SlideShare a Scribd company logo
1 of 11
Staying Safe In A Quickly Evolving World
Information Technology
Going Digital & Associated Risks
Andrews Duffy
• Why Us – independent advice, take ownership of IT on your behalf, work with
your IT providers, non techie chats on IT, trusted
• Risk Management
• Project Management
• IT Management – ownership of IT on your behalf
• IT Audits & Security Reviews
• Brian Andrews brian@andrewsduffy.ie
• www.andrewsduffy.ie
Current Digital Membership Solutions (Available)
• Online Banking Services - website
• Online Loan Applications, Processing and Approval
• Mobile Applications
• Current Accounts
• New Member Onboarding
Inhouse Resources
• AML Processing
• Customer Relationship Marketing
Digitisation
Interaction with customers online, email, social media or mobile (app)
• Methods of Communication
• Spread of Information/News quicker and more accurate
• Smaller Entities can Target Niche Segments or Geographical Locations
• Leverage Products, Services, Processes (Strategy)
• Free up resources, staff time
• Greater Exposure to potential avenues for Cyber Security Issues
• Cost
• Keeping your message relevant to your audience (Digital Marketing)
• Persons to understand how it all works together (Staff / Contractors)
Positive
Negative
Regulations & Guidance
Challenge to Risk Officers & CEO’s
• Who keeps you informed?
• How do you distinguish - what is required vs what
is nice to have?
• Who understands the audit findings?
CBI, EBA, ECB, PRA (UK)
Regulations, Reports, Guidance, Reviews and
Papers on IT Risks for financial institutions
“Information Technology is an
Operational Risk, it is a core
enabler of the business function
of any institution”
Central Bank of Ireland, PRISM Report
Management of ‘Risk’
“A Potential, Negative, Consequential Event “
Imagine the phone ringing at a point
in the future and hearing…..
Something has happened and serious
consequences has occurred
Is it preventable or can it be mitigated
now?
Risks Relevant to Boards & Management Team
• Credit Union Business Strategy is determined by the product offerings of core banking products
• Limited choice / cost of moving (disruption)
• Limited knowledge of their supply chain – who provides IT services to them
• Cyber Risks – Ransomware, Email, Data Breaches
• IT Risks – Updates to software (patches), obsolete equipment
• Governance – Policies not reflective of the IT requirements of CU
• Risk of not having active management of the IT Solution,
• Most providers provide a ‘breakfix or managed service provision’ (Reactive)
• Redundancy / Backups of Solution (BCP)
Understanding the Technology, Terminology and IT in general
• Many credit unions do not have volunteers to assist / advice on IT
• Many CEO’s rely on 3rd Party providers / CUDS to keep them aware of issues
Being Prepared – What If
• Asset Register
• System Updates (Patches)
• Passwords control
• Security Controls
• Training of Staff & BOD
• Resilience of Plan, Test & LEARN
Best Practice
• Understanding the Risk
• IT Asset Register & Risk Register
• IT Governance (Review of Policies & Procedures)
• Systems updated & patched; Antivirus, Firewall, Desktop & Servers – Logs Reviewed
• Awareness & Training
• Education & Training of Staff
• Ongoing Development of Policies & Procedures
• Communication
• Working with Risk Officer, Manager, Risk/Audit Committee
• Future Proofing
• Share & Seek Advice on IT Solutions
brian@andrewsduffy.ie Brian Andrews
www.andrewsduffy.ie

More Related Content

Similar to Staying Safe In A Quickly Evolving World

Community IT Innovators - IT Security Best Practices
Community IT Innovators - IT Security Best PracticesCommunity IT Innovators - IT Security Best Practices
Community IT Innovators - IT Security Best PracticesCommunity IT Innovators
 
Item46763
Item46763Item46763
Item46763madunix
 
Mergers and Acquisition Security - Areas of Interest
Mergers and Acquisition Security - Areas of InterestMergers and Acquisition Security - Areas of Interest
Mergers and Acquisition Security - Areas of InterestMatthew Rosenquist
 
ComResource Agency Solutions
ComResource Agency SolutionsComResource Agency Solutions
ComResource Agency SolutionsAnthony Dials
 
BSIDES DETROIT 2015: Data breaches cost of doing business
BSIDES DETROIT 2015: Data breaches cost of doing businessBSIDES DETROIT 2015: Data breaches cost of doing business
BSIDES DETROIT 2015: Data breaches cost of doing businessJoel Cardella
 
How to Mitigate Risk From Your Expanding Digital Presence
How to Mitigate Risk From Your Expanding Digital PresenceHow to Mitigate Risk From Your Expanding Digital Presence
How to Mitigate Risk From Your Expanding Digital PresenceSurfWatch Labs
 
Security and Compliance
Security and ComplianceSecurity and Compliance
Security and ComplianceBankingdotcom
 
