I was sitting in a board meeting once when a director asked me a question I wish more people would ask.
“Rusty, how much of this cybersecurity stuff do we actually need to understand?”
It was a good question.
Because the board had just listened to a presentation filled with acronyms.
Firewalls.
MFA.
EDR.
MDR.
SIEM.
By the time it was over, everybody had heard a lot of information.
I’m not sure anybody felt more confident.
So I told him something I’ve repeated many times since.
You don’t need to become a cybersecurity expert.
But you do need to understand the risks well enough to ask good questions.
That’s the board’s job.
Your IT team manages technology.
Your cybersecurity providers monitor systems.
Your compliance team helps interpret requirements.
But leadership and the board provide oversight.
And when member trust is on the line, cybersecurity belongs in the boardroom.
Cybersecurity Is a Business Risk
One of the biggest mistakes organizations make is treating cybersecurity like an IT department issue.
It isn’t.
A cybersecurity incident can affect:
- Member service
- Financial performance
- Operations
- Reputation
- Employee productivity
- Regulatory relationships
- Business continuity
That’s why the board conversation shouldn’t begin with:
“Which antivirus product are we using?”
It should begin with:
“What could prevent us from serving our members tomorrow morning?”
That’s a business question.
And it’s a much better place to start.
Board Members Don’t Need More Acronyms
Technology people sometimes forget how quickly technical language becomes overwhelming.
If someone tells you your EDR integrates with your MDR while your SIEM monitors the SOC…
You may smile and nod.
That doesn’t mean you understand whether the credit union is protected.
Good cybersecurity reporting should translate technical information into business language.
Instead of:
“We detected 742 endpoint alerts this month.”
Leadership needs context.
Were any of them serious?
What did we do about them?
Are we getting safer?
Where are the gaps?
The board doesn’t need more data.
It needs useful information.
Start With These Five Areas
If I were sitting with your board today, I would organize the cybersecurity conversation around five areas.
1. What Are Our Biggest Risks?
Every credit union has risks.
The goal isn’t to eliminate all of them.
That’s impossible.
The goal is to understand them.
Leadership should know which risks have the greatest potential to disrupt operations or harm members.
That might include:
- Phishing
- Ransomware
- Credential theft
- Aging technology
- Third-party vendors
- Employee mistakes
- Business continuity gaps
The board doesn’t need to manage each issue.
But it should understand which risks leadership is prioritizing and why.
2. How Are We Protecting Member Information?
This is where the conversation becomes very real.
Members trust your credit union with some of the most sensitive information they have.
The board should have confidence that appropriate safeguards are in place around that information.
Ask:
- Who can access sensitive data?
- How is access controlled?
- Are employees using multi-factor authentication where appropriate?
- How do we remove access when someone leaves?
- Are our vendors protecting information appropriately?
- Do we know where critical data is stored?
Those are not overly technical questions.
They’re governance questions.
3. What Happens If Something Gets Through?
No security program is perfect.
That’s why cybersecurity isn’t only about prevention.
It’s also about response.
Ask your leadership team:
“If ransomware affected us tomorrow morning, what happens during the first few hours?”
Who gets called?
Who makes decisions?
How are affected systems isolated?
How do we communicate with employees?
How do we continue serving members?
When was the plan last reviewed?
Preparation matters.
A calm response rarely happens by accident.
4. Can We Recover?
I’ve said this in other conversations, and it’s worth repeating.
A backup is not the same thing as recovery.
A credit union can have backup software running every day and still discover during an emergency that recovery takes longer than expected.
The board doesn’t need to understand the technical details of backup architecture.
It should understand whether recovery has been tested.
Ask:
- Are critical systems backed up?
- Have we tested restores?
- How quickly could essential services return?
- Which systems get restored first?
- What happens if our primary location is unavailable?
Those answers tell you far more than a green checkmark on a dashboard.
5. Are Our People Prepared?
Technology gets a lot of attention in cybersecurity.
People deserve just as much.
Employees are often the first line of defense.
A good training program helps people recognize suspicious emails, fraudulent requests, and social engineering attempts.
The board should ask:
- Are employees receiving ongoing cybersecurity training?
- Are we reinforcing lessons throughout the year?
- Do people know how to report something suspicious?
- Are leadership and board members included in appropriate awareness efforts?
Cybersecurity culture starts at the top.
Employees pay attention to what leadership takes seriously.
What Should a Cybersecurity Report to the Board Include?
This is where many organizations struggle.
They either provide too little information…
Or far too much.
A good board-level cybersecurity report should be simple enough to understand and detailed enough to support decisions.
I would focus on a small number of areas.
Current Risk
What are the most important cybersecurity risks facing the organization today?
Progress
What improvements have been completed since the last report?
Incidents
Were there any meaningful cybersecurity events?
If so, what happened and what did we learn?
Training
Are employees completing cybersecurity awareness activities?
Vulnerabilities
Are there significant weaknesses that leadership needs to address?
Business Continuity
When was recovery last tested, and what was learned?
Upcoming Decisions
Are there investments, projects, or policy decisions the board needs to understand?
That’s enough information to create a productive conversation without turning the meeting into an IT class.
Don’t Let a Green Dashboard Create False Confidence
One thing that concerns me is when cybersecurity reporting becomes a collection of green boxes.
Backup: Green.
Antivirus: Green.
Firewall: Green.
Training: Green.
Everything looks good.
Until it doesn’t.
Good cybersecurity oversight isn’t about asking whether tools are installed.
It’s about asking whether the overall program is working.
A green dashboard should start the conversation.
Not end it.
Ask About Vendors Too
Credit unions depend on technology partners.
Core providers.
Cloud platforms.
Fintechs.
Internet providers.
Managed service providers.
Cybersecurity firms.
