READER QUESTION #2

What are your panel's thoughts on offering money-back guarantees or pledges to members that their data is secure at the credit union and won't be breached?

Processing Content

Sue Pogatschnik, Credit Union Segment Manager, Wolters Kluwer Financial Services, St. Cloud, Minn.

With the recent press surrounding data security breaches at financial organizations, it's no surprise credit unions are considering marketing campaigns emphasizing the integrity of their data security systems.

However, money-back guarantees on data security should be approached with caution for the following reasons:

* From a regulator's point of view, a credit union's focus should be on maintaining a sound information security program that includes a security breach response plan.

Security breaches will happen, so practically speaking, the goal should be responding to breaches quickly, not guaranteeing that they won't happen.

* The credit union isn't always in control of its data. Third parties play a part in how data is collected and stored.

There is little a credit union can do if a box containing its data tapes falls off a delivery truck and ends up in the wrong hands.

* A money-back guarantee campaign could backfire if data hackers perceive the guarantee as a challenge to hack into the credit union's system.

* The credit union could be forced to put its money where its mouth is. If a breach were to occur, the credit union would need to pay up or be faced with claims of false advertising.

David McConney, Harland Financial Solutions

Unless the Credit Union has a third party managing networks/security/internet access, etc., it would be difficult to guarantee security of the data in regards to any possible punitive damages being assessed.

Any such agreement would need to be very detailed in what is the third party's or parties responsibility within the software, versus the credit union's responsibility.

If the credit union is managing the infrastructure and if a data compromise occurs, it becomes more complicated as a breach could come from a number of sources.

There would need to be auditable/accountability measures in place to determine where the compromise occurred.

Providing validation of data security levels, perhaps in the form of certifications and credentials, and member education might be a better approach than offering money-back guarantees or pledges.

Have A Question For The Technology Panel? E-mail Managing Editor Lisa Freeman: lfreeman cujournal.com


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More