Welcome!

News Feed Item

NAFCU: Credit Unions Pay High Price for Data Breaches

The National Association of Federal Credit Unions’ (NAFCU) February Economic & CU Monitor survey found that credit unions, and by extension their 96 million members, are paying a high price for retailers’ data breaches. NAFCU estimates that the recent Target data breach could end up costing the credit union community nearly $30 million. Among those surveyed, the average cost for the Target data breach was $45,000.

“The survey findings are staggering. Credit unions are being hit by a double whammy in terms of numbers of possible data breaches and costs while they continue to pick up the tab for retailers who are not subject to the same high level of data security standards,” said NAFCU Chief Economist and Director of Research David Carrier. “It is ironic that despite the ample rules in place to ensure data protection standards at financial institutions like credit unions, merchants and retailers are not held accountable for data breaches. Cybercriminals will continue to capitalize on this double standard and wreak havoc with consumers and our economy.”

NAFCU’s Economic & CU Monitor on data security reported:

  • Respondents were alerted to a possible breach 263 times on average in 2013, and the average amount spent on data security measures was $158,600.
  • Respondents reported an average of $152,000 for data breaches in 2013. The median cost was $59,000.
  • The bulk of these costs were related to fraud losses and investigations (46.7 percent), followed by reissue costs (34.4 percent) and monitoring costs (19 percent). Reissuing cards takes 7 days, on average, and costs $5 per card.
  • Almost half (42 percent) of respondents confirmed that their reputation had been harmed due to a merchant data breach.
  • Survey respondents indicated that an average of 10,300 cards were affected by merchant data breaches in 2013.

NAFCU was the first financial services trade association to weigh in on this issue on Capitol Hill and urged Congress to take action and set national data security standards for retailers and merchants. Financial institutions, including credit unions, have been subject to standards on data security since 1999 under the Gramm-Leach-Bliley Act. However, retailers and other entities that handle sensitive personal financial data are not. So, when a data breach occurs, financial institutions bear a significant burden as the issuers of payment cards used by millions of consumers.

NAFCU is urging Congress to pass S. 1927, the “Data Security Act of 2014,” by Sens. Tom Carper, D-Del., and Roy Blunt, R-Mo. This bill leaves intact the federal standards already imposed on financial institutions and seeks to extend the protection further, by setting national standards for all merchants and retailers to follow in protecting data, providing timely breach notification and paying their share of the clean-up when breaches occur.

NAFCU’s Economic and CU Monitor is a member-only monthly e-newsletter of the latest macroeconomic and financial trends affecting today's credit unions, including trend data among NAFCU member federal credit unions.