Every one of those relationships affects your technology environment.
Boards should understand how leadership evaluates critical vendors.
Ask:
- Which vendors have access to sensitive systems?
- How do we review those vendors?
- Who owns each relationship?
- What happens if a critical vendor suffers an outage or security incident?
- Are vendor responsibilities documented?
You may outsource services.
You don’t outsource responsibility for oversight.
Cybersecurity and Business Continuity Belong Together
Sometimes cybersecurity is discussed separately from disaster recovery.
I don’t think that makes much sense anymore.
A cyberattack can become a business continuity event very quickly.
If systems are unavailable, members don’t care whether the cause was ransomware, a failed server, or a storm.
They care whether the credit union can serve them.
That’s why every board should understand how cybersecurity, incident response, backup, and business continuity fit together.
They’re different pieces of the same resilience strategy.
What About Artificial Intelligence?
This is becoming another board-level conversation.
Employees may already be experimenting with AI tools.
Software vendors are adding AI features.
Cybersecurity platforms increasingly incorporate AI capabilities.
That doesn’t mean the board needs to understand how the technology works.
It does mean leadership should have a plan for how it’s being used.
Ask:
- Are employees using AI tools?
- Do we have guidelines?
- Could sensitive information be entered into unapproved systems?
- Are vendors introducing AI into products we already use?
- Who reviews new AI-related risks?
AI is another example of why cybersecurity governance can’t be a once-a-year discussion.
Technology changes too quickly.
A Conversation Every Board Should Have
Years ago, I watched a board chair do something very smart.
After listening to a lengthy cybersecurity presentation, he closed the report and asked:
“What are the three things you want us to worry about?”
The technology team paused.
Then the conversation changed.
Instead of talking about dozens of tools and metrics, they discussed the organization’s three biggest risks.
What leadership was doing about them.
Where additional investment was needed.
What the board could do to help.
That was one of the most productive cybersecurity conversations I’ve ever watched.
Because the board wasn’t trying to manage technology.
It was governing risk.
10 Questions Every Credit Union Board Should Ask About Cybersecurity
If you’re not sure where to begin, start here.
1. What are our three biggest cybersecurity risks right now?
Make the team prioritize.
2. What has changed since our last cybersecurity report?
Risk doesn’t stand still.
3. Are we seeing meaningful security incidents?
Understand what happened and what was learned.
4. When did we last complete a cybersecurity risk assessment?
Know what was identified and what has been addressed.
5. When did we last test our recovery plan?
Preparation should be proven, not assumed.
6. Are our employees receiving ongoing cybersecurity training?
People matter.
7. Which third-party vendors create our greatest technology risk?
Understand dependency.
8. Are there significant technology investments we need to plan for?
Cybersecurity should be part of budgeting.
9. How are we preparing for new technologies such as AI?
Governance should evolve with technology.
10. If a serious incident happened tomorrow, are we confident in our plan?
That’s the question that ties everything together.
What the Board Should Not Do
There’s another side to this conversation.
Boards shouldn’t become the IT department.
You don’t need to select firewalls.
You don’t need to compare security software.
You don’t need to diagnose vulnerabilities.
That’s not good governance either.
The board’s role is to:
- Ask questions
- Understand material risks
- Ensure accountability
- Support appropriate investment
- Monitor progress
- Challenge assumptions
- Help leadership prepare
Good oversight creates clarity.
Micromanagement creates confusion.
Final Thoughts
Cybersecurity can feel intimidating.
Especially when every conversation introduces another acronym, another threat, or another technology.
But the fundamentals are much simpler.
Know your risks.
Protect member information.
Train your people.
Prepare for incidents.
Test your recovery.
Manage your vendors.
Keep improving.
That’s what the board needs to understand.
You don’t have to know how every cybersecurity tool works.
You simply need enough visibility to ask:
“Are we protecting the people who trust us?”
After more than 26 years in technology, I’ve come to believe that’s the most important cybersecurity question any leadership team can ask.
Because cybersecurity isn’t really about protecting computers.
It’s about protecting confidence.
The confidence your employees have in the systems they use.
The confidence your board has in leadership.
And most importantly…
The confidence your members have in you.
Give Your Board Clearer Answers About Cybersecurity
Cybersecurity conversations shouldn’t leave your leadership team more confused than when they started.
At CTG, we help credit unions turn complicated technology issues into practical business conversations. Our goal is to give executives and board members clearer visibility into cybersecurity risk, business continuity, technology planning, vendor management, and the investments needed to strengthen the organization over time.
For more than 26 years, CTG has helped organizations navigate technology decisions, supported by a team with more than 200 years of combined experience.
Whether you’re preparing for your next board meeting, reviewing your cybersecurity program, planning next year’s technology budget, evaluating AI, or simply trying to understand where your greatest risks are, we’ll help you build a clear path forward.
Talk with CTG
Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net
Let’s make your next cybersecurity conversation less about acronyms—and more about confidence, preparation, and protecting the members who trust you.
Recent Blog Posts...
What Every Ohio Credit Union Board Should Know About Cybersecurity
How Should an Ohio Credit Union Prepare for a Cyber Insurance Renewal?
The AI Receptionist for Legal Practices: Automating Client Intake Without Losing the Human Touch
Artificial Intelligence for Ohio Credit Unions: Where Should You Start?
Breach Readiness: The Cybersecurity Checkup Every Growing Business Should Consider
- AI6
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud58
- Collaboration18
- Communication20
- Compliance4
- Contact Center1
- Credit Unions11
- Cyber Liability Insurance2
- Cybersecurity37
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure26
- Managed Network Services20
- Managed Services19
- Microsoft Teams2
- Network Performance29
- Network Security34
- News11
- Phishing1
- Press Release2
- Risk Assessment3
- security1
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx7
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

