Time To Step Up Security Protocols?

By Ray Birch

RANCHO CUCAMONGA, Calif.—The rapid rise of crime-as-a-service (CaaS) should have credit unions stepping up their security protocols, asserts one analyst.

Paul Love, chief information security officer at CO-OP Financial Services, says the rise in CaaS now places smaller organizations in the crosshairs of crooks.

“Early on the attackers focused on the big organizations; they wanted a big payday,” said Love. “But as larger organizations have strengthened their defenses, attackers are looking for easier targets that are paying less attention to security. They will take a number of smaller paydays now, which in the end they know add up.”

Love said that criminals are doing their research on organizations to see which are sophisticated and which are not when it comes to cyber defense. He said credit unions, as a result, are coming up more on fraudsters’ radar.

What is really concerning, said Love, is that CaaS is not only making it easier for crooks to hack into organizations, it is allowing more people to commit these crimes.

CaaS describes a new reality in which a professional criminal or group of criminals develop advanced tools, “kits,” and other packaged services, which are then offered up for sale or rent to other criminals who are usually less experienced. It lowers the bar for inexperienced hackers to commit more sophisticated cyber attacks.

Outsourcing

Love said CaaS also means outsourcing criminal activity.

“CaaS has been around for years and it is evolving,” said Love. “Just like corporations evolve, so has CaaS. It’s like the first version of a product is often rough around the edges and then is streamlined. We are seeing CaaS offerings getting easier and easier for criminals to use.”

When CaaS first started, a great deal of the work was placed on the criminal executing the attack.

“These CaaS companies would say, ‘We can create malware for you, but you have to figure out how to deploy it and monetize it,’” explained Love. “But now these offerings have improved dramatically and some have become full service. They say, ‘OK, you want to cause damage to a company, we’ll assign you a project manager, ID your requirements and they will run the whole attack for you and just give you the results at the end.’ CaaS has gotten slicker and the barrier to entry is far less than it used to be.”

Paul Love

Fraudsters no longer even have to have any technical prowess, Love said.

“Back in the day the attackers had to know how to code, deploy, gather information and how to monetize the attack,” he said. “Not anymore. Just outsource work. CaaS is evolving into a fully managed service capability.”

Love said if someone chooses to use a kit to commit their crime, they now have a high level of support from the kit’s manufacturer.

“You can buy different tiers of support, just like for software,” Love said. “So, the silver level gives you support from eight to five, and gold gets you 24/7. These organizations have call centers to support their malicious software.”

Don't Become A Target

What this means for credit unions, insisted Love, is that they must make sure their approach to security is not placing them high on criminals’ attack lists.

“Have someone focus on information security. If it is not a dedicated person at least have someone in the organization who is responsible for setting up the information security programs and putting in some of the security controls you would expect, such as monitoring for malicious activity,” he said. “Then make sure you have a system to regularly install software patches.”

Also, make sure staff understand their security obligations and that they play a significant role in preventing cyber crime.

“They need to know the basics, like not clicking on links or opening files they are not certain have come from trusted sources,” said Love. “The credit union should also conduct internal phishing tests to see how well employees are performing. Follow these steps because hackers, with CaaS on the rise, are going after those who are the weakest—and they know who that is.”

Section: Standard
Word Count: 793
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Time-To-Step-Up-Security-Protocols