26.3 C
New York
Tuesday, August 25, 2026

Annual Report to Congress on Cybersecurity and the Resilience of the Credit Union System

MESSAGE FROM THE CHAIRMAN

Introduction to Cybersecurity and Credit Union Resilience

On behalf of the National Credit Union Administration (NCUA), I present our annual, statutorily required Cybersecurity and Credit Union System Resilience Report. This vital document summarizes the current landscape of cybersecurity threats, highlights key initiatives from the agency, and outlines our continuous efforts to bolster cybersecurity preparedness within the credit union industry.

In 2023, the financial sector experienced unprecedented challenges due to rising cyberattacks targeting critical infrastructure, affecting systems that serve over 139 million Americans. The credit union system, which plays an integral role in communities nationwide, is not immune to these threats.

The Evolving Cybersecurity Threat Landscape

As the digital and geopolitical environments evolve, the prevalence of cyberattacks on financial institutions continues to grow. This imperative for vigilance cannot be overstated. The NCUA acknowledges that adversaries are increasingly sophisticated in their attacks, which now encompass an array of tactics aimed at undermining the integrity of our financial systems.

NCUA’s Commitment to Cybersecurity

The NCUA is committed to transparency, consistency, and accountability in its cybersecurity examination program. Our agency has made significant strides in fostering a culture of cybersecurity awareness among credit unions. Key initiatives include:

  • Information Security Examination Program: A program focusing on risk assessments tailored to each credit union’s unique vulnerabilities.
  • Cyber Incident Notification Regulation: Adopted in 2023, this regulation mandates credit unions report significant cyber incidents within 72 hours.

Key Initiatives and Risk Mitigation Strategies

In an effort to enhance cybersecurity practices, the NCUA has introduced several initiatives:

  1. Automated Cybersecurity Evaluation Toolbox (ACET): This tool aids credit unions in assessing their cybersecurity maturity while aligning with leading industry standards.

  2. Educational Outreach: The NCUA actively engages with credit unions, equipping them with the knowledge needed to navigate complex cybersecurity challenges.

  3. Collaboration with Federal Agencies: Through partnerships with agencies like CISA, the NCUA seeks to bolster the cybersecurity framework across the financial sector.

Advocating for Enhanced Regulatory Authority

Restoring the NCUA’s authority over third-party vendors is vital. Current regulations present a blind spot; without the ability to directly supervise these vendors, the NCUA struggles to effectively mitigate cybersecurity risks. For instance, a ransomware attack last year impacted over 60 small credit unions, underscoring the urgent need for comprehensive vendor oversight.

Various independent entities, including the Government Accountability Office and the Financial Stability Oversight Council, have identified this regulatory gap, advocating for enhanced oversight to safeguard credit union members and the broader financial system.

Importance of Third-Party Oversight

The reliance on third-party vendors for critical services exposes credit unions to significant risks. Approximately 73 percent of reported cyber incidents involve third parties, making it imperative for Congress to grant the NCUA necessary regulatory powers to oversee these external relationships.

Granting this oversight wouldn’t merely bridge a regulatory gap; it would enhance operational security across the board, providing credit union members protections akin to those enjoyed by bank customers.

Navigating Future Threats

As we look forward in the ever-changing cybersecurity landscape, the NCUA remains committed to continual improvement in our cybersecurity defenses. We acknowledge the increasing frequency and severity of cyber incidents, from ransomware attacks to sophisticated phishing schemes.

By enhancing IT supervision, equipping credit unions with cutting-edge resources, and advocating for robust regulations, we can better protect institutions and their members against emerging threats.

Resource Allocation for Cybersecurity Resilience

The NCUA continues to invest in improving its cybersecurity infrastructure, adopting a Zero-Trust model to ensure strict access controls and ongoing risk assessments. This proactive approach not only elevates our internal security but also positions us to support credit unions in mitigating potential vulnerabilities.

Through comprehensive training programs, modernized policies, and advanced technological resources, we aim to build an effective cybersecurity framework that withstands external threats.

Forward-Looking Perspectives

As we chart the course ahead, I urge all stakeholders—Congress, regulatory agencies, and industry partners—to join us in fortifying the cybersecurity resilience of the credit union system. Together, we can confront the challenges posed by cybersecurity threats and uphold the safety and soundness of the credit union system, ensuring it thrives for generations to come.

Sincerely,
Todd M. Harper
Chairman
National Credit Union Administration

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles