
If you’ve ever sat through an audit, prepared for an NCUA examination, or tried to answer questions from your board about cybersecurity, you’ve probably heard someone mention NCUA, FFIEC, or GLBA. Maybe all three. And if you’re like many of the credit union leaders I meet, you’ve probably wondered:
“Are these all different regulations? Which ones actually apply to us? And how do we know we’re doing enough?”
You’re not alone.
After more than 26 years working with organizations that operate in regulated environments, I’ve learned that compliance can feel overwhelming—not because the rules are impossible, but because everyone seems to explain them differently. So let’s make this simple. The three names you hear most often—NCUA, FFIEC, and GLBA—aren’t competing regulations. They work together. Think of them as three people trying to accomplish the same goal: Protect your members. Protect their information. Keep your credit union operating safely. Once you understand how they fit together, compliance starts making a lot more sense.
Start with GLBA: The Law Behind It All
Let’s begin with the one that carries the most legal weight. The Gramm-Leach-Bliley Act (GLBA) is federal law. Among other things, it requires financial institutions—including credit unions—to protect sensitive member information. The Safeguards Rule requires your organization to develop, implement, and maintain an information security program that’s appropriate for your size, complexity, and risk. Notice what it doesn’t say. It doesn’t tell you which firewall to buy. It doesn’t recommend a backup product. Instead, it expects leadership to understand the risks facing the organization and take reasonable steps to reduce them. That’s where the other pieces come in.
Where the NCUA Fits In
The National Credit Union Administration is your regulator. Their responsibility isn’t simply to make sure your numbers add up. They’re also evaluating whether your technology, cybersecurity, and risk management practices support the long-term safety of your institution.
During an examination, they’re likely to ask questions such as:
- How are you protecting member information?
- How do you manage third-party technology vendors?
- What happens if ransomware affects your systems?
- Have you tested your disaster recovery plan?
- Who oversees cybersecurity at the executive level?
Notice something? They’re not just evaluating your technology. They’re evaluating your leadership. They want to know that someone is paying attention.
What About the FFIEC?
The Federal Financial Institutions Examination Council, or FFIEC, doesn’t create laws. Instead, it publishes guidance and best practices that regulators—including the NCUA—often use when evaluating financial institutions. Think of the FFIEC as the playbook.
It provides recommendations for areas such as:
- Cybersecurity governance
- Business continuity planning
- Authentication
- Vendor management
- Information security
- Incident response
Following this guidance helps demonstrate that your credit union is taking a thoughtful, risk-based approach to protecting members.
Here’s an Easy Way to Think About It
When someone asks me to explain these three organizations, I usually use this analogy. Imagine you’re building a new branch.
GLBA says:“You must build a safe building.”
The FFIEC says: “Here’s what safe buildings generally look like.”
The NCUA walks through the front door and asks: “Show us how you built yours—and why you made those decisions.” That’s obviously a simplified example. But it’s surprisingly accurate.
What Credit Union Leaders Should Be Focusing On
Here’s the good news. You don’t need to memorize every page of every regulation. You do need to make sure your organization is consistently managing a handful of critical areas.
Cybersecurity
Protect systems with layered security controls, monitor for threats, train employees, and respond quickly when incidents occur.
Business Continuity
Ensure your credit union can continue serving members during outages, cyberattacks, or disasters.
Vendor Management
Understand who has access to member information and verify that your technology partners meet appropriate security standards.
Risk Assessments
Regularly evaluate technology risks and document how leadership is addressing them.
Policies and Procedures
Good technology without documented processes creates unnecessary risk. Documentation matters.
Compliance Isn’t Just an IT Responsibility
One of the biggest misconceptions I encounter is that compliance belongs to the IT department. It doesn’t. Technology teams manage systems. Leadership manages risk. Board members provide governance. Compliance officers monitor requirements.Your MSP supports the process. Everyone has a role to play. The strongest organizations understand that cybersecurity and compliance are business responsibilities—not simply technical ones.
A Conversation I’ll Never Forget
Several years ago, I met with the board chair of a community credit union before an upcoming examination. He smiled and said, “Rusty, I don’t expect everything to be perfect. I just want to know we’re prepared.” That comment has stayed with me. Because that’s really what regulators want too. They’re not looking for perfection. They’re looking for evidence that leadership understands the risks, has a plan, and is continuously improving. Preparation builds confidence. And confidence changes the entire tone of an examination.
The Questions Every Credit Union Should Ask
If you’re wondering where your organization stands, start with these questions.
- Do we know where our sensitive member data resides?
- Have we completed a technology risk assessment within the last year?
- Are our disaster recovery procedures documented and tested?
- Do we regularly evaluate third-party technology vendors?
- Does our board receive meaningful cybersecurity updates?
- Could we confidently explain our security program during an NCUA examination?
If any of those questions make you pause, that’s not a reason to panic. It’s simply a good place to begin.
Final Thoughts
Compliance isn’t about checking boxes. It’s about protecting the trust your members place in your credit union every single day. The regulations may have different names. The guidance may come from different organizations. But the goal is always the same. Protect your members. Protect your employees. Protect your institution. When you approach compliance with that mindset, the regulations stop feeling like obstacles and start becoming a roadmap for building a stronger, more resilient credit union. And that’s exactly where every great technology partnership begins.
Recent Blog Posts...

NCUA vs. FFIEC vs. GLBA: Which IT Requirements Actually Apply to Your Credit Union?
Why Buying from a “One-Bullet Vendor” Can Cost Your Business More Than You Think

What Does a Business Continuity and Disaster Recovery Plan for an Ohio Credit Union Really Include?

How Much Does a TruLinx Cloud Migration Cost in 2026?

Why Your Business Doesn’t Need More Technology Vendors—It Needs a Technology Quarterback
- AI3
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud52
- Collaboration18
- Communication19
- Compliance4
- Contact Center1
- Credit Unions2
- Cyber Liability Insurance1
- Cybersecurity33
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure20
- Managed Network Services15
- Managed Services14
- Microsoft Teams2
- Network Performance29
- Network Security32
- News11
- Phishing1
- Press Release2
- Risk Assessment1
- security1
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx1
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

