Credit unions
Credit union cybersecurity compliance that goes beyond NCUA
We help credit unions meet NCUA and GLBA expectations, answer examiner questions with evidence and protect member data every day. You get independent testing, security leadership and 24/7 monitoring from one team.


The challenge
What NCUA expects from your security program
Every federally insured credit union must maintain a written information security program under NCUA’s Part 748 and its Appendix A guidelines, which implement the GLBA safeguards for member information. The program has to be risk-based, approved by your board and reported on to the board at least annually. Since September 2023, a reportable cyber incident must also be reported to NCUA within 72 hours of forming a reasonable belief that it happened.
Examiners want to see that the program works in practice. That means documented risk assessments, independent testing, vendor oversight, a tested incident response plan and board-level engagement. Most credit unions run lean IT teams, and the work lands on a few people who are already busy.
How we help
Credit union cybersecurity services
Each service produces the evidence examiners ask for, and together they cover the full lifecycle from assessment to response.
Going beyond NCUA requirements
Cybersecurity for credit unions: the requirements and the best practices
NCUA’s rules set the foundation. A strong program adds the practices below, which examiners increasingly expect and which stop the attacks credit unions actually face.
Independent testing
Internal penetration testing shows what someone with network access could reach. External testing checks internet-facing systems such as online banking, VPNs and email. Social engineering tests measure how staff handle phishing and phone pretexts. Regular IT audits confirm your controls match your policies.
GLBA safeguards and state privacy laws
Your written information security program should cover risk assessment, access controls, encryption, monitoring, training, vendor oversight and incident response. State laws can add obligations; in California, for example, the CCPA can apply to some member data.
ACET and maturity assessments
The FFIEC retired its Cybersecurity Assessment Tool in August 2025. NCUA kept its Automated Cybersecurity Evaluation Toolbox (ACET) available, now framed as the ACET Maturity Assessment with statements mapped to NIST CSF 2.0. It remains voluntary. Many credit unions use it alongside a NIST CSF assessment to benchmark maturity and plan improvements.
Third-party and vendor risk
Your board remains responsible for activities you outsource. NCUA’s guidance on evaluating third-party relationships calls for risk assessment and planning, due diligence before you sign, and ongoing monitoring. Keep an inventory of vendors, rank them by risk and review the critical ones on a schedule.
Incident response, continuity and recovery
Keep a written incident response plan that includes the 72-hour NCUA notification and member communication, and test it with tabletop exercises. Pair it with business continuity and disaster recovery plans that are tested and updated.
Access, encryption and monitoring
- Least privilege and multi-factor authentication for staff and administrators
- Encryption of member data at rest and in transit
- Centralized logging and real-time monitoring of network activity
- PCI DSS controls where you process card transactions
- Regular review of policies for access, acceptable use, incident response and data retention
Board and management oversight
Give the board regular, plain-language reporting on risk, testing results, incidents and remediation progress. A framework such as NIST CSF or ISO 27001 gives that reporting a consistent structure.
Regulations and frameworks
Credit union requirements we help you meet
FAQ
Credit union cybersecurity questions
Related services
Related services
Talk to an expert
Strengthen your program before the next exam
Tell us about your credit union and your last exam, and an advisor will reply by email to set up a conversation.
Prefer email? Write to [email protected] or call (858) 712-0040.