The National Association of Federal Credit Unions is the only national organization that focuses exclusively on federal issues affecting credit unions, representing its members before the federal government and the public.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
Cloud Expo, Inc. has announced today that Andi Mann returns to 'DevOps at Cloud Expo 2017' as Conference Chair The @DevOpsSummit at Cloud Expo will take place on June 6-8, 2017, at the Javits Center in New York City, NY. "DevOps is set to be one of the most profound disruptions to hit IT in decades," said Andi Mann. "It is a natural extension of cloud computing, and I have seen both firsthand and in independent research the fantastic results DevOps delivers. So I am excited to help the great t...
Every successful software product evolves from an idea to an enterprise system. Notably, the same way is passed by the product owner's company. In his session at 20th Cloud Expo, Oleg Lola, CEO of MobiDev, will provide a generalized overview of the evolution of a software product, the product owner, the needs that arise at various stages of this process, and the value brought by a software development partner to the product owner as a response to these needs.
In 2014, Amazon announced a new form of compute called Lambda. We didn't know it at the time, but this represented a fundamental shift in what we expect from cloud computing. Now, all of the major cloud computing vendors want to take part in this disruptive technology. In his session at 20th Cloud Expo, John Jelinek IV, a web developer at Linux Academy, will discuss why major players like AWS, Microsoft Azure, IBM Bluemix, and Google Cloud Platform are all trying to sidestep VMs and containers...
SYS-CON Events announced today that MobiDev, a client-oriented software development company, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex softw...
SYS-CON Events announced today that Enzu will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enzu’s mission is to be the leading provider of enterprise cloud solutions worldwide. Enzu enables online businesses to use its IT infrastructure to their competitive ad...
Smart Cities are here to stay, but for their promise to be delivered, the data they produce must not be put in new siloes. In his session at @ThingsExpo, Mathias Herberts, Co-founder and CTO of Cityzen Data, discussed the best practices that will ensure a successful smart city journey.
In his session at 19th Cloud Expo, Claude Remillard, Principal Program Manager in Developer Division at Microsoft, contrasted how his team used config as code and immutable patterns for continuous delivery of microservices and apps to the cloud. He showed how the immutable patterns helps developers do away with most of the complexity of config as code-enabling scenarios such as rollback, zero downtime upgrades with far greater simplicity. He also demoed building immutable pipelines in the cloud ...
Traditional on-premises data centers have long been the domain of modern data platforms like Apache Hadoop, meaning companies who build their business on public cloud were challenged to run Big Data processing and analytics at scale. But recent advancements in Hadoop performance, security, and most importantly cloud-native integrations, are giving organizations the ability to truly gain value from all their data. In his session at 19th Cloud Expo, David Tishgart, Director of Product Marketing ...
Choosing the right cloud for your workloads is a balancing act that can cost your organization time, money and aggravation - unless you get it right the first time. Economics, speed, performance, accessibility, administrative needs and security all play a vital role in dictating your approach to the cloud. Without knowing the right questions to ask, you could wind up paying for capacity you'll never need or underestimating the resources required to run your applications.
Technology vendors and analysts are eager to paint a rosy picture of how wonderful IoT is and why your deployment will be great with the use of their products and services. While it is easy to showcase successful IoT solutions, identifying IoT systems that missed the mark or failed can often provide more in the way of key lessons learned. In his session at @ThingsExpo, Peter Vanderminden, Principal Industry Analyst for IoT & Digital Supply Chain to Flatiron Strategies, will focus on how IoT depl...
Adding public cloud resources to an existing application can be a daunting process. The tools that you currently use to manage the software and hardware outside the cloud aren’t always the best tools to efficiently grow into the cloud. All of the major configuration management tools have cloud orchestration plugins that can be leveraged, but there are also cloud-native tools that can dramatically improve the efficiency of managing your application lifecycle. In his session at 18th Cloud Expo, ...
The pace of innovation, vendor lock-in, production sustainability, cost-effectiveness, and managing risk… In his session at 18th Cloud Expo, Dan Choquette, Founder of RackN, discussed how CIOs are challenged finding the balance of finding the right tools, technology and operational model that serves the business the best. He also discussed how clouds, open source software and infrastructure solutions have benefits but also drawbacks and how workload and operational portability between vendors an...
With the proliferation of both SQL and NoSQL databases, organizations can now target specific fit-for-purpose database tools for their different application needs regarding scalability, ease of use, ACID support, etc. Platform as a Service offerings make this even easier now, enabling developers to roll out their own database infrastructure in minutes with minimal management overhead. However, this same amount of flexibility also comes with the challenges of picking the right tool, on the right ...
Big Data, cloud, analytics, contextual information, wearable tech, sensors, mobility, and WebRTC: together, these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at @ThingsExpo, Erik Perotti, Senior Manager of New Ventures on Plantronics’ Innovation team, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it m...
Manufacturers are embracing the Industrial Internet the same way consumers are leveraging Fitbits – to improve overall health and wellness. Both can provide consistent measurement, visibility, and suggest performance improvements customized to help reach goals. Fitbit users can view real-time data and make adjustments to increase their activity. In his session at @ThingsExpo, Mark Bernardo Professional Services Leader, Americas, at GE Digital, discussed how leveraging the Industrial Internet and...