NCUA Outlines What's Ahead

By Ray Birch

ALEXANDRIA, Va.—NCUA plans to slowly roll out its new cybersecurity examination tool next year, and a focus will be on creating a program that takes into consideration the size and complexity of an institution, the agency said.

The credit union community has been expressing concerns that NCUA may introduce what has been called a one-size-fits-all approach to cybersecurity examinations, which analysts and credit unions have stated could be too costly and time consuming for many credit unions to manage, particularly small ones.

The agency’s Office of Inspector General (OIG) recently audited the current version of NCUA’s new tool—Automated Cybersecurity Examination Tool (ACET). The self-implemented audit was conducted by the OIG from February 2016 through September to determine whether the NCUA's IT examination program provides adequate oversight to credit unions' cybersecurity programs and whether credit unions are doing enough to protect member information from cyber-attacks. 

Tim Segerson, NCUA’s deputy director of Examination and Insurance, told CUToday.info that the agency is still refining the tool based on feedback from credit unions and staff.

“Our overall goal is to have the tool fully scalable and completely flexible so it will work for small and large institutions alike,” said Segerson. “We are committed to being open and transparent with the industry about cybersecurity. We believe we can make the greatest inroads by collaborating and not forcing change.”

Segerson explained that during the initial testing of ACET earlier this year that NCUA received feedback that the tool was cumbersome. Segerson said ACET has been tested with 60 credit unions and 60 NCUA staff members.

“During our initial testing we got feedback, such as the document we were requesting was overwhelming, and I agreed with the audience,” Segerson said. “So we are reverse-engineering ACET so that we are only looking for the supporting information that we need based on the profile of the institution, as opposed to an all-encompassing list.”

Refine ACET

The agency plans to continue to refine ACET through the end of the year and then field test again in small groups of various size credit unions.

“We want to right-size this for the industry,” said Segerson.

Andrew Morris, NAFCU regulatory affairs counsel, said a key concern the trade association has is that the cybersecurity tool will be too prescriptive and apply requirements broadly across all credit unions, regardless of size.

“We have not seen any information on NCUA’s new tool, but if you read the OIG report they go through this mapping of the NCUA’s existing cybersecurity exam questionnaire to the NIST (National Institute of Standards and Technology) framework,” said Morris, noting that it has been expected that the agency’s new cyber exam process will follow the NIST and FFIEC (Federal Financial Institutions Examination Council) cybersecurity guidelines.

Morris explained that the OIG also mapped the new NCUA program to the same NIST and FFIEC guidelines and concluded “this new tool is a much more sophisticated and broad examination tool, much more expansive in scope,” Morris said. “However, without actually seeing the tool, it’s hard to tell how complex it will be or what the scope of exams will look like.”

Segerson said that ACET mirrors FFIEC and NIST guidelines and is not more expansive. He emphasized again that the agency is working with credit unions to design a process that works for all institutions. But he also cautioned that times are changing.

“We are moving into a very digitally driven economy, especially within the financial services sector,” he said. “The institutions that are not operating in that environment are not going to succeed, and they will eventually wither and die. So cybersecurity is going to be an increasingly important component of our jobs here at NCUA, so we are highlighting this with the industry and getting them to focus on cybersecurity.”

Not Mandatory

What the agency is doing, stressed Segerson about the tool that is not mandatory, is saying, “This is a risk management process that you have to consider and have to incorporate into your overall risk management program. This process may be rudimentary for small institutions, and we can live with that, and it may be more comprehensive in the larger, more connected credit unions.”

Tim Segerson

Segerson said NCUA is taking its time to look at the most common strategies credit unions might use to build their security programs so CUs can easily cross reference them with NCUA’s ACET guidelines. NCUA is also building a benchmarking tool that will cross reference other major cybersecurity frameworks and guidelines that a credit union may use, such as those from the NIST and FFIEC, with ACET.

“We want institutions to quickly see the interoperability, and our examiners can quickly see if an institution is using a different approach and how that lines up with what we are doing,” said Segerson.

Segerson emphasized that with ACET, NCUA is not mandating specific cybersecurity methods.

“We are not forcing credit unions to recreate the wheel,” he said. “If they have a process in place that is effective, we are not telling them to change that. But if they don’t have anything, then we recommend  ACET as the place to start.”

A lot of credit unions are managing cybersecurity well, said Segerson.

“Our goal is to make sure we have a good baseline set of expectations and that we are making sure we communicate that during the exam process,” he said.

NCUA expects it will slowly roll out ACET during exams sometime in 2018, among the largest, most complex credit unions first.

“We want to make sure we have ACET exactly where we need to have it,” said Segerson. “We have put a lot more supporting information into it. The CAT (Cybersecurity Assessment Tool) is a basic set of practices, behaviors and standards that an institution could then benchmark its program around. We have extended that out with ACET so there are plain language explanations on each component, as well as supporting information on what types of reports, documents or policies are required to support a credit union’s practices. We have built a more comprehensive, supported approach around the CAT. We want to get this as clean, efficient and effective as possible before we fully deploy it.

More Burden?

As CUToday.info has reported, some large credit unions have said the agency has been testing its new cybersecurity exam process during the exams they have gone through. One credit union, asking for anonymity, told CUToday.info that NCUA’s new approach was much more time-consuming and costly for the credit union, with this person expressing concern for the future of small credit unions if they have to absorb yet another expense and time demand on staff. However, that exam was conducted about a year ago.

“An overbroad cybersecurity exam that is not tailored to the complexity of the credit union could impose a substantial burden on the CU,” said Morris. “NAFCU supports the adoption of a voluntary cybersecurity framework that can be adjusted based on the credit union’s own needs and understanding of the environment they operate in.”

Segerson said that there will always be “naysayers,” stating that ACET is another example of NCUA layering on another burden.

“But this is not NCUA, this is the world changing,” stressed Segerson. “We all need to pivot when the world pivots, and the word is pivoting on us right now.”

Section: Standard
Word Count: 1377
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/NCUA-Outlines-What-s-Ahead