In business continuity planning, preparedness is everything. Exercises and drills ensure that every team member understands their role in responding to different types of disruptions.
One of the biggest challenges credit unions face is determining who needs to be involved in these exercises. Should every employee participate, or just specific departments? Below, we break down key business continuity exercises – penetration testing, ransomware impact analysis, backup power testing, and tabletop exercises – and outline which departments and individuals should be involved in each.
Objective: Identify potential security weaknesses by simulating cyberattacks to assess your defenses.
Who should participate:
IT and Cybersecurity Teams: These teams are essential in both conducting and understanding the results of penetration testing. They will implement necessary changes based on vulnerabilities identified.
Risk Management: Representatives from this department should be involved to understand the cybersecurity risks identified and integrate them into the broader risk management framework.
Executive Leadership: While they may not participate in the technical aspects, executives – including the CEO and board – should be briefed on high-level results to understand the impact of potential vulnerabilities on the credit union.
Additional considerations:
Legal, Compliance, and BSA: Credit unions operate under NCUA and FFIEC guidelines, which include specific cybersecurity and exam expectations. These teams should review penetration test findings and recommended actions to ensure ongoing regulatory compliance.
Objective: Assess your credit union's vulnerability to ransomware and its potential operational impact.
Who should participate:
IT and Data Management: The IT team, specifically those responsible for data security and core system integrity, should lead the exercise. They'll play a vital role in managing backup systems and protecting member data.
Operations and Department Leaders: Since ransomware affects daily operations – including teller systems, loan processing, and online banking – key department heads need to understand how an attack could impact workflows and member service.
Finance: This team should be aware of the financial implications of a ransomware attack, including potential costs related to downtime, recovery, and regulatory penalties.
Communications/Marketing: In case of a breach, this team needs to know the protocols for communicating with members, regulators, and the public. Member trust is a defining asset for credit unions, and clear communication during an incident can significantly affect its outcome.
Additional considerations:
HR: HR may need to handle internal communications and support staff during recovery, especially if the attack disrupts normal work routines or requires remote operations.
Objective: Test backup power systems to maintain branch and back-office operations during a power outage.
Who should participate:
Facilities Management: This team handles the physical aspects of backup power systems and ensures they function correctly across branch locations.
Operations and Branch Teams: These teams must understand how a power outage affects workflows – from ATM availability to teller operations – and what alternative power sources mean for their daily responsibilities.
Safety Officers: Any testing involving physical systems should include safety officers to mitigate risks and ensure a safe testing environment.
Executive Leadership: Leaders should be informed about potential interruptions to operations and associated costs for better decision-making and budget allocation.
Additional considerations:
Vendors and Third-Party Providers: Credit unions rely on core processors and third-party fintech providers. If certain systems or services depend on those partners, it may be necessary to coordinate with vendors to ensure seamless continuity during a power event.
Objective: Simulate a wide range of emergency scenarios, such as active shooter situations, natural disasters, or data breaches, to test response protocols.
Who should participate:
Crisis Management Team: This core team should include representatives from operations, HR, legal, communications, and security. They will be responsible for managing the overall response.
Executives and Department Heads: These leaders need to understand the impact on their teams and be prepared to support staff through a disruption.
HR and Employee Relations: HR plays a critical role in supporting employees, handling internal communications, and arranging for any needed support or counseling.
Security and Facilities: These teams are especially important in exercises involving physical threats like active shooter situations. They should lead the way in designing and executing the exercise.
Local Law Enforcement or Emergency Services: For active shooter and certain emergency exercises, collaborating with local authorities is valuable. They can provide insights on best practices and help refine your credit union's approach.
Additional considerations:
All Employees: While not everyone needs to actively participate in every tabletop exercise, all staff should be informed of protocols and aware of any role they may need to play in a real emergency. This is especially relevant for frontline branch staff who are often first to encounter a disruption.
Every credit union is unique, and the involvement needed may vary depending on asset size, branch footprint, and operational risks. When planning business continuity exercises, consider these steps:
Identify Critical Functions: Which teams are essential to your core operations – member services, lending, payments, compliance? Those individuals should participate in exercises that could impact those functions.
Engage Leadership Early: Executives and the Board can offer support, allocate resources, and set the tone for a culture of preparedness across the organization.
Run Pre-Exercise Briefings: This step helps everyone understand the exercise's objective, their role, and why their participation matters.
Conduct Post-Exercise Reviews: After each exercise, gather feedback from participants to assess what went well and where there's room for improvement. Document findings – regulators may ask for them.
Choosing the right departments and individuals for business continuity exercises ensures that, in the face of an emergency, every part of your credit union is prepared to respond quickly and effectively. By engaging relevant teams in specific exercises, you build resilience, foster a culture of preparedness, and give your members and staff the best chance to weather any disruption.
Need guidance on running effective business continuity exercises? Connect with Agility Recovery to learn how we can help you prepare with a wide range of test types for any interruption scenario.