Cyber and fraud threats against credit unions are evolving faster than most control environments. From online and mobile banking fraud to ACH and wire manipulation, business email compromise, vendor access abuse, and account takeover, attacks are no longer isolated IT issues — they are enterprise risk events.
This one-hour session provides a candid, real-world look at where cyber and fraud risk most often shows up inside credit unions — and how these attacks are actually starting. We will examine common entry points including phishing, ransomware, MFA fatigue, credential stuffing, deepfake impersonation, and third-party compromise, with practical examples of what is actively hitting financial institutions today.
Participants will explore where controls are breaking down, including:
- Weak identity and access management practices
- Overreliance on MFA without monitoring for fatigue and bypass
- Gaps in vendor oversight and third-party monitoring
- Disconnects between IT security and fraud teams
- Incident response plans that look strong on paper but fail in execution
We will also discuss where credit unions tend to be overconfident — particularly in access management, testing, fraud collaboration, and control validation — and what examiners and regulators are increasingly scrutinizing.
About the Speakers
Ben Brady began his career in accounting in 1989 but quickly transitioned into IT, becoming a network administrator and never looking back. He spent nearly 20 years working with Internet Service Providers in Tennessee, earning a Bachelor’s Degree in Management Information Systems from Tennessee Technological University along with multiple Cisco, Microsoft, and security certifications.
In 2007, Ben became a partner in an IT services company and later sole owner of CipherTek Systems, LLC, which serves regulated clients across communications, financial, healthcare, and industrial sectors. In 2011, he co-founded White Mile Consulting, LLC, focusing on audit, compliance, risk management, and policy for financial and healthcare organizations throughout the Southeast.
Ben holds CDPSE, CISA, CISM, CRISC, CISSP, and CDPP certifications and is pursuing a Master’s Degree in Cybersecurity. He is active in ISSA, ISACA, and Rotary, and lives in Cookeville, Tennessee with his wife and four children.
Jason Duke holds a BS and MBA in Information Systems from Tennessee Tech University, as well as a Master’s in Information Quality and a PhD in Computer and Information Science from the University of Arkansas at Little Rock. He also completed the Southeastern School of Banking at Vanderbilt while serving 18 years as CIO of a commercial bank.
With more than 30 years of experience in IT audits and network security within the financial sector, Jason specializes in IT audits, risk assessments, policy development, and cybersecurity consulting. He holds numerous industry certifications, including CISSP, CISA, CISM, CDPSE, Microsoft Certified Systems Engineer, CompTIA A+, Network+, Security+, Data+, and Certified Cybersecurity Practitioner.
Outside of work, Jason enjoys restoring log cabins and Ford Mustangs, flying, motorcycling, and traveling.