WASHINGTON–If they haven’t received them already, many credit unions across the country will soon be receiving invitations from the FBI–but for a good reason.
The primary goal: get credit union in contact with FBI and law enforcement authorities on cybercrime now rather than after a breach.
October is National Cybersecurity Month and where appropriate FBI field offices will be hosting the events with the invited financial institutions, according to Anjan Mukherjee, counselor to the secretary and deputy assistant secretary in the Treasury Department
In remarks to NAFCU’s Congressional Caucus here Mukherjee emphasized the cybersecurity threat to credit unions—which include not just their own operations, but the costs of breaches such as those at Home Depot and Target and extend beyond the balance sheet to issues such as faith in the institution–and said that while Treasury is responsible for coordinating cybersecurity efforts at the federal level credit unions must also do more.
“It is critical for credit unions to have in place strong baseline protections against cyberthreats,” said Mukherjee. “There are a number of critical questions to ask. How strong are the passwords in your systems? That leads to other issues of access control. Are your networks appropriately designed and segmented for privileged users? You need constant upgrades to security. How do you protect info when upgrading? This may seem granular, but are all very, very important.”
Mukherjee said the same questions a credit union is asking itself must also be asked of third party providers to credit unions, and not just those in the technology space.
“Do your contracts specifically lay out the liabilities should they falter?,” he asked, urging a review.
Don't Forget the Training Piece
Meanwhile, while establishing strong protections is “obviously a prerequisite,” Mukherjee reminded that there must be equally strong training, pointing to the number of cyberattacks made possible by human error, the so-called phishing attacks.
None of that guarantees a breach won’t happen, said Mukherjee, who called on credit unions to also create a clear set of “response and recovery” procedures.
“What if corporate email or phones aren’t working? Who needs to be involved?,” he asked, before answering, “Vendors, law enforcement, and regulators. How will members be assured their accounts are actually safe. What if an institution’s data integrity is compromised and it makes it more difficult to actually reassure your members? “
Mukherjee recommended credit unions create a response manual and include a proper sequencing of events.
“These also need to be thoroughly exercised,” he said. It’s critical to preform these exercises periodically, and important to have your technology providers as a critical part of these exercises.”
Mukherjee said Treasury supports giving NCUA the power to oversee third party providers, especially in the area of technology and cyber-risks. He noted the top five financial technology providers serve credit unions representing 75% of total CU assets. “Granting this authority to NCUA would be in the best interests of credit unions’ cybercultures,” said Mukherjee.
Credit unions have opposed granting NCUA such authority, although Mukherjee did not touch on that issue in his remarks.
Finally, he reminded credit unions as part of their cybersecurity planning to establish relationships now with law enforcement.
“So the aftermath of a cyberincident isn’t the first time you meet,” he said.
