Sometimes Keeping Hackers Out Is Often Easier Than Keeping Information In

KENSINGTON, Md. - Credit unions are getting better at preventing outsiders from compromising data, but the next challenge is to keep insiders from doing the same, especially via e-mail.

Processing Content

The concept of "intrusion prevention"-firewalls, penetration tests, and sensors-is old hat to most technology departments. Moreover, the NCUA mandates those tools.

But many credit unions are new to best practices in "extrusion prevention"-or stopping data leaks via e-mail and removable media.

In fact, more than half of U.S. IT managers think their protection is inadequate against internal data loss, according to a recent survey by the Elk Rapids, Mich.-based Ponemon Institute.

Perhaps not for long at credit unions. Stephen Jones, chief technology officer at Signal Financial FCU here, thinks that NCUA examiners will soon ramp up the focus on extrusion prevention.

"When network speeds got faster, it got easier to hack into networks and do damage," Jones said. "And there was about a three- year cycle before NCUA said we had to do something about it.

"Now we're in a very similar situation with extrusion prevention, where the examiners will soon look for you to have policies and tools in place," Jones suggested.

The NCUA already expects credit unions to protect members from the insider threat, according to Joy Lee, NCUA director, division of supervision, examination and insurance. "Extrusion prevention is a relatively new term, but NCUA Regulations address this concept," in NCUA Rules and Regulations, Appendix A to Part 748, explained Lee.

Though the NCUA specifically addresses intrusion prevention, there are no regulations, letters to credit unions, or legal opinions that mention extrusion prevention by name.

Insiders have become a serious threat, according to the 2005 Computer Crime and Security Survey conducted by the Computer Security Institute and the FBI, which reported that employees are responsible-purposefully or accidentally-for about 50% of today's security breaches.

Beyond the research tanks, CUs themselves have told Credit Union Journal about sobering incidents that reveal the extent of the problem.

Outgoing e-mail is the most heinous transgressor, according to several CUs. Ironically, those transgressions are accidental.

At Long Beach, Calif.-based LBS Financial CU, the "No. 1 security concern is accidental leakage of data," said Kevin Reed, vice president, information systems. "The most likely security incident is that an employee might accidentally e-mail information home or take data on a CD-ROM out of the credit union."

Twice in the past year, employees at the $1-billion CU have attempted to send documents containing member names with social security and credit card numbers to friends in an e-mail where the friend's address was accidentally autopopulated, Reed explained.

Fortunately for the credit union, the private data in those e-mails was detected, blocked and flagged by an automatic content filter, said Reed.

The $250-million Signal Financial is also wary of misdirected e-mails, though no data has been lost that way, Jones said. "But I know that it could happen.

"The biggest problem is when a member sends us an e-mail with their name and credit card number and asks for help with an account," Jones said. "If the member doesn't use the secure communication form through our website, our staff could reply to the e-mail and inadvertently leave the sensitive data in the e-mail body, sending the card numbers back out again."

By the end of the year, the credit union's content monitoring tool will be able to automatically remove sensitive data from outgoing e-mails or any TCP, SMTP, FTP, HTTP or web mail transmission.

EECU in Ft. Worth, Texas, told Credit Union Journal last year that it started encrypting outgoing e-mails after discovering that several departments across the $615-million CU were sending and receiving unsecured messages containing social security and account numbers and passwords.

For More Resources

Read more about extrusion prevention and e-mail filters at cujournal.com and search the following bolded terms in the archive:

Big Brother Tech Delivers Better Security, Awareness, for how credit unions are using employee-monitoring tools to prevent data leakage.

How 1 CU Is Ensuring Data Doesn't Leave On Employee Flash Drives And MP3 Players for more on South Western's use of USB security software.

e(ncrypting) e-mail, for more on the e-mail encryption platforms at EECU, Air Academy FCU and TPS CU.

For More Information on this story:

* LBS Financial CU, www.lbsfcu.org

* Signal Financial, www.sfonline.org

* EECU, www.eecu.org

To learn about the relevant regulations referred to in this story:

* NCUA Rules and Regulations, Appendix A to Part 748, http://www.ncua.gov/RegulationsOpinionsLaws/rules-and-regs/NCUA-RR-Complete-2.pdf

* NCUA General Counsel Robert Fenner on data security laws, www.ncua.gov/news/speeches/2005/Fenner/DataSecurityHearingNCUATestimony.pdf


For reprint and licensing requests for this article, click here.
Technology
MORE FROM AMERICAN BANKER
Load More