By Ray Birch
BALTIMORE—Credit union leaders feeling uneasy in the wake of a ransomware attack that has affected 60 credit unions should be taking steps now to protect against potential threats and to recover more quickly in the event of an attack, according to one cyber security expert. And that begins with two questions.
“If you're feeling uncomfortable or uneasy the number question is, do you have cyber insurance?” said Think/Stack VP of Security and Risk Jennifer Anthony. “If the answer to that is yes, have you spoken with your broker and know what would happen if a ransomware attack happened in your organization tomorrow? Those are conversations that you all can have right now.”
In this, part two of a two-part series highlighting recommendations to credit unions related to ransomware attacks (part one can be found here), Anthony shared her perspective via a webinar hosted by the cybersecurity firm Think/Stack aimed at providing CUs with insights and answers in light of the recent ransomware attack that hit the five-dozen credit unions that all shared the same data processor.
Detailed Conversations Needed
Anthony emphasized having detailed conversations with the insurance provider to learn how it would respond, especially since the after-effects of a ransomware attack typically can play out over nine months.
“Do you know what your coverage is, and do you know how that insurance plan will execute across those nine months?” Anthony asked.
While getting answers to those questions, Anthony said another step a credit union needs to take is to talk to its internal or external legal team.
“Have conversations with them,” said Anthony. “We think this is an important piece.”
Disagreeing With Attorneys
During those discussions Anthony said it’s likely attorneys will likely advise the credit union not to say anything to the media, or simply not speak with those outside the organization if the CU is attacked.
But she doesn’t agree with that strategy.
“Our feeling is that's not congruent with the way the credit union community operates,” she said. “I'm not telling you to go against the advice of your legal counsel, but I am saying that you're likely going to be advised not to talk. So, right now is the time to have that conversation with your legal team, and if you decide you are going to say something, what are the right words. You can be doing that right now.”
Conducting Tests
It’ also time to test disaster recovery plans.
“When NCUA comes and gives your disaster recovery plan a check mark and says you’re good to go, it's not enough,” Anthony said, stating NCUA is looking at the plan from a compliance perspective and not a pure data security position. “You need to use that disaster recovery plan. Have you tested that your backups work? We’re suggesting you take it a step further.”
Anthony, as many experts have stated in previous CUToday.info reports, emphasized staff are the biggest concern when it comes to ransomware attacks.
‘Can’t Say This Loudly Enough’
“I can't say this loudly enough: your employees are your biggest vulnerability,” she cautioned. “You can buy every single state-of-the-art cyber tool to keep you safe. You can partner with every single state-of-the-art vendor to keep you safe…We just can't overstate that you need to do a specific amount of staff training and you're probably using some tool to do it. But are you also having these conversations at your staff meetings, those kinds of things?”
Outside of training, the credit union must help staff understand their on-the-job insights, opinions, observations and concerns are valued and are a necessary element in the fight against ransomware, Anthony advised.
“Are staff empowered to say, ‘Wait a minute something about this doesn't feel right. I need to pause here and I need to talk to my boss, or I need to contact IT because this feels funny to me’,” Anthony said. “Almost after every (ransomware) incident with a client we always hear somebody say something about an employee who said something didn't feel right to them. ‘I wasn't sure’…Make sure that your staff, when they have that feeling, they do something. Make the right people know about it, and listen.”
Need for a Response Plan
Anthony said every credit union needs to have an (ransomware) incident response plan embedded into its disaster recovery plan.
“Your disaster recovery plan disaster could cover lots of things—a hurricane, a massive snowstorm…But an incident response plan is going to be specific,” she said. “Do you have a written plan for that, and does it include the stakeholders it needs to include? Have you practiced that plan with your key vendors? Have you practiced that with your legal team and your marketing and public relations teams? Having that plan is awesome, but understanding how to really utilize it is key.”
Time to Have the Talk
As the recent ransomware attack shows, all the planning, however, cannot protect the credit union from threats over which it has little control, Anthony reminded.
“The credit union community is highly dependent on vendors,” Anthony stated. “Have conversations with your vendors today and have them tell you what they’re doing for incident response.”
