Credit Unions
The security program your examiner expects to see
Part 748, ISE readiness, the 72-hour rule, and vendor oversight, built and run by senior people who have carried credit unions through real examination cycles and real vendor incidents. Member-first institutions deserve security sized for them, not a bank program cut down.
Our original research covers the rule's entire first year of filings.
The exposure examiners are asking about, and the one CUs control least.
Detect, scope, decide, document. The clock that finds out whether the program is real.
Figures from our analysis of the NCUA's first full year of cyber incident reports. Read the research →
What good looks like
Built for credit unions
NCUA and FFIEC alignment
ISE and ACET readiness from a team that has run credit-union security programs through real examination cycles. See our dedicated NCUA programs.
Member data protection
Part 748 Appendix A safeguards operationalized: risk-based controls around member information, tested and evidenced the way examiners expect.
Vendor due diligence
Core processors, digital banking, MSSPs. Risk-tiered oversight with the contract clauses that matter, wired into your 72-hour reporting path.
Incident response you can actually run
A plan sized for a credit-union team, rehearsed by tabletop, with reportability criteria decided before the incident instead of during it.
NCUA programs
Four programs, one examiner-ready posture
Each stands alone; together they are the program an examination assumes exists. See the full NCUA practice →
ISE & ACET exam readiness
Baseline, gap-to-roadmap, evidence build, and a pre-exam rehearsal so the examination is a walkthrough, not a discovery.
Learn morePart 748 security program
The written program, the risk assessment behind it, and board adoption with minutes: the governance evidence examiners look for first.
Learn more72-hour incident reporting
Reportability criteria decided before the incident, a rehearsed decision path, and documentation that shows your work.
Learn moreVendor due diligence
Core, digital banking, insurers, MSSPs, and yes, your registrar: risk-tiered oversight wired into your reporting path.
Learn moreThis summer's vendor lesson
When a key vendor goes dark, the clock is yours
The TruStage incident put every credit union's vendor dependence on the board agenda, and the data investigation is still running. Whatever the final scope, your examiner's question stays the same: show me what you did when you heard. We published a calm, Part 748-aligned response checklist that credit unions are using to pressure-test their own playbooks.
Free tools for credit unions
- Security Gap Analyzer →
Your stack vs CIS v8, NIST CSF, and FFIEC in about five minutes
- CU Cyber Incident Landscape →
The research report, free, no form
- vCISO Cost Calculator →
What senior security leadership actually costs at your asset size
- CAT-to-CSF 2.0 Transition Guide →
Keep your maturity narrative through the transition
Proof, not promises
From no CISO to examiner-ready in four quarters
A regional federal credit union was running security as a part-time duty inside IT, with examiners, auditors, and a growing threat landscape all demanding more. We embedded fractional security leadership and built the program quarter by quarter.
Read the case study →Latest for credit unions
From the blog
The Breach That Never Touched the Network
A credit union's EDR was clean. Its identity logs were clean. And members could still have been phished at the real online-banking URL. The attack lived somewhere else entirely.
Read moreYour Transfer Lock Doesn't Do What You Think It Does
clientTransferProhibited looks reassuring in a WHOIS record. It didn't stop an attacker from redirecting a credit union's domain, and then it didn't stop them from transferring it to another country.
Read moreTwo DNS Records That Would Have Stopped a Credit Union Hijack
Within hours of taking over a credit union's DNS, an attacker held valid certificates for the whole domain, including a wildcard. No CA did anything wrong. Two missing records made it legal.
Read moreFAQ
Questions credit union leaders ask us
What does an NCUA examiner actually expect from a credit union security program?
A written Part 748 program the board has adopted, a risk assessment that matches your real environment, evidence that controls operate (not just policies that describe them), a tested incident response plan with 72-hour reportability criteria, and vendor oversight proportionate to risk. Examiners increasingly test the program by asking for artifacts; the institutions that struggle are the ones doing archaeology instead of retrieval.
We're between exams. What should we prioritize?
Third-party risk, because 69% of the NCUA's first year of incident reports traced to a vendor, and this summer's vendor incidents made the exposure concrete. Start with the vendor inventory, tier it by member-data access and operational dependence, and close the due-diligence gaps on tier one, including overlooked vendors like your domain registrar and DNS host.
Do we need a full-time CISO?
Most credit unions under a billion in assets don't need, and can't justify, a full-time hire. What they need is someone senior who owns the program: exam readiness, vendor oversight, incident decisions, and board reporting. That's the fractional model: senior leadership at a fraction of a full-time cost, on the hook when the 72-hour clock starts.
What happened with TruStage, and what should we do about it?
TruStage took its network offline in July 2026 after a cybersecurity attack, disrupting member-facing services for weeks; the data investigation is still running. Whatever the final scope, your examiner's question is the same: show me what you did when you heard. We published a free, Part 748-aligned vendor-incident response checklist for exactly that.
Let's get your credit union examiner-ready.
A short call is enough to map where you stand against the next exam cycle and the fastest path to closing the gaps. No pitch deck, no obligation.