Data security breaches are a serious problem for both consumers and businesses. In fact, a recent Gallup survey reports that having one's credit card information from stores stolen is the top worry among Americans. Credit unions also bear a significant burden as they incur steep losses in order to reestablish member safety after a data breach occurs, whether online or otherwise. The number and scope of data breaches have been significant, and the damage realized may surprise those who have not been intimately involved.
Despite the fact that many credit unions have implemented sophisticated and effective data security (including cybersecurity) safeguards, attackers adapt to constantly evolving technology and find new ways to penetrate systems. Credit unions must make efforts to stay one step ahead, a core function of their organization. In addition, all entities – not just financial institutions – that handle consumer information should comply with comprehensive federal data protection standards.
In January 2014, Senators Tom Carper (D-DE) and Roy Blunt (R-MO) introduced the Data Security Act of 2014 (S. 1927), to require minimum data security measures and breach notification requirements for all U.S. businesses. Like similar legislation the senators proposed in 2012, the new bill provides a Gramm-Leach-Bliley Act carve-out for financial institutions – a provision that NAFCU deems essential in any new data security package. Breached entities would be responsible for investigating the scope of the breach and reporting the findings to appropriate agencies and victims.
In June 2013, Senator Pat Toomey (R-PA) introduced S.1193, the Data Security and Breach Notification Act of 2013, which among other provisions, would require companies to notify consumers promptly if their personal information was stolen. Given the reputational risk credit unions often suffer when personally identifiable information of their members is lost at the hands of outside parties, we see this as a step in the right direction. NAFCU has suggested several ways to strengthen this measure, and included these suggestions in our comprehensive Five-Point Plan for Regulatory Relief.
NAFCU was the first financial services trade association to weigh in on the data security issue on Capitol Hill in the wake of the 2013 Target data security breach. During hearings to discuss potential legislation that would better protect consumers from ongoing data breaches, we have asked for federal standards to ensure that merchants are responsible for breaches that occur on their end.
As the cybersecurity threat to national security grows, industry and agencies alike are urging federal action to establish national safeguards and standards.
The items NAFCU would like to see addressed in any comprehensive data security bill include:
NAFCU's work on data security and cybersecurity is ongoing and our team is committed to ensuring credit unions have the resources they need to address the cybersecurity environment financial institutions face.
Federal authorities are making a concerted effort to reinforce the fact that financial institutions must have robust safeguards in place to protect against data breaches.
In February of 2013, President Obama announced during the State of the Union address that he would sign an Executive Order addressing cybersecurity issues. The mainstay of the Executive Order was to effectively allow intelligence to be gathered on cyberattacks and cyberthreats to privately-owned critical nation infrastructure – such as the private defense sector, utility networks, and the banking industry – so they can better protect themselves, the general population, and the greater economy.
Following President Obama's Executive Order, a number of open comment periods and stakeholder workshops were held. The input gathered led to the development of a voluntary set of best practices for critical infrastructure. On February 12, 2014, the National Institute of Standards and Technology (NIST) issued a "Framework for Improving Critical Infrastructure Cybersecurity". As part of the framework, NIST also released a "Roadmap" discussing next steps and identifying key areas for development, alignment, and collaboration. The Department of Homeland Security has the discretion to promote the voluntary best practices.
The financial services and banking sector is among the industries considered to be critical infrastructure under the framework. NAFCU will remain vigilant that the NIST standards do not become a stepping stone to increase regulation and add compliance costs to credit unions. NAFCU welcomed the NIST framework but reminded regulators that credit unions and other financial institutions are already subject to stringent regulatory requirements under the Gramm-Leach-Bliley Act and continually work to make cybersecurity a priority.
NAFCU has stayed at the forefront of this issue and continued to advance the call for national data security standards for all parties and champion credit unions in major media nationwide.
How MasterCard Is Taking Biometrics To The Masses (PYMNTS.com, February 23, 2015)
Poll: CUs Spent Average of $226K On Breaches (CUtoday.info, February 19, 2015)
Obama: Cybersecurity Is Shared Responsibility (PYMNTS.com, February 16, 2015)
FINANCIAL TRADES FIGHT BACK (POLITICO Morning Money, February 13, 2015)
Seven of the biggest financial industry trade organizations write Congress another missive in the ongoing letter war with retailers (POLITICO Morning Cybersecurity, February 13, 2015)
Financial Services Trade Letter to Congress (Morning Consult Finance, February 13, 2015)
NAFCU President & CEO Dan Berger To Attend White House Summit on Cybersecurity & Consumer Protection
(February 12, 2015)
LETTERS FLOOD LAWMAKERS AHEAD OF CYBER HEARING (POLITICO Morning Cybersecurity, January 28, 2015)
Congress to Hold First Data Breach Legislative Hearing (PYMNTS.com, January 26, 2015)
Obama's SOTU Cybersecurity Talk Pleases Trades (Credit Union Times, January 21, 2015)
B. Dan Berger: America needs national data security standards for retailers now (The Hill, January 19, 2015)
Credit unions want congressional data breach working group (The Hill, January 15, 2015)
NCUA Board Approves $50K For Palm Springs FCU Data Breach Costs (Credit Union Journal, January 15, 2015)
The National Association of Federal Credit Unions writes to congressional leaders urging the formation of a bipartisan working group on retailer data breaches (POLITICO Morning Cybersecurity, January 15, 2015)
Obama Announces New Data Security Proposal (Credit Union Times, January 12, 2015)
US fast food giant Chick-fil-A probes security breach (Daily Mail, January 1, 2015)
Chick-fil-A Confirms Breach Investigation (Credit Union Times, January 1, 2015)
Read recent letters from NAFCU to members of Congress on key data security issues that affect credit unions and their members.
2-4-2015 NAFCU Letter on the Importance of Data Security
2-3-2015 NAFCU Letter to the Senate Commerce Committee
1-27-2015 NAFCU Letter on How Congress Must Tackle Cybersecurity and Data Security Together
1-23-2015 NAFCU Letter on Data Security to the Subcommittee on Commerce, Manufacturing, and Trade
1-23-2015 Joint Trades Letter on Data Security to the Subcommittee on Commerce, Manufacturing, and Trade
1-23-2015 Joint Trades Letter on Data Security to the Senate
1-23-2015 Joint Trades Letter on Data Security to the House
1-14-2015 NAFCU Letter to Congressional Leadership Urging for a Bipartisan-Bicameral Working Group on Data Security
12-9-2014 NAFCU Letter to the Senate Banking Committee on Cybersecurity and Data Security
12-1-2014 NAFCU Letter to Congress on "Cyber Monday" and the Need for National Data Security Standards for Retailers
View all NAFCU policy letters
In December 2014, the Payment Security Task Force (PST), of which NAFCU is a member, issued a white paper on protecting cardholder data at the merchant's physical or virtual point of sale. Download PST's "U.S. Payments Security Evolution and Strategic Road Map" paper.
Current cyber-related law and recent legislative proposals and action are outlined in the Congressional Research Service (CRS) report from June 20, 2013, titled Federal Laws Relating to Cybersecurity: Overview and Discussion of Proposed Revisions.
The National Credit Union Administration's cybersecurity guidance, 13-Risk-01, lists a number of mitigation practices that credit unions should implement, including:
The following websites also offer resources that may help your credit union bolster the measures you have already taken:
Updated February 2015