Principle Security Principle Security.

Credit Unions

The security program your examiner expects to see

Part 748, ISE readiness, the 72-hour rule, and vendor oversight, built and run by senior people who have carried credit unions through real examination cycles and real vendor incidents. Member-first institutions deserve security sized for them, not a bank program cut down.

1,072
NCUA incident reports analyzed

Our original research covers the rule's entire first year of filings.

69%
Traced back to a third party

The exposure examiners are asking about, and the one CUs control least.

72 hrs
Your reporting window

Detect, scope, decide, document. The clock that finds out whether the program is real.

Figures from our analysis of the NCUA's first full year of cyber incident reports. Read the research →

What good looks like

Built for credit unions

NCUA and FFIEC alignment

ISE and ACET readiness from a team that has run credit-union security programs through real examination cycles. See our dedicated NCUA programs.

Member data protection

Part 748 Appendix A safeguards operationalized: risk-based controls around member information, tested and evidenced the way examiners expect.

Vendor due diligence

Core processors, digital banking, MSSPs. Risk-tiered oversight with the contract clauses that matter, wired into your 72-hour reporting path.

Incident response you can actually run

A plan sized for a credit-union team, rehearsed by tabletop, with reportability criteria decided before the incident instead of during it.

This summer's vendor lesson

When a key vendor goes dark, the clock is yours

The TruStage incident put every credit union's vendor dependence on the board agenda, and the data investigation is still running. Whatever the final scope, your examiner's question stays the same: show me what you did when you heard. We published a calm, Part 748-aligned response checklist that credit unions are using to pressure-test their own playbooks.

Free tools for credit unions

Proof, not promises

From no CISO to examiner-ready in four quarters

A regional federal credit union was running security as a part-time duty inside IT, with examiners, auditors, and a growing threat landscape all demanding more. We embedded fractional security leadership and built the program quarter by quarter.

Read the case study →
4
Quarter program arc
Monthly
Retainer model
100%
Audit findings tracked

FAQ

Questions credit union leaders ask us

What does an NCUA examiner actually expect from a credit union security program?

A written Part 748 program the board has adopted, a risk assessment that matches your real environment, evidence that controls operate (not just policies that describe them), a tested incident response plan with 72-hour reportability criteria, and vendor oversight proportionate to risk. Examiners increasingly test the program by asking for artifacts; the institutions that struggle are the ones doing archaeology instead of retrieval.

We're between exams. What should we prioritize?

Third-party risk, because 69% of the NCUA's first year of incident reports traced to a vendor, and this summer's vendor incidents made the exposure concrete. Start with the vendor inventory, tier it by member-data access and operational dependence, and close the due-diligence gaps on tier one, including overlooked vendors like your domain registrar and DNS host.

Do we need a full-time CISO?

Most credit unions under a billion in assets don't need, and can't justify, a full-time hire. What they need is someone senior who owns the program: exam readiness, vendor oversight, incident decisions, and board reporting. That's the fractional model: senior leadership at a fraction of a full-time cost, on the hook when the 72-hour clock starts.

What happened with TruStage, and what should we do about it?

TruStage took its network offline in July 2026 after a cybersecurity attack, disrupting member-facing services for weeks; the data investigation is still running. Whatever the final scope, your examiner's question is the same: show me what you did when you heard. We published a free, Part 748-aligned vendor-incident response checklist for exactly that.

Let's get your credit union examiner-ready.

A short call is enough to map where you stand against the next exam cycle and the fastest path to closing the gaps. No pitch deck, no obligation.