I spent more than two decades in financial services sitting in the chair that every credit union technology leader knows too well—the one where you're simultaneously the innovation champion, the risk officer, the budget defender, and the person examiners call first when something goes wrong. I wore the CIO hat and the CISO hat, sometimes on the same day, sometimes in the same meeting. And if there's one thing I learned in that seat, it's this: credit unions don't lose to big banks because our people care less or our members trust us less. We lose ground because we're often forced to make technology decisions with a fraction of the budget, a fraction of the talent pool, and none of the room for error that our balance sheets allow.
I'm writing this not to sell you anything, but because looking back on my career, I wish I'd had a vendor that provided the kind of partnership I needed. I think about the fires I fought, the vendors I regretted, and the strategic partner I never quite found. This is my attempt to unpack what CIOs and CISOs in this space are up against today, in the hope that it's useful to whoever is sitting in that seat right now.
The job nobody outside IT fully understands
When you're the CIO of a credit union with a few hundred million to several billions in assets, you're not running a Fortune 500 IT shop. You're running a lean team, sometimes just a handful of people that must do everything a bank three times your size does: core system management, network operations, cybersecurity, disaster recovery, vendor management, regulatory compliance, and increasingly, cloud strategy. And you must do it while an NCUA or state examiner is reviewing your risk assessments, your board is asking why the technology budget keeps climbing, and your fraud team is asking why it isn't climbing faster.
What I needed, more than any single tool or platform, was a partner who had sat where I sat. Not a vendor selling me a project. Not a consultant who parachutes in for a scoping engagement and leaves before the go-live date. Someone who understood that when I asked about recovery time objectives, I wasn't asking academically. I was thinking about the Tuesday morning when our members can't access online banking, and my phone won't stop ringing. That kind of understanding doesn't come from a sales deck. It comes from having lived it. Too many of the vendors I worked with over the years had never actually operated inside a financial institution, they'd sold to one but never carried the pager. Yes, I said pager, Did I say I have been in IT for a very long time?
Budget: The constraint that shapes everything else
Every technology decision I made was really a budget decision wearing a different hat. Credit unions operate on thin margins compared to banks, and technology has to compete for capital against loan growth initiatives, branch investments, and member service programs that board members can see and touch. Meanwhile, the cost of doing IT well has exploded.
Here's the shift that I think a lot of boards still don't fully appreciate: the traditional IT generalist who could rack a server, manage a firewall, and troubleshoot a switch is being replaced by a very different, and very expensive, skill set. Cloud engineers, FinOps specialists, and security architects who understand hybrid and multi-cloud environments command salaries that most credit unions in the $1 million to $5 billion range simply cannot justify for one or two headcount. You can't hire a fractional cloud architect. You either pay for a full-time senior engineer at a premium salary with a competitive benefits package and a retention risk that keeps you up at night, or you make do with a team that's stretched too thin to modernize while keeping the lights on.
That's the gap I felt most acutely, not a lack of ambition or vision, but a lack of access to the specialized talent needed to execute on it, at a price a credit union's budget could actually absorb.
Paying upfront for something that might not work
If there's one thing that used to keep me up at night more than staffing and of course disaster recovery, it was the procurement risk. Traditional cloud migrations and MSP engagements almost always started the same way: a statement of work, a professional services fee, a multi-month scoping and implementation charge all paid before you knew whether the outcome would actually match what was promised. I signed contracts where the "assessment" alone cost six figures, and I still had no guarantee the eventual environment would perform, scale, or secure the way it was pitched.
That's an enormous amount of risk to ask a credit union to absorb, especially when every dollar spent on a failed initiative is a dollar that isn't going toward loan growth, member rates, or the next branch. As a former CIO who had to defend budget line items to a board and a supervisory committee, I would have given a great deal for a partner who let me see a working solution built and proven before I had to commit to a long-term contract or write a check for services that might not pan out. An outcome-based structure where you pay for results rather than hours and promises would have changed how confidently I could bring a modernization plan forward.
Security and compliance aren't a feature—they're the job
As a CISO, I never had the luxury of treating security as a project with a start and end date. Frameworks like FFIEC, GLBA, PCI, and SOC 2 aren't boxes you check once; they're a continuous posture you have to prove, document, and defend to examiners year after year. Ransomware protection, immutable backups, real recovery point and recovery time objectives aren't nice-to-haves for a credit union, they're existential. I've lived through the tabletop exercises that expose how fragile a homegrown disaster recovery plan really is when you finally stress-test it.
A security first architecture with real audit trails, automated vulnerability management, and disaster recovery built around actual RPO/RTO commitments rather than a binder on a shelf is what I wanted every time I sat across from an examiner. That's the kind of built-in accountability that changes the conversation from "we hope this works" to "here's how we've proven it works."
Why this matters for every CU
I want to be clear about why I'm writing this. Credit unions are in a genuine bind. We're expected to compete with banks that have technology budgets and staffing levels we'll never match, while also preserving the member-first, community-rooted identity that makes us different. The only way to close that gap is to stop trying to build everything in-house and start being honest about where a strategic partner, one who has actually worn the CIO and CISO hats, can carry weight we can no longer carry alone.
Every CU technology leader should be asking the same three questions before their next cloud or security initiative: Does this partner understand my seat, not just my sector? Am I being asked to pay upfront for an outcome I can't yet, see? And is my security posture something I can prove to an examiner, or something I'm hoping holds up?
Those are the questions I wish I'd had better answers to years ago. Looking back, I believe having the right kind of partner earlier in my career would have changed how confidently I could have modernized, and how much less risk I would have carried on my own shoulders and my boards.
A note on why I'm sharing this now
I'm sharing these reflections now because I work at Veritium as a fractional CIO for credit unions across the country and a customer success manager for our credit union MSP clients. Veritium is a cloud managed services provider built around many of the things I just described: a team of people who've operated inside financial institutions, an outcomes-based model with no upfront professional services fees, and a security posture built for the audit, not just the sale. I'm not writing this to pitch you. I'll leave that conversation for another time, if you're ever curious. I wrote this because the challenges I've described are real and they're shared by nearly every CU technology leader I know.
Please visit our website at www.veritium.com and/or email me for more of my insight at mmcgovern@veritium.com.
The author has led IT and IS teams and has held the role of CIO and CISO during more than two decades in financial services. These are his own words and opinions.