WASHINGTON—Whether from an unexpected investment return, the upcoming Share Insurance Fund distribution, or just plain luck, what should a credit union do if it finds some extra budget money this year?
NASCUS said it has spent a lot of time looking at the issues its member credit unions are facing, and has recommendations on prudent ways to invest that extra capital.
The insights are being shared as part of a CUToday.info series on what to do with unexpected budget surpluses, such as the payment from the NCUSIF many credit unions will receive this year.
“It’s probably no surprise that our first set of recommendations are around cybersecurity,” said NASCUS President and CEO Lucy Ito. “When I talk to credit union CEOs, cybersecurity tends to be one of the most daunting and frustrating issues they face. It can seem like there is no limit to how much you can spend, because when it comes to cybersecurity credit unions need to win 100% of the time since the hacker only needs to win once. The good news is that even with just a modest investment there are some simple steps that can help any institution boost its cyber defenses.”
NASCUS’ tips on cyber security:
- Have the CU’s cyber risk assessment validated by an outside firm. “Whether the third-party review validates your product or generates recommendations for changes, your cybersecurity program will feel the benefit from a third-party review,” Ito said.
- If money is available, do penetration testing. “This is the best way to know if your systems and staff protocols are up to snuff. While we often focus on digital vulnerabilities, the biggest cyber threat remains human capital,” reminded Ito.
- Listen to the experts. “Financial cybersecurity conferences, like the one NASCUS holds each June, are the best way to get the most current information broken down so that makes sense for your institution,” Ito said.
Other Compliance Issues
As much as CUs are focused on cyber, they can’t forget FinCEN is still looking closely at credit unions’ adherence to Bank Secrecy Act/Anti Money Laundering/Counter Terrorist Financing rules, NASCUS reminded.
“Whether it’s managing MSB (money service businesses) accounts or doing business in the 30 states that have legalized some form of marijuana, issues related to money laundering compliance remain just as pressing as those related to cybersecurity,” said Ito. “If you’re worried you haven’t been doing enough to keep up, a few well-placed dollars can go along way to making sure you don’t fall behind.”
NASCUS’ tips:
- “While it may not be the compliance department on the front of your mind, make sure you have enough staff for your BSA risk assessment,” Ito said.
- “If you haven’t done so already, evaluate whether additional investment in monitoring software is needed. This will make the compliance process easier, safer and more effective,” she said.
Don’t Forget This
Ito said that while all CUs know how critical it is to look toward the horizon and prepare for the future, she wonders if everyone is looking in all the right places.
“Ever since FASB published the Current Expected Credit Losses (CECL) model, NASCUS has been talking to our members and holding regional training events to ensure they are ahead of the curve,” Ito said. “The new CECL model will change everything from how we collect data to how we calculate the allowance for loan losses, which is why this issue will be a big topic at the NASCUS National Summit in Orlando in July. While it won’t go into effect until 2021, it’s never too early to begin preparing for the implementation.”
The CELC guidelines are public, and Ito shared steps to take today:
- Work with the CU’s vendors to make sure they are aware of the change and are starting to capture the right data to be compliant down the road.
- Look at the CU’s internal data reporting to ensure the credit union has the ability to both capture and sort its data in ways that will give the organization the information the CECL model will require.
- Consider early adoption to smooth the CU’s way into 2021.
Final Recommendations
Ito’s final recommendation cuts across all her advice. She said training is vital for successfully implementing any of the above ideas.
Her training advice:
- “For cybersecurity, that means training your staff to make them both aware of and immune to social engineering threats,” she said.
- “For BSA, it’s critical that staff receive training on reporting requirements and identifying suspicious activity,” Ito said.
- “For CECL, it’s never too early to start training staff on the new accounting model. Major changes like this can be stressful for new and veteran employees alike and giving them time to get comfortable can do a lot for office morale,” Ito said.
“Here’s a bonus training idea: More and more regulators are expecting credit union boards to be knowledgeable on everything from cybersecurity to CECL,” said Ito. “When was the last time you reviewed your directors’ training opportunities? As the only organization serving both credit union executives and state regulators, NASCUS regularly holds trainings specifically geared toward directors.”
