SERVICES / CREDIT UNION PENETRATION TESTING

SERVICES / CREDIT UNION PENETRATION TESTING

NCUA & GLBA Compliance Assurance

NCUA & GLBA Compliance Assurance

Why Credit Unions Need More Than a Vulnerability Scan

Member financial data (account numbers, Social Security numbers, and loan records) is among the most valuable targets on the black market, and unlike a card number it cannot simply be reissued. Credit unions run a sprawling attack surface: core banking platforms, online and mobile banking, member portals, ATM and ITM fleets, third-party fintech integrations, and flat branch networks that were never designed with segmentation in mind.

The NCUA’s Part 748 guidelines and the GLBA Safeguards Rule require credit unions to run a risk-based assessment of the controls protecting member information, and to test those controls regularly. An automated scan lists missing patches; it does not tell you whether an attacker can pivot from a compromised teller workstation into your core banking system. Thorium bridges that gap. Our team spent their careers running offensive operations at the Department of Defense level, and we bring that adversarial rigor to financial environments where a missed finding puts member funds and member trust at risk.

Every engagement produces evidence-backed proof of exposure mapped directly to NCUA and GLBA safeguards, along with a prioritized remediation roadmap and examiner-ready documentation that stands up to scrutiny.

WHAT’S REALLY AT STAKE

A credit union runs on one thing above all: member trust. A breach doesn’t just expose account numbers; it breaks the promise that a member’s money and identity are safe with you.

A credit union runs on one thing above all: member trust. A breach doesn’t just expose account numbers; it breaks the promise that a member’s money and identity are safe with you.

We test the way an attacker does, so you can prove, to members, examiners, and your board, that the promise holds.

$6.08M

$6.08M

$6.08M

Average cost of a financial-services data breach, well above the cross-industry average

72 hrs

72 hrs

72 hrs

NCUA’s deadline to report a reportable cyber incident after it is discovered

§748

§748

§748

The NCUA regulation requiring a written security program and incident response plan

GLBA

GLBA

GLBA

The Safeguards Rule mandating risk-based testing of member-data controls

MAPPED TO NCUA & GLBA REQUIREMENTS

How Testing Satisfies 12 CFR 748 & the GLBA Safeguards Rule

Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.

12 CFR 748 App. A

Information Security Program

A penetration test delivers the risk-based assessment of the controls protecting member information that the NCUA guidelines require, with demonstrated exploitability, not theoretical risk.

16 CFR 314.4(d)

Testing of Safeguards

The GLBA Safeguards Rule mandates regular testing or monitoring of key controls. Annual engagements and continuous assessment satisfy this obligation after any material change.

16 CFR 314.4(c)

Access Controls

We test whether authentication, least-privilege, and MFA actually prevent unauthorized reach into core banking, online banking, and member records.

16 CFR 314.4(c)(3)

Encryption in Transit & at Rest

We validate encryption of member data across online and mobile banking, APIs, and internal transfers, attempting interception, downgrade, and man-in-the-middle attacks.

12 CFR 748 App. A · III.C

Staff Security Awareness

Phishing and social-engineering simulations measure how tellers, MSRs, and back-office staff respond to realistic attacks aimed at harvesting credentials and member data.

12 CFR 748.1(c)

Incident Response & Notification

NCUA requires reporting a reportable cyber incident within 72 hours. We stress-test detection and response so your team notices an intrusion before member funds are at risk.

THE THREAT LANDSCAPE

The Attacks That Hit Credit Unions Most

01

Ransomware & Data Extortion

Attackers encrypt core and member-facing systems, then threaten to leak member data, halting operations and triggering NCUA reporting obligations.

02

Wire & ACH Fraud

Business email compromise and social engineering redirect member and institutional funds through fraudulent wire and ACH transfers.

03

Account Takeover

Credential stuffing and phishing against online and mobile banking give attackers direct access to member accounts and balances.

04

Third-Party & CUSO Compromise

Core processors, fintech integrations, and shared CUSOs extend your attack surface far beyond your own network perimeter.

ENGAGEMENT METHODOLOGY

A Repeatable, Evidence-Driven Process

01

Scope & RoE

02

Reconnaissance

03

Exploitation

04

Data Impact

05

Reporting

06

Re-Test

ASSESSMENT COVERAGE

What We Test in a Credit Union Environment

Engagements are scoped to your environment. Below are the domains we most commonly assess for credit unions and the members whose data and funds they protect.

