Your vendors have keys to your credit union. When did you last check who else does?
Those two questions cover the two doors attackers actually use most. Not the firewall. A vendor with live credentials into your systems whose own security you have never verified. An account that belonged to someone who left eight months ago and still works. Nobody breaks in through those doors. They sign in.
This guide covers both: what credit union vendor risk management actually requires, how an employee access review works in practice, and how a cybersecurity gap assessment ties it all together so you know what to fix first.
Door One: Credit Union Vendor Risk Management
Every credit union runs on vendors. Core processor, online banking platform, card services, IT support, the HVAC company with a portal login. Every one of them is access, and access is risk you have inherited whether you documented it or not.
When we wrote about what to do when a vendor has a cyber incident, the starting point was the uncomfortable part: most community banks and Montana credit unions do not have a documented answer to “what could that vendor reach?” until an examiner asks for one.
Vendor risk management is the discipline of having that answer before anyone asks. In practice, it starts with three questions, asked of every vendor with access:
- What can you access in our systems, exactly?
- How is that access secured on your side?
- What happens to it when your people leave?
A vendor who cannot answer in plain language has answered. Write the responses down. That record is both the vendor due diligence your examiners expect and your map of which doors exist.
Door Two: The Employee Access Review
The second door is internal: accounts that outlive the people and roles they were created for. A teller moves to lending and keeps teller permissions. A contractor’s project ends and the login does not. Someone leaves, email gets closed, and the four other systems they could reach do not.
A credit union employee access review closes this door, and it takes one afternoon per quarter:
- Pull the full user list. Every system, not just email: core, online banking admin, remote access, third-party portals.
- Match it against payroll. Any account that does not match a current employee gets disabled today. Not reviewed. Disabled.
- Match access to roles. Permissions should follow the job someone has, not every job they have ever had.
- Put it on the calendar. Thirty minutes, every quarter, with a named owner.
In our work with credit unions, wrong or stale access is among the most common findings there is. It is also the cheapest to fix.
Why Good Credit Unions Still Have These Gaps
Neither door stays open because anyone is careless. They stay open because checking them is nobody’s job. Vendor access sits between IT and whoever signed the contract. Employee access sits between IT and HR. Each assumes the other has it.
This is what security policy development actually fixes. Not a binder, a page: who runs the access review, who owns vendor due diligence, how often, and where the evidence lives. Examiners ask for the policy before they ask for the proof, and a one-page policy with a named owner beats a thick one nobody follows.
Gap Assessment vs. Vulnerability Assessment
The terms get used interchangeably. They do different jobs.
A credit union vulnerability assessment is technical: it scans your systems for known weaknesses such as unpatched software, exposed services, and misconfigurations. Ongoing vulnerability management services keep that scanning and remediation running continuously instead of once a year.
A cybersecurity gap assessment is wider. It measures your whole program against what your risk and your examiners actually require. The difference in one example: a scan finds the unpatched server. A gap assessment finds that nobody owns patching.
| Vulnerability assessment | Gap assessment | |
| Looks at | Your systems | Your whole program: systems, people, policies |
| Finds | The unpatched server | That nobody owns patching |
| Output | A list of technical weaknesses | Gaps ranked by business risk, in priority order |
| Cadence | Continuous, through vulnerability management services | First, then periodically |
You will eventually want both. The gap assessment comes first, because it tells you where vulnerability work belongs in the priority order, and whether a more basic door is standing open. The two doors in this guide live in one of its five areas, access. The assessment covers the other four as well: backups, alerts, patching, and response.
The SecurityStack Challenge is that gap assessment in its simplest form: one 30-minute conversation that scores your credit union across five areas and ranks the gaps by business risk.
Where to Start This Quarter
- Run the access review this week. One afternoon. Disable what does not match payroll.
- Send the three vendor questions to your five highest-access vendors.
- Write the one-page policy naming who owns each check and how often it happens.
- Get scored. Thirty minutes for a ranked view of every gap, so the next quarter’s work is chosen by risk instead of by guesswork.
None of this needs a budget approval. It needs a decision that the doors get checked.
FAQ
What is a cybersecurity gap assessment?
A structured review that measures your security program against your actual risk and regulatory expectations: backups, access, monitoring, patching, policies, and response. The output is a list of gaps ranked by business impact, with a recommended order to close them.
How often should a credit union review employee access?
Quarterly is the practical standard: a 30-minute review matching every account against current staff and current roles, with departures disabled immediately rather than at the next review.
What is vendor risk management for a credit union?
Knowing, in writing, what every vendor can access in your systems, how that access is secured, and what happens to it when their staff change, before an incident or an examiner forces the question.
What is the difference between a gap assessment and a vulnerability assessment?
A vulnerability assessment scans systems for technical weaknesses. A gap assessment reviews the whole program, people and policies included, and tells you which gaps matter most. Run the gap assessment first; it sets the priority order for everything else.
Get Your Security Score
Don’t wait for the breach, or the exam, to find out which doors are open. The SecurityStack Challenge is one 30-minute conversation that scores your credit union across five areas: backups, access, alerts, patching, and response. You leave with your gaps ranked by risk and a clear answer on what to fix first. No pitch, no prep, no technical overwhelm. It is the same first step we take as the Montana Credit Union Network’s approved IT service provider, and it works whatever you decide to do with it.


