Orange County's Credit Union is a federally chartered credit union that has been operating since 1938, serving more than 145,000 members across Orange, Los Angeles, Riverside, and San Bernardino counties. With over $3 billion in assets, it provides the full suite of financial services - deposit accounts, auto and home loans, credit cards, business banking, wealth management, and insurance. It's a member-owned institution, meaning profits cycle back to members through lower rates and fewer fees, which also means the attack surface is the membership itself: over a hundred thousand people trusting the institution with their financial lives.
For a cybersecurity professional, the threat model here is classic financial services: credential stuffing, account takeover, business email compromise targeting commercial banking clients, and regulatory pressure from NCUA and federal oversight. The perimeter isn't just the corporate network - it's the member-facing digital stack, the lending platforms, the wealth management interfaces, and every integration point with third-party insurers and loan processors. A credit union this size likely operates with a lean security team, which means broader ownership of domains rather than deep specialization.
The environment is one where the stakes are immediate - fraud losses hit the membership directly - and where a "people-first" culture means security decisions are filtered through the lens of member trust and usability. Community involvement is central to the mission, so the security posture needs to protect without creating friction that erodes that relationship. This is not a fintech chasing hypergrowth; it's a long-standing institution where operational resilience and regulatory compliance are the day job.






