Third Level IT

HomeIndustriesFinancial Institutions

The examiner left a list. I close it.

Audit remediation for credit unions and community financial institutions — NCUA examination findings, GLBA safeguards, and FFIEC-aligned infrastructure, delivered with the evidence your examiner will ask for.

  • NCUA
  • GLBA Safeguards Rule
  • FFIEC CAT
  • NIST CSF
  • SOC 2 readiness
The situation

A finding is a deadline with your name on it.

Examination findings land on the CEO and the board, not the IT vendor who let the gaps accumulate. A Document of Resolution or a repeat finding changes the tone of every conversation with your regulator.

The usual response — asking the incumbent MSP to fix what it built — produces the usual result. The findings that show up in credit union exams are infrastructure problems: flat networks, shared administrator credentials, logging that exists but is never reviewed, backups nobody has tested against ransomware, vendor access nobody inventoried.

Those are engineering deficits. They don't get fixed with a policy binder.

What I do

From findings letter to evidence file.

  • Finding-by-finding remediationEach examination finding mapped to its root cause, remediated, and documented with configurations, logs, and change records — the artifacts examiners actually accept.
  • Information security programGLBA safeguards implemented in the infrastructure, not just described in policy: encryption, MFA, access reviews, and monitoring that matches what the program document claims.
  • Network segmentationSeparation of member-facing systems, core processing connections, and back-office networks behind FortiGate next-generation firewalls.
  • Logging & monitoringWazuh SIEM deployment with retention and alerting aligned to FFIEC expectations, plus reporting your ISO or committee can present.
  • Vendor & remote access controlInventory and lockdown of third-party access — core processor, ATM vendor, MSP — with MFA and session logging.
  • Independent assessmentPre-exam security assessments with findings backed by device output, so you see what the examiner will see, first.
Why it works

One accountable engineer, not a rotating bench.

Credit unions in the 20–500 employee range sit in an awkward spot: large enough for full-scope exams, too small for a security team. I fill that gap directly — fifteen years of enterprise network engineering, applied to your examination cycle.

For institutions that want continuity after remediation, a fractional CTO retainer keeps someone accountable for the exam response year-round.

About the fractional CTO practice

The follow-up exam is the one that matters. Walk in with an evidence file, not a promise.

Nate HowardFounder & Principal Engineer

Holding a findings letter right now?

Send it over. I'll give you a straight read on scope and sequence before you commit to anything.