at stopping anyone from spoofing your email address and from conducting phishing campaigns,” said Maley. “DMARK puts a digital signature on your emails that is extremely difficult to spoof.”

Maley said when emails seek to travel through a company’s system without a DMARK signature, they are automatically flagged as spam and never reach the end user.

“This is very important,” said Maley. “In looking at our report we see that about 88% of credit unions don’t have a DMARC policy in place. That is a key flaw among credit unions.”

Threat Via Vendors

Maley added the flaw exists with numerous credit union vendors, as well, which could lead to crooks conducting phishing and email spoofing attacks against credit unions using their business partners. He pointed out, too, many vendors that work with credit unions have blacklisted IP addresses, meaning reports indicate malware is emanating from their IP.

“That doesn't necessarily mean the malware is on the side of the vendor, it depends on how that vendor has their infrastructure deployed,” said Maley. “A lot of times a vendor will have infrastructure that uses a shared IP address.”

Section: Standard
Word Count: 922
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Problematic-Cyber-Defense-Issues-Among-CUs