By Ray Birch
EUGENE, Ore.–Credit unions already know they have “too many doors” vulnerable to cybercrooks. The challenge comes in closing them–and ironically, several IT experts are offering some “keys” for doing so.
Where credit unions should be focused on, say cybersecurity experts, is shrinking the attack vector and limiting access points for cybercrime.
But that’s obviously easier said than done, acknowledged Brandon Harvey, senior director of technology at $1.2-billion Northwest Community CU here, as the days of protecting the data center and its servers have drastically changed.
“Whereas traditional IT defense was once focused on hardware, it’s now mobile and cloud-based and …,” said Harvey. “Things are much different today than 10 years ago regarding securing data.”
The key, said Harvey, is not spreading the credit union too thin, giving crooks too many access points and making it hard for the CU to effectively or affordably defend them.
“It’s just like having four doors to your house you have to protect,” he said. “For each door you have to have a security solution, dedicate time and human resources to protecting it, and then pay for that. Credit unions need to consolidate their egress points.”
Using Private Networks
Harvey said it is critical to aggregate network traffic so the credit union is protecting one point. He’s not alone in stressing that point.
“You don’t want to have data going out to the Internet from each of your branches,” said Milan Patel, chief client officer, managed security services at cybersecurity firm BlueVoyant. “What more financial institutions are doing is taking branch traffic and sending it back to a private network. Say the private network is located at the headquarters office. So whether my branch is three miles or 300 miles away from my main office, I am first passing my branch data traffic through a secure tunnel to headquarters, which then transfers the data out to the Internet. All of the traffic from the branches is hidden, behind the scenes.”
What the crooks then see, explained Patel, is one point of access to the credit union. “It then become easier and more cost effective to protect your members’ data,” he said.
‘Holistic Defense’
But Patel acknowledged that is just part of the defense solution and with crooks able to gain access to member data through touch points out of the credit union’s control, such as payment cards, PayPal, P2P, more of a “holistic” defense solution is needed.
“Yes, it used to be about protecting a single data center, and a lot of transactions were paper,” Patel said. “Now that has completely flipped, with many more access points, many more digital transactions and little paper. The defense needs to be holistic—not just protecting your on-premise data but data members are sharing when they’re swiping their credit cards or are using PayPal.”
The thinking about defense needs to change, said NCCU’s Harvey, who stressed it’s getting more important with security to “meet our members where they are. Which, more and more, is not coming into the branches. They want to use their mobile phones and do their transactions not even from a physical computer. They want to transact on their watches, on their tablets, on their iPhones and on their Android devices. It's a complete shift in security thinking.”
The First Thing to Understand
Nayan Patel, VP of strategic alliances at Fiserv, said a CU needs to first understand its most critical assets and identify where they might be vulnerable.
“This is not a one-time exercise, rather an ongoing mission,” he said. “Once assets and potential vulnerabilities are identified, proper point solutions to protect those areas should be implemented, managed and monitored. One tactic many credit unions are not executing today is taking information from all of their various security solutions, including next-generation firewall, data-loss prevention, user behavior analytics, etc., and using all that data together to execute comprehensive threat detection.”
Another useful tactic, Fiserv’s Patel said, is to automate processes so that “meaningful, actionable intelligence” can be provided to analysts as soon as possible to prevent an incident from becoming a breach. Automation can also make investigations quicker and more efficient, he added.
Growing Sophistication of Scammers
All of the experts agreed with a point challenging institutions of all kinds—just as defenses have become more sophisticated, so have the skills of cyberthieves.
“The adversary’s education is increasing and they are getting broader,” explained BlueVoyant’s Patel. “More cybercriminals are getting into the market today because the tools by which they commit these crimes are easily attainable. You don't have to be a cybersecurity expert or a programmer to use some of these tools that are designed to hack into an organization.
“So we're seeing more bad actors globally, and were also seeing a sophistication from our adversaries,” continued Patel. “Over the last 10 years we have gone from short, solo acts from individual criminals to full-fledged criminal organizations that have an infrastructure—a marketing team, a sales team, a customer service team.”
BluVoyant’s Patel also warned that crooks’ targets are changing, and that smaller organizations are now on their radar.
“It used to be the big banks were the targets,” he said. “But crooks are saying that targeting the big banks is no longer returning the ROA they are looking for. Now they are turning more toward smaller organizations because they know they have to protect their data 24/7 and often lack the sophisticated operations and expertise to manage their own defense tools. The velocity of attacks on companies that are not Fortune 500 it is where the biggest increases in cyberattacks is occurring now.”
A To-Do List
Fiserv’s Patel suggested CUs adopt the following cybersecurity to-do list:
- Develop the organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities
- Develop and implement the appropriate safeguards to ensure delivery of critical infrastructure services
- Develop and implement the appropriate activities to identify the occurrence of a cybersecurity event
- Develop and implement the appropriate activities to take action regarding a detected cybersecurity event
- Develop and implement the appropriate activities to maintain plans for resilience and to restore any capabilities or services that were impaired due to a cybersecurity event
