Cybersecurity Tips for the Holiday Season

ATTENTION ONLINE CREDIT UNIONS

This holiday season, cybersecurity should be top of mind for all credit union professionals.  Maintaining member data security begins with YOU, so what should you be doing right now to improve your chances of staying ahead of the bad guys trying to steal your member’s information?

  1. Don’t trust email
    1. Email remains a primary weapon of deception for bad actors. It’s easily spoofed to look like someone you might trust.
    2. Verify with the sender before clicking links or opening attachments.
    3. Test your users with fake emails and make sure they can identify the suspect ones.
    4. If in doubt, delete it!
  2. If you use cloud email services, turn on multi-factor authentication right now
    1. Bad actors are tricking users into giving up their cloud passwords, and then accessing the victim’s email to impersonate them or steal what’s in their mailboxes.
    2. Multi-factor authentication requires a secondary code on a device like a smartphone to gain access to the account.
    3. Turn on multi-factor authentication NOW for all your cloud accounts if you haven’t already.
  3. Don’t be an administrator
    1. Admin level accounts are the first ones bad actors try to abuse.
    2. Reduce your risk by knowing which accounts are administrators, and remove those that aren’t absolutely necessary.
    3. Never use an administrator level account to operate your computer daily. Administrator accounts should only be used sparingly when needed to make configuration changes.
    4. Know your user accounts. Look for unexpected or suspicious accounts.
  4. Avoid storing member data unencrypted on your network.
    1. Delete it promptly when you’re done with it.
  5. Regularly review your network management reports
    1. Understand the health of your network, backups, firewall and cyber hygiene.
    2. If you’re not getting reports from your network manager, ask for them.

Other great tips can be found in the CUSO Mag article Four Things Credit Union Executives Should Do About Cybersecurity Right Now.  If you have questions about, or would like verification for these recommendations, please contact your network administrator, or reach out to the Help Desk if you’re a CNS-managed client.