CHICAGO—Beefing up cyber security can be costly, but there are inexpensive steps credit unions can take that will improve defenses and not require new software or hardware, according to one person.
Chad Carrington, vice president for IT, cyber security, and facilities for Golden 1 CU in Sacramento, Calif., said his $10.2-billion CU has made some adjustments to its cyber defenses in the last several years that are not costly and have resulted in some significant enhancements to its ability to thwart fraudsters.
“All of the things I am going to talk about today don’t require specialized software, and you have the capability to do these today, no matter your size,” Carrington said during the 2016 NASCUS/CUNA Cybersecurity Symposium here. “The thing is you have to have the dedication to do this. Because it does require a great deal of dedication.”
Carrington said the six steps are:
- Strong patching
- Inventory and validate the web environment
- Remove PC admin rights from the general population
- Ensure web and email have strong filters
- Introduce a proper logging and alerting system
- Have a strong business continuity and disaster recovery plan that is exercised regularly
Patching
Of all the steps, Carrington emphasized the critical importance of ongoing and thorough patching.
“You patch, patch and patch, and then you patch some more,” said Carrington. “We have over 7,000 devices that need to be patched in our shop. We have been doing this for six years.”
When a patch is applied, make sure users have 10 days to test.
“If no one says anything after that time, we go live,” said Carrington. “We use the free tools from Microsoft. When you look at all of the studies on data breaches the lack of patching is the number one cause for breaches.”
Inventory And Validate The Environment
“You need to know where everything is within your environment,” said Carrington. “The only way to protect your house is to know what is in your house. Every three months use a tool that reads everything that goes through our registry. We do this ourselves. Software you will buy to do this, we have found, is not useful.”
Carrington said the exercise will lead the credit union to find some “interesting things.”
“You think you have things locked down, but you will be surprised by what is not,” he said.
Carrington said that besides the formal audit, he will randomly ask an IT staff member to give him the inventory on the environment right when he walks through their area.
“This is a good exercise to challenge your team to know the environment, all the time,” said Carrington.
Remove PC Admin Rights From The General Population
From the CEO, all the way down to the front line, no one (outside of IT) has admin rights on their computers at Golden 1.
“I know this, culturally, can be challenging,” said Carrington. “But this is a critical to do.”
Carrington said he realizes some software programs offered by vendors insist that users have admin rights.
“But they are wrong. No program needs that,” he said. “And if that is something a vendor insists on, we don’t use the software. And no third-party plug-ins are allowed, as well.”
Ensure Web And Email Have Strong Filters
Golden 1 has a “white list” of 300 websites its staff are allowed to visit, and no others, explained Carrington. The CU uses a web filtering tool to monitor staff activity. The credit union also uses an email filtering tool.
While Carrington acknowledged that most CUs use these tools, where they fall short, he said, is by not “tuning” them—learning all the tools’ capabilities and then adjusting them to address the habits and needs of the credit union.
“These two tools need to be tuned all the time,” said Carrington. “You can’t just put them in and let them go. It can be helpful to use a third party to assist you with tuning. By using these tools and tuning them, in just the last two months we prevented 700 malware packages from coming inside.”
As other cyber experts have cautioned, Carrington pointed out that malware can enter through compromised advertisements that run on websites that are considered to be safe to browse.
Introduce A Proper Logging And Alerting System
Carrington said that using a proper logging and alerting system allows the CU to see the “tips of the spear,” when a system intrusion may be starting.
He said Golden 1 regularly looks at the “intelligence data” and in doing so has learned the typical signs that a hack that is starting.
“You just need to know what to look for,” he said. “We primarily look at six different things—telltale signs that something is going on.”
Golden 1 monitors:
- To see if anyone has attempted to become a local administrator
- If anyone has attempted to log on to more than one PC in about a ten-15-second window
- Who or what is being added to a domain active group
- Any logons that occur between 10 p.m. and 6 a.m. that are not from an IT person
- Failed logon attempts from more than one user in a five-second timeframe.
- To see if anyone is attempting to run PowerShell on their desktop
“We don’t allow PowerShell to run on our environment (for staff outside of IT, and then for only special circumstances),” said Carrington. “You can take over entire company quickly with PowerShell.”
While the steps are important they won’t be as effective if upper management does not support the efforts, which helps all other departments fall in line with the mandates and practices, said Carrington.
“I know we are a big credit union, but this works for any size CU,” said Carrington. “You can take them on with the resources that you have. And just take on what you can with what you have. I can tell you that if you do these things well, the examiners and auditors will focus on more meaningful things when they come in.”
