Reader Technology Questions

READER QUESTION: For each of your tek panelists, can they name some specific new ways CUs are using their solution to measure, contain risk?

Processing Content

 

Tom DeSot, EVP, Chief Compliance Officer, Digital Defense, Inc., San Antonio, Texas

Probably the three most prevalent ways our clients are measuring and containing risk within their institution are through the use of our enterprise risk assessment utility, our Risks, Ratings, and Certification (RRC) module contained with the workflow management system in our secure client portal, Frontline, and finally, through the utilization of our VLM-Pro offering.

The ERA utility is a key component to many of our client's risk assessment programs as it provides them with the means to manage, update, and report on their ongoing enterprise-wide information security risk assessment program. Based upon the OCTAVE Allegro methodology developed by the Software Engineering Institute at Carnegie-Mellon, the utility gives each client the capability to capture all of information assets critical to their operations, analyze associated risks, document remediation activities (along with uploading and storing associated policies and procedures), and produce reports for use during exams and audits. In effect, it becomes a centralized repository for all of their risk assessment data, releasing them from the burden of managing multiple Word and Excel documents for documenting, tracking, and reporting on their enterprise risk profile.

The RRC module is most commonly utilized by our clients to evaluate the risk software vulnerabilities present to their institution when evaluated against CIA (confidentiality, integrity, availability) parameters, as well as any expected outage costs (in real dollars), should a system be compromised. These CIA and monetary ratings are coupled with the client's vulnerability and penetration test ratings to derive an overall risk score. This risk score ultimately gives our clients the capability of quickly and effortlessly determining which key systems are at greatest risk, and which software vulnerabilities require more immediate attention. This value point is critical when considering the number of systems, and associated vulnerabilities, many of our clients deal with on a daily basis.

Lastly, but certainly not least, are our clients who are taking advantage of our VLM-Pro offering. VLM-Pro (vulnerability lifecycle management-professional) is a managed service offering where our clients work hand-in-hand with our security analyst team to manage, remediate, and report on vulnerabilities discovered during assessments or penetration tests.

While our security analysts do not remediate any of the discovered vulnerabilities, they manage the client's vulnerability remediation process per defined service level agreements and provide reporting which allows the client to clearly illustrate to examiners, and auditors, the breadth and depth of their vulnerability remediation program.

In effect, VLM-Pro allows our clients to focus on their key business goals, while at the same time ensuring their vulnerability remediation program continues to meet their stated business goals.

Clients taking advantage of these three programs, and others offered by Digital Defense, can easily monitor and manage information security risks within their institution, report progress to their Board, Supervisory Committee, and management team, and ultimately portray their risk posture to examiners and auditors when the need arises.

 

Kay Nichols, EVP, Decision Solutions, Fidelity National Information Services, Inc. (FIS), Jacksonville, Fla.

With all of the uncertainties in the market facing credit unions, it's more important than ever to effectively measure and manage risk; however, the emphasis is on managing the risk not inhibiting business development. Scoring the risk associated with opening a new account, proactively monitoring and managing client accounts on an ongoing basis and scoring foreign deposits to determine when to make funds available are three specific ways we are seeing credit unions step up.

FIS is playing a major role in these initiatives. Using an FIS QualiFile® score, credit unions are able to easily and accurately assess risk for any potential member, and implement account-opening strategies that can be tailored by the credit union to meet their desired account-opening goals. Many credit unions have turned to us to help develop and deploy account-opening strategies that automatically segment new members into appropriate products based on risk. This allows the credit union to serve a broader range of members while guarding against risks that might be associated with doing so. In fact, we have credit union clients who open accounts for virtually anyone who applies for membership, but use our solutions-such as the recently launched FIS DepositShield-to help them manage the risk associated with check deposits.

Nearly 4000 credit unions across the country use our solutions today. To learn more, please visit our website at www.fisonevoice.com.

Heather Czermak, Senior Product Manager, Wolters Kluwer Financial Services.

For credit unions staring down the Nov. 1 deadline for meeting the requirements of the new Red Flag Regulations, technology can help facilitate a rapid program deployment including program design, program documentation, "customer" identification, ongoing assessment, account monitoring and reporting.