Marketing Program Overview_Sal A _2012 v2.1
Marketing Program Overview_Sal A _2012 v2.1Marketing Program Overview_Sal A _2012 v2.1
Marketing Program Overview_Sal A _2012 v2.1Sal Abramo
 
bh-win-04-conacher.ppt
bh-win-04-conacher.pptbh-win-04-conacher.ppt
bh-win-04-conacher.pptRakesh Kumar
 
The myth of secure computing; management information system; MIS
The myth of secure computing; management information system; MISThe myth of secure computing; management information system; MIS
The myth of secure computing; management information system; MISSaazan Shrestha
 
Infocon Bangladesh 2016
Infocon Bangladesh 2016Infocon Bangladesh 2016
Infocon Bangladesh 2016Prime Infoserv
 
Data Loss Prevention from Symantec
Data Loss Prevention from SymantecData Loss Prevention from Symantec
Data Loss Prevention from SymantecArrow ECS UK
 
Business RISKS From IT
Business RISKS From IT Business RISKS From IT
Business RISKS From IT Sanjiv Arora
 

Similar to Staying Safe In A Quickly Evolving World (20)

PMI Event
PMI EventPMI Event
PMI Event
 
Community IT Innovators - IT Security Best Practices
Community IT Innovators - IT Security Best PracticesCommunity IT Innovators - IT Security Best Practices
Community IT Innovators - IT Security Best Practices
 
Item46763
Item46763Item46763
Item46763
 
Mergers and Acquisition Security - Areas of Interest
Mergers and Acquisition Security - Areas of InterestMergers and Acquisition Security - Areas of Interest
Mergers and Acquisition Security - Areas of Interest
 
ComResource Agency Solutions
ComResource Agency SolutionsComResource Agency Solutions
ComResource Agency Solutions
 
Information Leakage - A knowledge Based Approach
Information Leakage - A knowledge Based ApproachInformation Leakage - A knowledge Based Approach
Information Leakage - A knowledge Based Approach
 
BSIDES DETROIT 2015: Data breaches cost of doing business
BSIDES DETROIT 2015: Data breaches cost of doing businessBSIDES DETROIT 2015: Data breaches cost of doing business
BSIDES DETROIT 2015: Data breaches cost of doing business
 
CIO 360 grados: empoderamiento total
CIO 360 grados: empoderamiento totalCIO 360 grados: empoderamiento total
CIO 360 grados: empoderamiento total
 
How to Mitigate Risk From Your Expanding Digital Presence
How to Mitigate Risk From Your Expanding Digital PresenceHow to Mitigate Risk From Your Expanding Digital Presence
How to Mitigate Risk From Your Expanding Digital Presence
 
Security and Compliance
Security and ComplianceSecurity and Compliance
Security and Compliance
 
Marketing Program Overview_Sal A _2012 v2.1
Marketing Program Overview_Sal A _2012 v2.1Marketing Program Overview_Sal A _2012 v2.1
Marketing Program Overview_Sal A _2012 v2.1
 
bh-win-04-conacher.ppt
bh-win-04-conacher.pptbh-win-04-conacher.ppt
bh-win-04-conacher.ppt
 
The myth of secure computing; management information system; MIS
The myth of secure computing; management information system; MISThe myth of secure computing; management information system; MIS
The myth of secure computing; management information system; MIS
 
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
Privacy, Encryption, and Anonymity in the Civil Legal Aid ContextPrivacy, Encryption, and Anonymity in the Civil Legal Aid Context
Privacy, Encryption, and Anonymity in the Civil Legal Aid Context
 
Infocon Bangladesh 2016
Infocon Bangladesh 2016Infocon Bangladesh 2016
Infocon Bangladesh 2016
 
Byod final (2)
Byod   final (2)Byod   final (2)
Byod final (2)
 
Data Loss Prevention from Symantec
Data Loss Prevention from SymantecData Loss Prevention from Symantec
Data Loss Prevention from Symantec
 
BREACHED: Data Centric Security for SAP
BREACHED: Data Centric Security for SAPBREACHED: Data Centric Security for SAP
BREACHED: Data Centric Security for SAP
 
Security challenges in 2017
Security challenges in 2017Security challenges in 2017
Security challenges in 2017
 
Business RISKS From IT
Business RISKS From IT Business RISKS From IT
Business RISKS From IT
 

Recently uploaded

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfpollardmorgan
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...lizamodels9
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.Aaiza Hassan
 
NewBase 22 April 2024 Energy News issue - 1718 by Khaled Al Awadi (AutoRe...
NewBase  22 April  2024  Energy News issue - 1718 by Khaled Al Awadi  (AutoRe...NewBase  22 April  2024  Energy News issue - 1718 by Khaled Al Awadi  (AutoRe...
NewBase 22 April 2024 Energy News issue - 1718 by Khaled Al Awadi (AutoRe...Khaled Al Awadi
 
