WASHINGTON – Thousands of credit unions, banks, payment processors and other businesses are expected to join a series of simulated cyber attacks next month, which will test the vulnerability of the financial network.
As many as 500 credit unions are expected to participate in a variety of scenarios that will test third-party vulnerability, according to Bill Nelson, president of the Financial Services Information Sharing and Analysis Center, the private sector group organizing the tests. "Our goal is to create more awareness of the cyber threats within financial institutions and other groups being targeted," Nelson told The Credit Union Journal last week.
The participants are expected to include Navy FCU, which has a representative on the FSISAC’s board of directors.
Among the scenarios that may be tested – the actual tests will not be revealed until the Feb. 9-11 event – are spear phishing attacks, a denial of service attack that shuts down one or more payment systems; or a takeover of checking accounts. A different scenario will be introduced on each of the three days and participants will be asked to provide input on the impacts.
Participants will be expected to activate their incident response procedures in accordance with the scenario presented and to complete an anonymous survey to evaluate their organization's response.
"We have to be prepared for these types of possibilities," said Nelson. "We can’t have our heads in the sand."
The tests will gather the potential effects of the scenarios on participants and their payments partners and how they may have successfully fended off the attacks. Readiness and risk mitigation will be gauged. "We’ll be looking at everything that makes sense in protecting financial institutions and their customers," he said.