Many credit unions are already using automation to detect the identified relevant red flags. In addition to providing real-time data validation against current data sets, automated solutions reinforce internal policies and procedures consistently throughout operations.

For example, many credit unions are already using a technology solution to facilitate identity verification and authentication for Bank Secrecy Act and anti-money laundering requirements. Existing Customer Identification Programs (CIP) and Customer Due Diligence (CDD) controls also provide many of the required validations for new and existing members. Through the use of comprehensive CIP software solutions, like Wiz SentriTM: RiskID, existing BSA/AML tests can be easily leveraged to simultaneously meet Red Flag requirements for detection, investigation and reporting.

 

David McConney, EVP & GM

Credit Union Core Systems Group, Harland Financial Solutions, Pleasanton, Calif.

Technology solutions are not "one size fits all." But by analyzing our clients' current and future technology needs, we can find affordable solutions-very much like our clients offer financial solutions for their members. Through our alliance building partnerships and core products and services, we're able to match our clients' long-term goals.

Containing technology costs in tough economic times is always a concern. However, to remain competitive in the marketplace may require further examination of your current technology goals to determine how you can pinpoint your needs:

Take inventory of your current technology efficiencies-is it costing more in manual processes that could possibly be automated?

What products and services are available within your budget? Bundled services can satisfy many core business requirements, including member satisfaction, at the same time you're keeping costs down.

Increase awareness of member self-service offerings, and leverage online channels that support next generation strategy.

Challenging economic times require wise choices of technology to support your initiatives in the years to come.

 

John San Filippo, Marketing Manager,

Symitar Systems, San Diego

The measures necessary to identify and prevent external security breaches are well-known. However, what sometimes gets overlooked is the fact that much cyber crime comes from within. In other words, it's committed in whole or in part by employees. It's for this reason that today's savvy credit unions are beginning to deploy monitoring systems that keep an eye on the entire enterprise, ensuring that ANY suspicious activity is identified.

For example, systems like the one I describe can watch for due dates changed on loans, back-dated interest rate changes, and large credit limit changes, to name a few. In most instances, these will be legitimate activities. However, by having your security software monitor such activity, you can quickly and easily spot fraud if and when it does occur.

Software such as this can also monitor privileged account activity, as well as authority changes within the operating system and the core software. Again, these are common activities-so common in fact that fraudulent access might otherwise be missed. The key here is a well-balanced suite of security tools that actively watches for potential fraud, yet doesn't prevent employees from performing their assigned duties.

Jon Reneslacis, Director, Solutions Engineering, VSoft

Image-based processing heightens efficiency and speeds transaction flow. However, some of the long-standing risk mitigation tools are seemingly compromised by the lack of paper in the flow. VSoft solutions engage multi-layer electronic evaluations, credit union business rules, and experienced operators to manage item integrity. VSoft believes that the application of image quality standards and the automated evaluation key points of interest on a document create an environment in which exceptions are managed, not the majority of the workflow volume. Risk filtering can be administered by dollar amount, document type, origination point, or destination point.

Multiple entry channels require solutions to survey work across a broader array to detect duplicate items, possible kiting, and attempts at bulk fraud (such as blocks of fraudulent cashiers checks). Evaluation at both the point of capture and initial presentment as well as in the back office across channels and across a time period creates a more effective net for catching risk-producing documents.

Todd Zerbe, Manager, COCC, New York

Today's risks come in many forms, from underwriting to money laundering, check kiting, card fraud, identity theft, and data breaches. While technology-based solutions can easily detect and contain many of these risks, the solutions have an added challenge of integrating with the credit union's core system and workflow.

Often the technical integration issues are easier to resolve than the workflow issues, particularly for open core systems that employ the latest database technologies. Workflow requires study, training, and solid functional design.

For example, COCC's core processing system enables a credit union to specify the procedures that a Member Services Representative must take during the account opening process.

Skipping any of these steps, such as a Chex verification, prevents the account from fully opening. Another example is encrypted data file attachments. We require all data files emailed from COCC to be encrypted. This procedure and technology combination dramatically reduces the threat of a data breach.

Containing risk really involves a marriage between technology and workflow. Technology will never be effective if it isn't used. When the technology is designed for the credit union's procedures, it will prove its value time after time.

