Why Credit Unions Need More Than a Vulnerability Scan
Member financial data (account numbers, Social Security numbers, and loan records) is among the most valuable targets on the black market, and unlike a card number it cannot simply be reissued. Credit unions run a sprawling attack surface: core banking platforms, online and mobile banking, member portals, ATM and ITM fleets, third-party fintech integrations, and flat branch networks that were never designed with segmentation in mind.
The NCUA’s Part 748 guidelines and the GLBA Safeguards Rule require credit unions to run a risk-based assessment of the controls protecting member information, and to test those controls regularly. An automated scan lists missing patches; it does not tell you whether an attacker can pivot from a compromised teller workstation into your core banking system. Thorium bridges that gap. Our team spent their careers running offensive operations at the Department of Defense level, and we bring that adversarial rigor to financial environments where a missed finding puts member funds and member trust at risk.
Every engagement produces evidence-backed proof of exposure mapped directly to NCUA and GLBA safeguards, along with a prioritized remediation roadmap and examiner-ready documentation that stands up to scrutiny.
WHAT’S REALLY AT STAKE
We test the way an attacker does, so you can prove, to members, examiners, and your board, that the promise holds.
Average cost of a financial-services data breach, well above the cross-industry average
NCUA’s deadline to report a reportable cyber incident after it is discovered
The NCUA regulation requiring a written security program and incident response plan
The Safeguards Rule mandating risk-based testing of member-data controls
MAPPED TO NCUA & GLBA REQUIREMENTS
How Testing Satisfies 12 CFR 748 & the GLBA Safeguards Rule
Each engagement is scoped to produce evidence that maps directly to the administrative and technical safeguards your organization is required to implement and evaluate.
12 CFR 748 App. A
Information Security Program
A penetration test delivers the risk-based assessment of the controls protecting member information that the NCUA guidelines require, with demonstrated exploitability, not theoretical risk.
16 CFR 314.4(d)
Testing of Safeguards
The GLBA Safeguards Rule mandates regular testing or monitoring of key controls. Annual engagements and continuous assessment satisfy this obligation after any material change.
16 CFR 314.4(c)
Access Controls
We test whether authentication, least-privilege, and MFA actually prevent unauthorized reach into core banking, online banking, and member records.
16 CFR 314.4(c)(3)
Encryption in Transit & at Rest
We validate encryption of member data across online and mobile banking, APIs, and internal transfers, attempting interception, downgrade, and man-in-the-middle attacks.
12 CFR 748 App. A · III.C
Staff Security Awareness
Phishing and social-engineering simulations measure how tellers, MSRs, and back-office staff respond to realistic attacks aimed at harvesting credentials and member data.
12 CFR 748.1(c)
Incident Response & Notification
NCUA requires reporting a reportable cyber incident within 72 hours. We stress-test detection and response so your team notices an intrusion before member funds are at risk.
THE THREAT LANDSCAPE
The Attacks That Hit Credit Unions Most
01
Ransomware & Data Extortion
Attackers encrypt core and member-facing systems, then threaten to leak member data, halting operations and triggering NCUA reporting obligations.
02
Wire & ACH Fraud
Business email compromise and social engineering redirect member and institutional funds through fraudulent wire and ACH transfers.
03
Account Takeover
Credential stuffing and phishing against online and mobile banking give attackers direct access to member accounts and balances.
04
Third-Party & CUSO Compromise
Core processors, fintech integrations, and shared CUSOs extend your attack surface far beyond your own network perimeter.
ENGAGEMENT METHODOLOGY
A Repeatable, Evidence-Driven Process
01
Scope & RoE
02
Reconnaissance
03
Exploitation
04
Data Impact
05
Reporting
06
Re-Test
ASSESSMENT COVERAGE
What We Test in a Credit Union Environment
Engagements are scoped to your environment. Below are the domains we most commonly assess for credit unions and the members whose data and funds they protect.
DIGITAL / ONLINE BANKING
Online & Mobile Banking Testing
We assess online banking, mobile apps, and account-opening flows for authentication bypass, broken access control, and functions that could expose member accounts, balances, and transfers to an attacker.
ONLINE BANKING
MOBILE
AUTH BYPASS
ACCOUNT TAKEOVER
MEMBER-FACING / PORTALS
Member Portals & Bill Pay
Member portals, bill pay, and loan-application systems are tested for insecure direct object references that expose other members’ records, account takeover, and weak session handling.
IDOR
BILL PAY
SESSION
ACCOUNT TAKEOVER
CORE / PROCESSING
Core Banking System Testing
Symitar, Fiserv, Corelation, and other core platforms are tested for insecure interfaces, weak access control, and pathways that expose the general ledger and complete member records.
SYMITAR
FISERV
CORE ACCESS
LEDGER
CLOUD / MEMBER DATA
Cloud & Member Data Audits
AWS, Azure, and GCP environments holding member data are reviewed for exposed storage, misconfigured IAM roles, and unencrypted backups, mapped to GLBA and FFIEC control expectations.
IAM MISCONFIG
BUCKET EXPOSURE
ENCRYPTION
GLBA
INTERNAL / NETWORK
Internal Network & Segmentation
We simulate a breached teller workstation to test lateral movement, flat-network exposure, and whether a single foothold can reach the core banking system, domain controllers, and backups.
LATERAL MOVEMENT
ACTIVE DIRECTORY
SEGMENTATION
PRIVILEGE ESC
PAYMENTS / ATM
ATM, ITM & Payments Testing
ATM and ITM fleets, card systems, and payment rails (ACH, wire, and card processing) are tested for network exposure, default credentials, and fraud pathways.
ACH
CARD DATA
WIRE FRAUD
WIRELESS / PHYSICAL
Branch Wireless & Physical Access
Branch Wi-Fi, guest networks, and physical access to teller stations, vaults, and server rooms are tested, including tailgating into restricted areas and unlocked, unattended sessions.
WPA2 / WPA3
ROGUE AP
TAILGATING
TELLER STATION
HUMAN / SOCIAL
Social Engineering & Phishing
Targeted phishing, vishing, and pretexting against branch and back-office staff measure real-world susceptibility to credential theft and unauthorized access to member data, the leading cause of financial breaches.
PHISHING
VISHING
PRETEXTING
MFA FATIGUE
WHO WE SERVE
Built for Every Charter
Community Credit Unions
Lean teams protecting tight-knit memberships
Mid-Size & Regional
Growing branch and digital footprints
Corporate Credit Unions
Wholesale services and settlement at scale
CUSOs & Fintech Partners
Shared platforms and third-party integrations
STANDARDS & FRAMEWORKS
Aligned to the Regulations That Govern You
NCUA
Part 748
GLBA
Safeguards
FFIEC
CAT
NIST
CSF / 800-53
PCI DSS
Card Data
SOC 2
Trust Services
WHAT YOU RECEIVE
Examiner-Ready Documentation, Not Just a Tool Dump
Examiner-Ready Findings Report
A findings report structured to support your NCUA examination and GLBA risk-assessment obligations, with reproducible evidence and severity ratings for every issue.
Executive Attestation Letter
A signed engagement summary suitable for your board, supervisory committee, examiners, and cyber-insurance carriers.
Prioritized Remediation Roadmap
Every finding mapped to a concrete fix and sequenced by risk to member data and funds, so your IT team can close the most dangerous gaps first.
Complimentary Re-Test
After you remediate, we re-test the confirmed findings and update your documentation to verify closure, at no additional cost.
We scope every credit union engagement individually. Tell us about your environment (online banking, core, ATMs, branches) and we’ll respond within one business day.
Request a Scoping Call
