Three Questions TruStage Should be Able to Answer Rght Now

Editor’s Note: Theis is the second in a two-part series by Jeff Bassill on the ongoing TruStage security incident. Part one can be found here.

By Jeff Bassill

TruStage still hasn’t said anything about the scope of its cybersecurity incident. As of its most recent public update, the company has confirmed that account balances, including 401(k) and other retirement accounts, were not affected, but it has offered nothing on whether member or credit union data was accessed. 

Three weeks in, that’s the honest state of the investigation, and it may need to stay that way for a while longer. Some things genuinely take time to determine.

But there’s a difference between what an active investigation can’t yet confirm and what a well-run vendor should already be able to tell its credit union partners regardless of where that investigation stands. The questions below don’t ask TruStage to reveal anything about this incident’s findings. They ask about practices that should already be documented, incident or not. If TruStage can’t answer these, that’s worth knowing too.

What are Your Data Retention Policies?

This is a policy question, not an investigative one. Every credit union with a current or former TruStage program should be able to get a straight answer on how long member and credit union data is retained, both during an active relationship and after a program or contract ends. This shouldn’t require the incident to be resolved first. A vendor either has a documented retention schedule or it doesn’t, and that answer exists independent of anything currently under investigation.

Do You Maintain an Inventory of What Credit Union Data Was in Your Systems?

Before TruStage can tell any individual credit union whether its members were affected, TruStage needs to know what data it held in the first place, and from which institutions. That’s an inventory question, not a forensic one. A vendor with mature data governance should already know what categories of data live in which systems, tied to which client relationships. 

If that inventory doesn’t already exist in usable form, that itself says something about the maturity of the program, separate from whatever this specific incident turns out to involve.

Do You Use Third-Party Processors or Subcontractors, and Were Any in Scope?

Vendor risk rarely stops at the first vendor. If TruStage relies on a data processor, subcontractor, or technology partner to handle any part of member or credit union data, credit unions are entitled to know that relationship exists and whether it falls within the scope of this incident. This is a disclosure question about TruStage’s own vendor chain, not a request to name a root cause or a specific point of compromise.

These are process questions, and a mature vendor relationship has answers to them before an incident ever occurs, not after.

What to Do While You Wait

None of this requires TruStage to say anything it isn’t ready to say. But it does put a documented request on record, and that record matters regardless of how the investigation resolves. Put your questions to TruStage in writing, not just a phone call or a portal message, and keep a copy. If your contract specifies a data retention or destruction timeframe, that language matters, but absent a current, direct response confirming what actually happened with your institution’s data, you cannot assume the contract terms were followed as written. 

A stated policy and a confirmed outcome are two different things, and only one of them is currently known.

Document every step of this process as you go, your written inquiry, the date it was sent, any response received, and any internal decisions your institution makes in the meantime. This is exactly the kind of record an incident response plan should already be capturing, and it protects your institution regardless of what TruStage eventually discloses.

And keep watching. An investigation that hasn’t produced answers in three weeks may produce them in three more, or it may not, but the credit unions in the best position when it does will be the ones who asked these questions early, wrote them down, and kept paying attention.

Jeff Bassill has 45 years of experience in financial institutions and currently serves as Chief Financial & Risk Officer at Kings Federal Credit Union, a role he moved into after retiring as the credit union’s President & CEO in 2022. He is also the founder of CU Risk Advisors, focused on Risk Management, Regulatory Compliance, and Indirect Lending.

The views expressed in this post are my own and do not represent the official position of Kings Federal Credit Union. This post reflects publicly available information as of the date above and is not legal advice. Institutions should consult counsel regarding their own contractual rights and notification obligations.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.