 

READER QUESTION

Like other CUs, we're looking for strategies in our 09 planning to contain technology costs? What suggestions do your panelists have?

 

Frank M. Catucci, CISSP, First Bristol FCU, Bristol, Conn.

Containing technology costs for a credit union can be a daunting task but yet not impossible. There are various methods in which the institution can achieve the desired expenditure reduction. Keep in mind that every credit union will face unique challenges due to differing asset sizes, resources, and technologies. I will use general industry suggestions. Some I have implemented and others I have not.

So you will need to decide which if any are best for your institution.

The first thing that must be addressed is the most controversial. Can your institution share IT resources (personnel) with another credit union or credit unions? This can be a great way for some institutions to be able to save some outsourcing expenses. The next thing I would look at is uniformity. If you are going to be purchasing new systems, buy all the same make and models. This will reduce repair or upgrade expense. Keep a few spares available. Also keep all systems on the same brand of software and versions. Another thing to try and achieve is purchasing systems that are above and beyond your current technology requirements. A system that has too much power and overbuilt resources will last longer and therefore not have to be replaced as soon. Finally we come down to what is desired versus what is required. What should your credit union be purchasing this year as a necessary technology as opposed to a desired technology?

All of the above suggestions may assist you in containing costs for 2009, however combining this with the big picture for your institution will also help. One of the most important things to remember is try to have a long-term technology plan. Perhaps plan, budget and try to estimate what is going to be needed in 5 years from now. This will help alleviate many technological monetary burdens in future years to come.

 

Todd Zerbe, COCC, New York

Today's challenging financial landscape makes sound, effective IT strategies more important than ever. This is best achieved through a combination of education, collaboration, creativity and strong vendor partnerships. By education,

I mean gaining a complete understanding of the challenges and the available solutions. Maintaining close relationships with peers enables your credit union to see how others have addressed the same challenges and to learn from their results.

Be sure to collaborate with all affected parties in the credit union to gain a clearer understanding for everyone involved. Support an environment that fosters creativity since many challenges require 'out of the box' thinking to develop great solutions.

Maintain close relationships with your IT vendor(s). A good relationship should result in a free exchange of ideas resulting in solutions that meet your requirements and financial resources.

Finally, an institution's options are greatly impacted by its core processing system. An open system provided by a vendor that truly believes in collaboration will offer many low cost options for integration with other products and service providers. Having an integrated set of solutions is key to ensuring that your credit union can successfully meet its objectives while containing costs.

 

Jon Reneslacis, Director, Solutions Engineering, VSoft

VSoft encourages credit unions to spend wisely and to spend in a manner that is consistent with the institutions' strategies. Specific to technology, that may actually mean increasing the bottom line spend for a given calendar year to place the credit union in an advantageous market position. Budgeting does not always allow for the less quantifiable "opportunity cost" of waiting for an implementation. That being said, key advantages of technology reside is the facilitation of compliance, transparency of information, security and access, and end-to-end tracking and validation. Effective solutions will incorporate other sources of information without compromising management reporting and audit transparency.

VSoft contends that effective spending will create a return on investment that is easy to quantify, easy to track, and easy to understand. If the technology spend of the credit union does not fit the strategy of the organization and creates a disjointed management system, then the spend was inappropriate.

 

John San Filippo, Marketing Manager

Symitar Systems

Your core system is the cornerstone of your entire technology environment. So the first step in managing IT costs is ensuring that you have the right core system-one that enables rather than hinders your growth and progress.

Beyond that, however, it's essential to make sure you're getting the most from whatever system you do have. I'm always surprised how many times a client will see a feature we've had for years and say, "Gee, I didn't know we could do that." An enhancement that doesn't seem important today may suddenly become important a year from now-but a year from now, your staff may have forgotten about it. Keeping up on core system enhancements can be a real challenge.

Chances are that your core processor offers a wide ranges of professional services, including operational reviews, currentization and database cleansing, to name a few. It's important to recognize these opportunities as investments rather than expenses.

Just like regular checkups from your doctor, regular checkups from your core processor will keep your system humming along at maximum efficiency. And that will inevitably lead to reduced operating costs.

 

Have a question for our panel of experts? Send it to Managing Editor Lisa Freeman at lfreeman@cujournal.com.


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More