Credit unions
- NCUA ISE
- ACET
- 12 CFR 748
Federally insured credit unions are examined on information security, and the scope grows with asset size. Examiners expect a current risk assessment, a written program, board oversight and evidence, and assembling that evidence is often the hardest part.
- Risk assessments aligned to NCUA expectations.
- ACET-aligned maturity and inherent risk profiling.
- Vulnerability assessments of your network, Microsoft 365 and internet-facing systems, with findings written up for your board and examiners.
- Exam preparation: assembling the documentation examiners request.
- Board reporting, and incident procedures that meet the 72-hour reporting rule.