CARMEL, Ind.—Credit unions are doing a better job of enhancing their cyber risk management strategies to include more advanced risk controls, but employee education continues to often be overlooked as one of those controls, according to one analyst.
News stories about lost thumb drives, misplaced laptops, and employees becoming victims of e-mail attacks that open the organization’s doors to criminals point to the need.
“With cyber attacks increasing, credit unions need to make employee risk education a top priority, so staff members at all levels of the organization can help the credit union detect and prevent future fraud risk exposures,” said Ann Davidson, VP of risk consulting at Allied Solutions.
Davidson said regular risk training should be provided to employees in order to instill a “data security culture” within the credit union.
Training Topics
Davidson said employee risk education training should touch on the following:
Common cyber threats and security risks, and the related vulnerabilities and threats to credit union operations. “So employees understand the gravity of these potential breaches,” Davidson said.
Common warning signs for different types of fraud attempts. “So staff know what to look out for and report,” added Davidson.
The nature of data security and reminders that each employee is individually responsible to help protect the credit union’s data.
Legal and regulatory obligations to respect and protect the privacy of secure accountholder and credit union information.
A procedure for incident reporting in the event a device being used on the credit union’s network becomes infected by a virus or is operating with unexplained errors, “including the importance of common warning messages and alerts and who to report incidents to,” Davidson said.
Employees should follow workplace policies to help prevent cybercrime, such as:
- Internet and social media usage: Internet browsing should be limited and social media usage should not be permitted while at work, Davidson said.
- Software usage: Employees should not install unlicensed software on any work device.
- Personal device usage: Employees should not use their personal computer, tablet, or mobile device while on the credit union’s network.
- Work device usage: Employees should not leave workplace devices unattended without securely locking them and should ensure virus protection software is kept current, Davidson said.
- Password usage: Employees should be required to use strong passwords that are unrelated to their personal information, and different for every secure account.
- E-mail usage: Employees should never respond to e-mails or open e-mail links that look suspicious or are from unknown sources, Davidson said.
Stay Step Ahead
Davidson said that without proper employee training it is difficult to battle growing cybercrime.
“That’s why it is critical that the credit union remain one step ahead of the cybercriminals by educating employees about the part they need to play in protecting the credit union from these potential exposures,” Davidson said.
