Scammers can spoof Sound Credit Union’s phone number. Sound will never ask for your Online Banking username, password, verification codes or one-time passcode. If you receive a suspicious call, hang up and call us directly at 800.562.8130. When in doubt, hang up and call us.
Protecting Your Business: Cybersecurity FAQs
Explore our cybersecurity FAQs and learn easy ways to protect your accounts, data, and business.
Cybersecurity FAQs
Cyber threats are constantly evolving, but protecting yourself doesn’t have to be difficult. If you’ve ever wondered how to spot a phishing scam, create stronger passwords, or keep your business information secure, you’re not alone. To help make cybersecurity a little less intimidating, we’ve answered some of the most common questions we hear, so you can browse, bank, and do business online with greater peace of mind.
What Is Cybersecurity?
Just like you’d protect your home with house security (locks, gates, doors), cyber security protects your business from malicious (and accidental) attacks through your internet-connected networks, computers, mobile devices, software, and applications. These cyber security measures are designed to defend against attackers trying to access, destroy, or extort sensitive data, including customer information. Key cyber security measures include strong passwords, two-factor authentication, staff training, and disaster recovery plans.
What is a data breach?
A data breach is when an intruder gets unauthorized access to your information such as customer records and personal information, intellectual property, or company secrets. It’s often a PR nightmare having to inform the customers and suppliers that you, and maybe their data, has been stolen.
What is malware?
Malware is named from ‘malicious software’, where software has been installed on your computer or network without your knowledge and tries to disrupt your business. It could be executable code, computer viruses, worms, trojans, bots, spyware, ransomware, or other malicious programs. Malware is often picked up when installing or clicking on links you or an employee shouldn’t.
What is a phishing email?
Phishing is an email disguised as a trusted contact or source. Attackers try to get personal data such as passwords or bank/credit card numbers by hoping that you’ll click on fake links to sites or open attachments which install malware or direct you to pay an invoice or amount owed to a fake bank account.
What are business email compromise hacks?
Business email hacking involves someone gaining access to an employee’s business email account so they can pose as the employee, to then trick others into fraudulent wire transfers, gift card purchases, or other financial transactions. Often, the hack involves the attacker impersonating the business owner, but can include pretending to be a supplier requesting you use a new bank account for your latest purchase.
What is ransomware?
Ransomware occurs when you’ve mistakenly installed a rogue piece of software (from clicking on a link or opening an attachment), giving access and control of your systems to an attacker, who then demands money. If you don’t pay, usually by an untraceable currency such as Bitcoin, the attacker will delete your data, or lock your screens and deny you access.
What is scareware?
Scareware is similar to ransomware, as it aims to overwhelm you with persistent notifications, expose your online behavior (both real and fabricated), or intimidate you with potential consequences, such as a tax audit.
What is a denial of service?
This occurs when your computer or network crashes due to an overload of unwanted traffic or information. This attack denies you access to the internet and your data by consuming your device’s resources. Attackers often demand a ransom to stop their attacks, knowing the cost of downtime may outweigh the payment.
Do I need cyber insurance?
Cyber-risk insurance depends on your risk profile. If you have strong cybersecurity measures, staff awareness, and a solid recovery process, you may require less coverage. However, since connecting to the internet always exposes your business to potential hackers, cyber insurance can protect you from financial losses and claims resulting from your online activities.
How do I write a digital disaster plan?
Start by listing all internet-connected devices (servers, desktops, laptops, phones) and how you protect them (e.g., passwords, backups). Identify essential data and software, then detail your security measures (e.g., passwords, two-factor authentication, staff training) and your recovery plan if those measures fail. Finally, test the plan to ensure it works effectively.
What is two-factor authentication?
Two-factor authentication (or 2FA) is when you are asked for one more security step before getting access to what you have logged into. Typically, you receive a code via email or text that you must enter to confirm your identity. These codes are randomly generated, often valid for one use only, and usually expire quickly.
What is three-factor authentication?
Three-factor authentication (3FA) adds another layer of security by requiring three different types of verification:
- Knowledge, like a PIN or password;
- Possession, like a phone for a one-time password;
- Inherence, which is biometric data like a fingerprint or voice recognition.
How do I know I’ve been hacked?
It’s not always obvious, but some common hints you’ve been hacked include an inability to log in to an account, unknown programmer opening when starting your computer, pop-up windows, lots of spam emails, social media posts appearing that you didn’t write, or your computer isn’t performing as it usually does.
What’s the best way to back up my data?
There are several options. While copying files to a USB stick or external hard drive is simple, it may not be practical for large amounts of data. Cloud storage services like Google Drive and Dropbox are more for syncing than pure backups, especially for terabytes of data. Experts recommend the 3-2-1 rule, where you maintain three copies of your data, two local on different devices, and one off-site. This typically includes the original data on your computer, a backup on an external hard drive, and another on a cloud service.
Who can help me with practical cybersecurity advice?
If you have internal staff or an external IT provider, discuss your security with them. Otherwise we suggest checking out https://www.fbi.gov/investigate/cyber to access information on potential or real-time cyber-attacks. Use the Two Factor Directory to check what IT services use 2FA, which is a recommended pre-requisite for accessing critical data.
Who do I contact if I’ve been hacked?
Step one is to get it immediately fixed. Talk to your in-house or external IT support person. If you don’t have anyone, there are lots of consultants and IT support businesses you can call. Then report it to the FBI’s Internet Crime Complaint Center (or ‘IC3’) at https://www.ic3.gov/. Make sure you inform your staff, customers, and anyone else that supports your business (bank, accountant, business colleagues).

Charlene Homan
VP Risk Management & Compliance
Charlene Homan serves as the Vice President of Risk Management and Compliance at Sound Credit Union, where she leads compliance initiatives and oversees risk management strategies, including BSA compliance, fraud prevention, quality assurance, and enterprise risk management. With over 15 years in the credit union industry, Charlene has advanced from an entry-level position to her current leadership role, demonstrating comprehensive understanding of credit union landscape that supports Sound Credit Union’s values while ensuring a strong commitment to regulatory compliance and risk management.
As Sound’s appointed Compliance Officer, Charlene ensures adherence to all relevant laws and regulations while providing essential oversight on compliance issues, with the overarching goal of effectively serving members. She actively engages in professional development by attending key industry conferences and training programs. She is passionate about supporting her teams to create awareness to the membership and surrounding communities, with the intent to empower individuals to protect themselves from common scams and other fraud activities.