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCRsoniya singh
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedKaiNexus
 
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiFULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiMalviyaNagarCallGirl
 
A.I. Bot Summit 3 Opening Keynote - Perry Belcher
A.I. Bot Summit 3 Opening Keynote - Perry BelcherA.I. Bot Summit 3 Opening Keynote - Perry Belcher
A.I. Bot Summit 3 Opening Keynote - Perry BelcherPerry Belcher
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckHajeJanKamps
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCRsoniya singh
 
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadIslamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadAyesha Khan
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Serviceankitnayak356677
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...lizamodels9
 

Recently uploaded (20)

Intro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdfIntro to BCG's Carbon Emissions Benchmark_vF.pdf
Intro to BCG's Carbon Emissions Benchmark_vF.pdf
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
Call Girls In Connaught Place Delhi ❤️88604**77959_Russian 100% Genuine Escor...
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
M.C Lodges -- Guest House in Jhang.
M.C Lodges --  Guest House in Jhang.M.C Lodges --  Guest House in Jhang.
M.C Lodges -- Guest House in Jhang.
 
NewBase 22 April 2024 Energy News issue - 1718 by Khaled Al Awadi (AutoRe...
NewBase  22 April  2024  Energy News issue - 1718 by Khaled Al Awadi  (AutoRe...NewBase  22 April  2024  Energy News issue - 1718 by Khaled Al Awadi  (AutoRe...
NewBase 22 April 2024 Energy News issue - 1718 by Khaled Al Awadi (AutoRe...
 
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Hauz Khas 🔝 Delhi NCR
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… AbridgedLean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
Lean: From Theory to Practice — One City’s (and Library’s) Lean Story… Abridged
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiFULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
 
A.I. Bot Summit 3 Opening Keynote - Perry Belcher
A.I. Bot Summit 3 Opening Keynote - Perry BelcherA.I. Bot Summit 3 Opening Keynote - Perry Belcher
A.I. Bot Summit 3 Opening Keynote - Perry Belcher
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
 
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in IslamabadIslamabad Escorts | Call 03274100048 | Escort Service in Islamabad
Islamabad Escorts | Call 03274100048 | Escort Service in Islamabad
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
 
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
Call Girls In Sikandarpur Gurgaon ❤️8860477959_Russian 100% Genuine Escorts I...
 

Staying Safe In A Quickly Evolving World

  • 1. Staying Safe In A Quickly Evolving World Information Technology Going Digital & Associated Risks
  • 2. Andrews Duffy • Why Us – independent advice, take ownership of IT on your behalf, work with your IT providers, non techie chats on IT, trusted • Risk Management • Project Management • IT Management – ownership of IT on your behalf • IT Audits & Security Reviews • Brian Andrews brian@andrewsduffy.ie • www.andrewsduffy.ie
  • 3. Current Digital Membership Solutions (Available) • Online Banking Services - website • Online Loan Applications, Processing and Approval • Mobile Applications • Current Accounts • New Member Onboarding Inhouse Resources • AML Processing • Customer Relationship Marketing
  • 4. Digitisation Interaction with customers online, email, social media or mobile (app) • Methods of Communication • Spread of Information/News quicker and more accurate • Smaller Entities can Target Niche Segments or Geographical Locations • Leverage Products, Services, Processes (Strategy) • Free up resources, staff time • Greater Exposure to potential avenues for Cyber Security Issues • Cost • Keeping your message relevant to your audience (Digital Marketing) • Persons to understand how it all works together (Staff / Contractors) Positive Negative
  • 5. Regulations & Guidance Challenge to Risk Officers & CEO’s • Who keeps you informed? • How do you distinguish - what is required vs what is nice to have? • Who understands the audit findings? CBI, EBA, ECB, PRA (UK) Regulations, Reports, Guidance, Reviews and Papers on IT Risks for financial institutions
  • 6. “Information Technology is an Operational Risk, it is a core enabler of the business function of any institution” Central Bank of Ireland, PRISM Report
  • 7. Management of ‘Risk’ “A Potential, Negative, Consequential Event “ Imagine the phone ringing at a point in the future and hearing….. Something has happened and serious consequences has occurred Is it preventable or can it be mitigated now?
  • 8. Risks Relevant to Boards & Management Team • Credit Union Business Strategy is determined by the product offerings of core banking products • Limited choice / cost of moving (disruption) • Limited knowledge of their supply chain – who provides IT services to them • Cyber Risks – Ransomware, Email, Data Breaches • IT Risks – Updates to software (patches), obsolete equipment • Governance – Policies not reflective of the IT requirements of CU • Risk of not having active management of the IT Solution, • Most providers provide a ‘breakfix or managed service provision’ (Reactive) • Redundancy / Backups of Solution (BCP) Understanding the Technology, Terminology and IT in general • Many credit unions do not have volunteers to assist / advice on IT • Many CEO’s rely on 3rd Party providers / CUDS to keep them aware of issues
  • 9. Being Prepared – What If • Asset Register • System Updates (Patches) • Passwords control • Security Controls • Training of Staff & BOD • Resilience of Plan, Test & LEARN
  • 10. Best Practice • Understanding the Risk • IT Asset Register & Risk Register • IT Governance (Review of Policies & Procedures) • Systems updated & patched; Antivirus, Firewall, Desktop & Servers – Logs Reviewed • Awareness & Training • Education & Training of Staff • Ongoing Development of Policies & Procedures • Communication • Working with Risk Officer, Manager, Risk/Audit Committee • Future Proofing • Share & Seek Advice on IT Solutions

