Changing Cybersecurity Rules Become a Threat

By Ray Birch

KALAMAZOO, Mich.—A credit union with a highly-graded cybersecurity program could find itself with less than a passing mark in the not-too-distant future, warn experts, who say the rapidly evolving state rules around securing consumers’ personal data could be the reason.

Cybersecurity attorneys at Honigman LLP shared with CUTodayinfo their concerns following a recent report that reveals credit unions are doing a good job at protecting their members’ personal data.

Feature Cybersecurity Grade  ow

A new report from cybersecurity firm Black Kite gave credit unions a “B” grade for their state of security, meaning “cyber breaches would require the skills of persistent, highly experienced hackers.”

Michael Hindelang, co-chair of the data privacy and cybersecurity group at Honigman, recognized credit unions for their efforts to keep their members’ data protected.

Experience Required

“Whenever you give something a letter grade, it's always open to interpretation,” said Hindelang. “But what Black Kite says in the report is a fair description of credit union defenses.”

In his work with credit unions on cybersecurity matters, Hindelang said he has learned it would take an experienced crook to penetrate the typical CU’s cyber defenses, which was also the conclusion of the Black Kite study.

“The average hacker poking around in his parents’ basement is likely to have difficulty accessing systems because of the security efforts credit unions are taking,” said Hindelang. “But when you have a direct, concerted effort to break through security systems from a highly experienced attacker, almost anyone is vulnerable. You know the saying, ‘They don't build castles anymore for a reason.’  Crooks will always find a way to get in. But the Black Kite reports shows credit unions have serious defenses at work, and I would say it covers all asset-size CUs.”

As CUToday.info reported, Black Kite reviewed 250 NCUSIF-insured credit unions and 150 of their commonly used vendors.

Credit unions did not receive an A grade in part,  as Black Kite pointed out, most credit unions and their vendors “experienced leaked employee credentials, employed poor software patch management practices, and used insecure email networks. These vulnerabilities create the opportunity for significant financial impacts if credit unions are attacked directly or via a third-party that has access to credit union networks.”

Hindelang, Mike 11-12-14 (500px)

Michael Hindelang

Breaking Down the Costs

According to Black Kite, direct attacks to credit unions have resulted in estimated annual financial risks ranging from $190,000 for small credit unions to more than $1.2 million for large credit unions. Potential third-party attacks through credit union vendors pose a higher financial risk, the company said.

Hindelang said there is a reason credit unions’ defenses are sound.

“Financial services one of is one of the industries that’s well regulated, so it's not surprising to me to see that the majority of FIs that were involved in the survey have a satisfactory rating, given there is just so much guidance,” Hindelang said.

But CUs, as well as all organizations, could benefit from attention to staff training. Jad Sheikali, a member of the data privacy and cybersecurity group at Honigman, said that in his work with credit unions involving security breaches he has seen a common weakness.

“It’s the same weaknesses for all businesses, which, unfortunately, is the human factor,” Sheikali said. “No matter how good you make your technical defenses, no matter how good you get at making everything run securely on your systems, you still have people interacting with those machines. They fall prey to phishing attacks, those are the common things we see.”

‘Something is Not Right’

Hindelang said strong employee training programs help staff gain a strong sense that “something is not right” regarding an email, for example.

“If employees are well-trained, they will be much less likely to click on that link, that to a well-trained eye looks suspicious,” he said.

But despite all that, Hindelang said those credit unions feeling comfortable with their level of cybersecurity defense could soon find themselves scrambling to make adjustments, due to changes being made in privacy laws in some states.

Jad_Sheikali_500px

Jad Sheikali

As CUToday.info reported, over a year ago the California Consumer Privacy Act (CCPA) took effect—and many other states have since followed with similar proposals—all of it requiring credit unions to invest significant time and money to update data privacy policies and procedures.

A Big Challenge

Hindelang said the new laws present one of the biggest cybersecurity challenges ahead for credit unions.

“The landscape of data privacy laws in this country is changing rapidly,” said Hindelang. “The policies you developed on risk assessments, even a year ago, have changed in the interim, because the privacy laws are based on the current residence of individuals. If you're a local credit union somewhere in the Midwest and you have members who keep their accounts with you as they move around the country, you may find yourself subject to a variety of laws that have a number of different legal repercussions concerning not only what to do in the event of a breach, but also what constitutes personal information.”

‘California Started This’

The speed of change within this legal landscape is something that's fairly unusual right now, as normally law moves slowly, noted Hindelang.

“California started this, now suddenly many other states are jumping out of the woodwork with their own sets of laws and regulations,” Hindelang said. “The best way to put it, is you can’t just rest on your laurels anymore, because what was an A-plus cybersecurity program today may be a C-plus program in a few short months.”

Section: Standard
Word Count: 1244
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Changing-Cybersecurity-Rules-Become-a-Threat