Archive Links

Consumer Archive
CU System Archive
Market Archive
Products Archive
Washington Archive

News Now

Washington
NEW: Matz says merchants must be subject to same data security standards as CUs
WASHINGTON (UPDATED: 2/24/14, 11 A.M. ET)--The data breach at Target is the story of a double standard "that is neither healthy nor fair," National Credit Union Administration Chairman Debbie Matz said today at the 2014 Governmental Affairs Conference. "While financial institutions are required by law to protect sensitive personal information, data protection standards for retailers are too often simply not adequate," Matz added.

The Credit Union National Association has made this same point in several recent letters to the U.S. Congress.
The NCUA leader identified cyber-security as one of the top priorities for the regulator and the credit union system going forward.

"A data breach--even if it's outside the financial system--can have enormous negative repercussions inside the financial system," Matz said. "No matter how far removed a given data breach is from your credit union, if it affects your members, you can pay dearly--both in terms of your reputation and your balance sheet."

Data breaches are not the only cyber-security risk, according to Matz.  Hackers have used passwords stolen from a credit union to access one of the larger credit bureaus, and cyber-terrorists are now targeting credit unions.

"When these attackers break through, websites crash. Members are unable to access their accounts. It can take hours to bring systems back online," she said. Hackers can infiltrate systems and compromise or destroy data, and could use a credit union as an entry point to gain access to payment systems and vendors.

Some also use front-end denial of service attacks to create a diversion while others break into a network through a back door. "Think about the damage they could do," Matz said.

Agency examiners will be looking to see how credit unions are implementing appropriate risk mitigation controls to better protect, detect, and recover from cyber-attacks. Vendor due diligence, strong password policies, proper patch management, employee training, and network monitoring are among the items credit unions will need to address or improve.

To prepare for potential attacks, credit unions can share cyber-security best practices  at league meetings and take part in national information-sharing forums.

The NCUA itself is also partnering with federal law enforcement, intelligence and financial agencies to improve its own cyber-security.

"NCUA needs to be ready. The credit union system needs to be ready. Working together, we will be ready," Matz said.


RSS print
News Now LiveWire
#FreeGasFriday courtesy of @tvfcu, TN #creditunions http://t.co/wDRFYJVlpz
57 minutes ago
If you were unable to watch or attend @cuna 's @thehill Hill forum on Wed., you can now watch the archived version: http://t.co/FhUnp7HbU8
2 hours ago
Time is running out. If you haven't taken the #NewsNow readership survey, please click here now: http://t.co/4Gp6C2Wa4o
2 hours ago
African financial inclusion possible with mobile money: @IMFNews study http://t.co/0V5DTQToxY
3 hours ago
Louise Herring's birthday is Saturday. 105 years later, her legacy lives on through her kids http://t.co/oMqGADmo0d http://t.co/T3NmS9NqEY
3 hours ago