Editor's Notes

  1. Digital transformation is an essential condition for credit unions to operate, it provides a whole new set of competitive skills and platforms for members. On the other hand, puts credit unions in the face of a whole new series of risks that they have to understand and manage.
  2. The two large players have similar product offerings – Online Banking Solutions, Online Loan Applications, Mobile Applications, Current Accounts. Separately solutions to save credit union resources for AML processing and customer relationship marketing
  3. Digitalisation Digital interaction with customers is allowing organisations to provide a richer user experience – online, email or mobile.   With our current working environments, online services are important to each CU’s future sustainability, with cost a large factor. The larger CUs have sophisticated IT support systems and are more concerned with keeping up-to-date with the latest digital technology and applications. The smaller CUs, on the other hand, are concerned about their inability to provide even basic digital services through the cost of deploying these solutions. Members may never have to step across the threshold of the credit union Many credit unions are now focusing on big data and data analytics - to drive strategy, operational activity, and marketing, the online member platforms are only a tool to better engage with members.
  4. All of these papers outline a variety of Risks for Credit Unions. There are numerous papers produced each quarter reflecting, as we all know the current risks that IT brings to any industry. There is a challenge to credit unions to keep abreast of all of these regulations, understand their content. Again, the risk is that your risk officer, CEO and or Risk Committee may not be aware of them, let alone understand their potential impact to the credit union.
  5. We have to consider the Information Technology risk to credit unions and all business entities. The results of poor Risk Management can result in financial losses due to bad decisions, theft of personal / customer information hurting the credit unions brand, reputation, GDPR and violating laws, audits and prosecutions.  Information Technology has specific issues it must address relative to security and protection of data assets. Balance the needs of operations with that of security and member services
  6. Define the event – it’s the potential of a thing to turn into a reality The phone never rings at 9am on a Monday morning, it tends to be 4pm on a Friday evening. The nature of IT, is that it is best being proactive rather than reactive.
  7. Having worked with many boards, I have observed that when IT is mentioned, eyes start to gloss over, many people get lost with the terms, phrases or technology. Some are lucky to have a person who has a background in IT and can step in when needed with advice. Risks to credit unions Understand that the CU business strategy is influenced by the capabilities of IT which in turn comes from the product offerings of their core banking provider. Cyber Issues, keeping abreast of IT – Credit unions have a break fix / managed service solution, a reacrtionary solution. How do you know if your policies match the need of the Business Continuity Plan How do you actively reviewed the outsourced service provider on behalf of your own credit union? Many times, credit union managers and boards are left with their 3rd party IT Service Providers to explain the need for X, Y and Z with out the understanding on how it fits with in the strategy of the credit union.
  8. Information Technology Going Digital & Associated Risks is about understanding the nature of IT, breaking it down into sectors Keeping the status quo operational, incremental changes to the policies and procedures. Old equipment is cycled out of the system when required. Ensuring that updates occur, Working with the IT vendors to manage risk, building backups in to the system, resources accordingly. Develop an Asset register of all IT equipment Ensure updates are enabled Review the access control for users Develop a training plan for staff, BOD Work with risk officer to develop scenario to test the readiness against our plan
  9. Best Practice is what an organisation would look like Risk analysis, monitor and control where possible Ensure policies & procedures are relevant to the credit union based on best practice Awareness – develop a training program for staff & BOD to educate on the best use of IT in the workplace Communication – regular meetings with stakeholders to ensure transparency on the program of work, done scheduled Future Proofing – work with staff to ensure the correct use of the IT solution. Determine the future needs of the CU and in vestige potential savings of a collective working group.
  10. We have tailored our services for the credit union environment, partly based from the reports from the Central Bank. These focus on IT Governance IT Systems & Security Business Continuity Plan IT Outsourcing & Vendor Management Training Reports to the Board and Audit Committee