Cyberwall Blog · August 24, 2026

What Credit Unions Should Ask a Managed Security Provider

A practical checklist for credit union IT Directors and CEOs evaluating a managed security provider, from examiner expectations to incident notification timelines.

By Alex Plotkin, CEO

Credit unions sit in an unusual spot in the security world. You carry the same member-data sensitivity and regulatory scrutiny as a bank, often with a fraction of the internal security staff. When the board asks how the institution is protected, “we have antivirus and a firewall” stopped being an acceptable answer years ago. So did picking a managed security provider based on a glossy sales deck.

Examiners, whether that’s OSFI in Canada or an NCUA or FFIEC-aligned reviewer in the US, don’t grade your vendor’s marketing. They grade whether your institution can demonstrate it understood what it was buying, verified the vendor could actually deliver it, and can produce evidence of that oversight on request. That means the questions you ask a prospective provider matter as much as the answers. Below are the ones worth asking before you sign anything.

1. How do you handle regulatory reporting, not just technical alerts?

A credit union’s board and examiners don’t want a feed of blocked IP addresses. They want a posture summary they can act on: what’s being monitored, what’s changed, what residual risk looks like, and what decisions the board needs to make. Ask a provider to show you a sample report, not describe one. If what they hand you reads like a firewall log, that’s a real signal about how they’ll perform under actual regulatory pressure. A provider used to serving credit unions should be comfortable producing something a director with no technical background can read in five minutes and explain to an examiner.

2. What’s your actual notification timeline if something happens at 2 a.m.?

Every vendor will claim “24/7 monitoring.” Fewer will commit, in writing, to a specific time for the first human callback after something suspicious is confirmed. Credit unions face incident and breach notification expectations under both Canadian privacy law and US state breach-notification statutes, and those clocks often start running before your own team even knows there’s a problem. Ask for the exact triage, escalation, and full-team-engagement timeline, and ask what happens if they miss it. A provider without a specific, documented SLA is asking you to take their word for it during the worst week of the year.

3. How do you support our vendor risk management obligations, not just your own?

Examiners increasingly treat a credit union’s third-party vendors, including its security provider, as part of the institution’s own risk surface. That means you’ll periodically need evidence about the vendor itself: their own security posture, their subprocessors, their audit history. A provider who has been through this before will have documentation ready, most commonly a SOC 2 report or similar independent attestation, without treating the request as unusual. If a vendor bristles at being asked to prove their own controls, that’s worth noting before, not after, you’re the one explaining the gap to an examiner.

4. What happens with our cyber insurance if we have an incident?

This is a question a lot of credit unions skip, and it’s an expensive one to get wrong. Ask specifically how the provider works with your carrier and breach counsel during an active incident: do they understand chain-of-custody requirements well enough that the evidence they collect will actually hold up during a claim review? Be direct about one thing in particular: no legitimate provider should claim to be “on” your carrier’s approved panel unless they can show you that in writing. What a strong answer sounds like is coordination, not a panel claim: the provider works directly with your carrier and counsel throughout the incident, understands what insurers expect from documentation, and won’t be a surprise name your carrier has never heard of when a claim is filed.

5. Can you show us your response plan for a credit-union-specific scenario, not a generic one?

A ransomware tabletop is useful. A tabletop that walks through core banking system disruption, member notification obligations, and coordination with your regulator specifically is more useful. Ask the provider to walk through, in detail, how they’d handle a scenario involving your member-facing systems, not just your back office. If they can only describe a generic enterprise incident response process, they haven’t done this with a financial institution before, or haven’t done it enough times to have the specifics memorized.

6. What does day-to-day monitoring actually cover, and what’s excluded?

“Managed security” means different things to different vendors, and the gaps usually surface at the worst possible time. Ask explicitly what’s inside the service versus billed separately: endpoint coverage, email and browser threats, cloud environments, dark web exposure of member or staff credentials, and backup integrity are all things a credit union should expect visibility into, not assume are automatically included. Get the list in writing and compare it line by line against what you’re actually being billed for. A good managed services provider will be able to show you exactly where coverage starts and stops without vague language.

7. How do you help us prepare for our own compliance and examination cycles?

A credit union’s compliance obligations don’t stop at “prevent a breach.” Examiners want evidence of ongoing risk assessments, policy reviews, and documented controls mapped to whatever frameworks apply to your institution. Ask whether the provider actively supports that documentation and evidence-gathering work, or whether it’s assumed to be entirely on your internal team. Providers that offer real compliance services alongside monitoring tend to save credit unions the most time here, since the same evidence that supports day-to-day security also supports the next exam.

8. Who actually answers the phone, and what do they know about credit unions?

Finally, ask about the humans. A dashboard doesn’t call your CEO at 3 a.m. A support contract with no named team behind it doesn’t understand the difference between a retail business and a federally or provincially regulated financial institution. Ask who staffs the response, whether they have direct experience with credit unions or community financial institutions specifically, and whether you’ll be talking to the same team consistently or a different analyst every time you call. Consistency and sector familiarity matter more here than almost anywhere else in the relationship.

None of these questions have a single “right” vendor behind them. What they should produce is clarity: specific answers, documentation you can show your board, and a provider willing to be evaluated on the same terms your examiners will eventually evaluate you on. A vendor that treats those questions as reasonable, rather than as an inconvenience, is usually the one worth a longer conversation.

Related reading: Cyberwall Successfully Passes SOC 2 Type II Audit · Recent Privacy Breaches: A Wake-Up Call

Not ready to wait on a blog post?

Book a preparedness call and get a straight answer for your specific situation, no searching required.