The Board’s Role in Cybersecurity: From Oversight to Ownership

By Jennifer Gunter

Historically, cybersecurity and operational resilience was something Directors typically delegated entirely to IT management. That model no longer works. Regulators have made that explicitly clear. 

NCUA’s updated examination framework holds boards directly accountable for cybersecurity oversight. Examiners are looking beyond technical controls to evaluate whether directors understand the risks, receive meaningful reporting, and are actively engaged in governance. The message is clear: cybersecurity is no longer an IT issue. It is a board-level responsibility.

The Board’s Responsibility Has Evolved

The board’s job is not to run the credit union’s cybersecurity program; that’s management’s work. But the board has a distinct and irreplaceable role: setting the tone at the top, approving the risk appetite, demanding credible reporting, and making sure the institution is investing appropriately in its cybersecurity defenses.

NCUA’s examination framework has raised the bar on board oversight: it’s no longer just about whether your technical controls are in place. Boards are now expected to stay actively informed on the threat landscape, how well your incident response plan holds up in testing, where your third-party vendors stand on security, and whether your cyber insurance coverage actually matches your real-world exposure.

Meeting that standard requires a deliberate governance structure. If a risk committee exists, cybersecurity oversight should be a standing responsibility, including regular review of management reports, tracking remediation efforts, and escalating material risks to the full board. If there is no risk committee, cybersecurity should be a regular item on the full board agenda, with structured management reporting at least quarterly.

Not Gotcha Questions

NCUA examiners are now sitting down with board members directly and asking: When did you last receive a cybersecurity briefing? What metrics does management report to the board? How does the board know the credit union is adequately protected?

These are not gotcha questions. They’re the baseline for what an effective cybersecurity governance looks like in 2026. Boards that cannot answer them clearly have a governance gap, not an IT problem.

What the Board Should Be Monitoring

Boards should receive regular, substantive reports from management in four key areas, each tied to a different aspect of the credit union’s risk profile.

  • The threat landscape. Attacks on credit unions are constantly evolving. AI-generated phishing emails are difficult for employees to identify, and voice cloning is used to impersonate executives and authorize fraudulent transfers. Boards do not need detailed technical briefings, but should receive plain-language summaries of relevant threats and management’s proactive responses.
  • Incident response readiness. Having an incident response plan is the baseline; effectiveness depends on regular testing. Directors should receive an annual report from management covering the most recent tabletop exercise, key findings, and resulting changes. If management cannot answer these questions, there is a governance gap.
  • Third Party Relationships. Vendor dependency exposes the credit union to direct risk. The board should know which vendors have access to critical systems or member data, how those vendors are assessed for security risk, and what contractual protections exist in the event of a breach. A compromise at your core processor is effectively a compromise at your institution.
  • Cyber insurance alignment. Cyber insurance is now standard for risk transfer, but coverage varies widely. Boards should annually confirm that policies reflect the credit union’s current size, operations, and risk profile.

What’s Actually at Risk

Historically, cybersecurity has been viewed as a technical problem or a compliance checkbox. Today it is neither. It is a business continuity problem, a member trust problem, and increasingly, a financial viability problem.

A significant breach can shut down credit union operations for days, trigger regulatory scrutiny, generate litigation exposure, and/or permanently damage the relationship members have with an institution they have trusted with their financial lives. The reputational cost — particularly if the investigation reveals that the board was not paying attention — can outlast the operational disruption by years.

Boards that are actively engaged in cybersecurity governance are not just checking a regulatory box. They are protecting the credit union’s ability to serve its members for the long term.

The Bottom Line

NCUA is watching how boards oversee the institution’s cybersecurity risk, not just how IT teams manage it. That is a meaningful shift, and it calls for a meaningful response. Strong board oversight means understanding the credit union’s exposure, demanding credible and regular reporting, insisting that plans get tested, and making sure the institution is adequately protected and insured.

This is the essence of governance. The credit unions that will navigate the next wave of threats most 

Jennifer Gunter is Senior Strategy, Risk & Assurance Consultant with Rochdale.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.