DIGITAL / ONLINE BANKING

Online & Mobile Banking Testing

We assess online banking, mobile apps, and account-opening flows for authentication bypass, broken access control, and functions that could expose member accounts, balances, and transfers to an attacker.

ONLINE BANKING

MOBILE

AUTH BYPASS

ACCOUNT TAKEOVER

MEMBER-FACING / PORTALS

Member Portals & Bill Pay

Member portals, bill pay, and loan-application systems are tested for insecure direct object references that expose other members’ records, account takeover, and weak session handling.

IDOR

BILL PAY

SESSION

ACCOUNT TAKEOVER

CORE / PROCESSING

Core Banking System Testing

Symitar, Fiserv, Corelation, and other core platforms are tested for insecure interfaces, weak access control, and pathways that expose the general ledger and complete member records.

SYMITAR

FISERV

CORE ACCESS

LEDGER

CLOUD / MEMBER DATA

Cloud & Member Data Audits

AWS, Azure, and GCP environments holding member data are reviewed for exposed storage, misconfigured IAM roles, and unencrypted backups, mapped to GLBA and FFIEC control expectations.

IAM MISCONFIG

BUCKET EXPOSURE

ENCRYPTION

GLBA

INTERNAL / NETWORK

Internal Network & Segmentation

We simulate a breached teller workstation to test lateral movement, flat-network exposure, and whether a single foothold can reach the core banking system, domain controllers, and backups.

LATERAL MOVEMENT

ACTIVE DIRECTORY

SEGMENTATION

PRIVILEGE ESC

PAYMENTS / ATM

ATM, ITM & Payments Testing

ATM and ITM fleets, card systems, and payment rails (ACH, wire, and card processing) are tested for network exposure, default credentials, and fraud pathways.

ATM / ITM

ACH

CARD DATA

WIRE FRAUD

WIRELESS / PHYSICAL

Branch Wireless & Physical Access

Branch Wi-Fi, guest networks, and physical access to teller stations, vaults, and server rooms are tested, including tailgating into restricted areas and unlocked, unattended sessions.

WPA2 / WPA3

ROGUE AP

TAILGATING

TELLER STATION

HUMAN / SOCIAL

Social Engineering & Phishing

Targeted phishing, vishing, and pretexting against branch and back-office staff measure real-world susceptibility to credential theft and unauthorized access to member data, the leading cause of financial breaches.

PHISHING

VISHING

PRETEXTING

MFA FATIGUE

WHO WE SERVE

Built for Every Charter

Community Credit Unions

Lean teams protecting tight-knit memberships

Mid-Size & Regional

Growing branch and digital footprints

Corporate Credit Unions

Wholesale services and settlement at scale

CUSOs & Fintech Partners

Shared platforms and third-party integrations

STANDARDS & FRAMEWORKS

Aligned to the Regulations That Govern You

NCUA

Part 748

GLBA

Safeguards

FFIEC

CAT

NIST

CSF / 800-53

PCI DSS

Card Data

SOC 2

Trust Services

WHAT YOU RECEIVE

Examiner-Ready Documentation, Not Just a Tool Dump

Examiner-Ready Findings Report

A findings report structured to support your NCUA examination and GLBA risk-assessment obligations, with reproducible evidence and severity ratings for every issue.

Executive Attestation Letter

A signed engagement summary suitable for your board, supervisory committee, examiners, and cyber-insurance carriers.

Prioritized Remediation Roadmap

Every finding mapped to a concrete fix and sequenced by risk to member data and funds, so your IT team can close the most dangerous gaps first.

Complimentary Re-Test

After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.

Find out what an attacker could reach before an examiner does.

Find out what an attacker could reach before an examiner does.

We scope every credit union engagement individually. Tell us about your environment (online banking, core, ATMs, branches) and we’ll respond within one business day.

Request a Scoping Call

Thorium Information Security, LLC.

Hayden, Idaho, USA

Hayden, Idaho, USA

(208) 352-2877

(208) 352-2877

Sales@ThoriumInfosec.com

Sales@ThoriumInfosec.com

Copyright © 2026 Thorium Information Security LLC. All rights reserved.

Copyright © 2026 Thorium Information Security LLC. All rights reserved.