The hardest question a credit union board asks its security team is also the shortest: "Are we secure?" For years, the most honest answer has been "probably." And as both speakers in this CUInsight session made clear, the distance between "probably" and "we can prove it" is exactly where attackers operate, and closing it is now a business decision, not a technical one.
Greg Schaeffer, President of vCISO Services, traced his own turning point to the 2024 Patelco Credit Union ransomware incident, which took the core down and put one question in front of every board: are we exposed to the same thing? His team shored up its control inventory and ran a ransomware tabletop, then walked away with more questions than answers. The best they could say was, "We think this would have blocked it."
That story is not an outlier.
Alper Memis, co-founder and CEO of Picus Security, noted that more than 1,000 cyber incidents were reported to the NCUA last year, roughly one in four credit unions, and that around half of financial-services ransomware victims never identify the root cause. These weren't organizations that neglected security. They had tools. They passed audits.
The gap was the assumption that the defenses would hold.
The credit union disadvantage: Rabbits and turtles
Credit unions answer to the same regulators and face the same sophisticated threat actors as the largest banks, but without the resources.
A firm like JPMorgan can spend hundreds of millions a year and field thousands of security staff; a typical credit union runs on a two- or three-person team (sometimes fewer). Attackers don't care about that asymmetry; they go for the lowest-hanging fruit.
Memis framed it as a rabbit-and-turtle problem. The average attacker breakout time is about 29 minutes, and the fastest observed intrusions move from initial access to data theft in under 30 seconds. Defenders, by contrast, can't shed their shell: the board, the NCUA examiner, the CFO, and the change-control process all come with them. AI is the accelerant widening that gap, which is precisely why exposure validation has become urgent. And buying tool number 77 (financial firms already run about 76 on average) doesn't close it.
Security validation is the practice of continuously testing your real defenses against real attacker techniques, in your own environment, to prove what they actually stop, then turning every finding into a defensible decision: patch, mitigate, monitor, or accept. It runs as a loop: validate, decide, fix, re-validate.
The word both speakers kept returning to was evidence.
A summary report that says "we're probably fine" doesn't survive an auditor, an examiner, or a board, so it shouldn't satisfy a CISO either. And evidence only means something in context.
- A "critical" 9.9-rated vulnerability may not be exploitable in your environment because a control already blocks it, or the asset has no path to production.
- Meanwhile, a routine 6.5 sitting at a critical junction in your loan-origination system, where nothing is blocking it, can be the real risk.
Severity scores can't tell you that; validated, context-aware evidence can.
Both, the speakers stressed, are complementary, not competitors. An annual penetration test is a focused, point-in-time snapshot; continuous validation keeps proving the answer as your environment drifts. Trust, but verify.
Likewise, your EDR is the car; validation is the assurance layer, because a single exclusion broadened to silence a false positive can quietly let real threats through.
For the inevitable "won't running attacks break production?" concern, Memis explained that simulations run between Picus's own agents inside a controlled digital mirror of your controls, not against live production assets. And autonomy is tunable: teams keep a human in the loop, preserve a chain of custody for the evidence, and dial up automation only as trust builds.
Start small, with what matters most.
For most credit unions, that's ransomware: validate your defenses against active ransomware techniques and see exactly where you stand. The key, Memis added, is not to drown a stretched team in gaps. Pair every finding with an actionable mitigation, then watch the baseline improve over time.
That reframes the boardroom conversation. Instead of "we assume we're covered," you can say: "We continuously test the controls protecting the core, and we can show with evidence that our exposure to a core-down event is low." As Greg put it, it's not enough to tell the what; you have to tell the so what.
The shift is simple to state and hard to live: move from assumption to evidence. Watch the full CUInsight and Picus webinar, "A Credit Union's Playbook for Proving Security Effectiveness," for the complete conversation, including the board, budget, and audit plays.
See exactly which ransomware techniques your controls stop today, and what it takes to close the gaps that matter. You can grab your consulting call from here.
