On July 15, 2026, TruStage, an insurance provider sold through credit unions across the country, disclosed a cybersecurity incident and did something that deserves more credit than it will get. It shut its own network down.

As of this writing, twelve days after detection, the company is still restoring systems in a controlled, prioritized sequence. Most products are operational again, with manual workarounds carrying some claims processes. Investigators now believe the intrusion began when an employee inadvertently downloaded a malicious file while trying to install a legitimate software tool.

Hold on to that last sentence. We will come back to it, because it describes something that happens in small businesses every single week.

First, I want to separate two things that get blurred every time a story like this runs, because the useful lesson is in the second one.

The shutdown was probably the right call

When you find an intruder in your environment, containment competes directly with availability. Staying up preserves revenue and customer service. Going down stops the spread. Choosing to go down means absorbing enormous, visible, immediate cost in exchange for preventing damage nobody will ever be able to measure, because it did not happen.

That is a hard decision to make at speed, and it is the decision most incident response plans describe in theory and few organizations execute in practice. Whatever the investigation eventually finds, that specific choice reflects a team doing the unglamorous, correct thing.

The customers who lost service did nothing wrong

This is the part worth studying.

The credit unions that sold these insurance products did not get breached. Their own security did not fail. Their members still could not file certain claims, because the service was delivered by somebody else, and that somebody else went dark.

That is third-party risk in one sentence. Your security posture is not only your own. It extends to every organization that holds your data or delivers a function you depend on, and you inherit their bad days whether or not you had any say in their controls.

Small businesses tend to hear third-party risk management and file it under enterprise vocabulary. It is not. If you are a five-person dental practice, your practice management software vendor going offline for twelve days is an existential event, not an inconvenience. If you are a defense supplier, a managed service provider outage can freeze the systems your contract obligations depend on.

The root cause is the most ordinary thing imaginable

An employee tried to install a legitimate software tool and got a poisoned version instead. No zero-day, no nation-state tradecraft in the opening move. A download that looked right and was not.

Every small business has this exposure, every day, because every small business installs software. Two controls shrink it dramatically. First, software comes only from the publisher's own site or a managed catalog, never from a search result or an ad, because attackers buy search ads against popular tool names precisely to catch people mid-install. Second, on business machines, standard users do not hold administrator rights, so one wrong download cannot quietly become one compromised network.

Three questions worth answering before you need the answers

1. Which vendors, if they disappeared for two weeks, would stop you from operating or from serving customers? Write the list. Most owners have never written it, and it is usually shorter and more alarming than expected.

2. For each one on that list, what is the manual fallback? Not a good fallback. Any fallback. Paper forms, a phone number, a second provider, an exported copy of your own data held somewhere you control. The goal is to convert a full stop into a slowdown.

3. What does your contract actually say about notification? Not whether the vendor promises to be secure, because they all do. Specifically: how fast do they have to tell you when something happens, and what are they obligated to tell you.

The disclosure gap is where trust erodes

Twelve days in, there has been no statement about whether personal information was accessed. Investigations genuinely take time, and responsible organizations refuse to guess in public. Both of those things are true.

But silence has a cost that compounds. Customers who do not know whether their data is involved cannot decide whether to freeze credit, watch accounts, or simply stop worrying. And the vacuum gets filled, reliably, by criminals sending breach-themed phishing to the exact population that is anxious and waiting for a message.

The lesson for the rest of us is not to criticize a company mid-incident with incomplete information. It is that incident response planning does not end at containment. Most plans I read stop at the technical steps and treat communication as an afterthought. Decide now who speaks, to whom, how quickly, and what gets said when the honest answer is still that you do not know yet. That last message is the hardest one to write under pressure and the most valuable one to have drafted in advance.

Where this connects to the compliance world

For companies working toward the Cybersecurity Maturity Model Certification (CMMC) or already assessing against National Institute of Standards and Technology Special Publication 800-171, this maps directly onto control families that are easy to treat as paperwork: incident response, contingency planning, and in Revision 3, supply chain risk management as a family of its own. Supply chain is the net-new lift in Revision 3, and it is exactly the muscle this situation exercises.

Those controls stop feeling abstract the moment you connect them to a real question: what happens to my operation when someone else has the bad day.

If you are affected

Watch for official notification through the company's own channels, treat unexpected calls or emails claiming to be from any involved organization as suspect until verified independently, and remember that a service outage does not suspend a contractual obligation. Insurance policies, in particular, remain in force when the systems administering them are offline.

Sources for the incident facts: TruStage's own outage hub and incident updates at trustage.com, and reporting from Credit Union Times, CU Today, and American Banker.

Adams Cloud and Cybersecurity LLC helps small businesses build the vendor list, write the fallback plan, and connect both to the control families assessors actually check. Service-Disabled Veteran-Owned Small Business. CISSP, CCSP, Security+ certified.

Do you know which vendor could take you offline?

The vendor dependency list takes about fifteen minutes and is the highest-return security exercise a small business can do without spending money. If you want help building it, and connecting it to the contingency and supply chain controls that CMMC and NIST 800-171 assessments check, start with a conversation.

Book a free thirty minute consultation