Data breaches and cybersecurity incidents happen every day, and credit unions need to be considering what to do when – not if – they are attacked. Not only are breaches due to hackers, malware and phishing attacks on the rise, they are becoming increasingly complex and expensive to fix. In this risky climate, credit unions must do what they can to stop potential threats and prepare to respond to attacks.

Earlier this year, the NCUA released its Supervisory Priorities for 2016. Topping that list were Cybersecurity Assessments and Response Programs for Unauthorized Access to Member Information. With the NCUA carefully evaluating credit unions' risk management and information security programs, it is especially important that institutions and their service providers have the necessary policies and best practices in place.

Credit unions must focus on four main impacts of a data breach: Legal, reputational, financial and operational, according to a 2015 FFIEC Cybersecurity Assessment Tool Presentation. Legal impacts are the result of a credit union's duty to protect member information, as required by the Gramm-Leach-Bliley Act, the Children's Online Privacy Protection Act and the Fair Credit Reporting Act. Credit unions may also find themselves in violation of Dodd-Frank by committing unfair, deceptive and/or abusive acts or practices if the credit union is determined to have advertised security protections that weren't actually in place. Violations of these rules and regulations can result in civil penalties and administrative sanctions.

Continue Reading for Free

Register and gain access to:

  • Breaking credit union news and analysis, on-site and via our newsletters and custom alerts.
  • Weekly Shared Accounts podcast featuring exclusive interviews with industry leaders.
  • Educational webcasts, white papers, and ebooks from industry thought leaders.
  • Critical coverage of the commercial real estate and financial advisory markets on our other ALM sites, GlobeSt.com and ThinkAdvisor.com.
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.