TruStage Adds New Resource for CU Boards as Part of Update on Cybersecurity Incident

MADISON, Wis. — TruStage is reporting it has created a new resource specifically for credit union boards as it continues recovering from a cyberattack, acknowledging that directors are raising questions about the potential impact on member data, the status of restored services and what credit unions can learn from the incident.

The company said its new September Board Discussion Guide is intended to give credit union CEOs a concise, executive-level overview they can use during upcoming board meetings.

Tammy Schultz, TruStage’s chief sales and marketing officer, said the guide was developed after conversations with credit union executives, league leaders and other industry partners indicated that CEOs needed additional information to address questions from their boards, employees and members.

“I’ve heard from several of our sales executives that there is a need for a concise, Board-level resource that explains where our recovery stands, what has meaningfully changed and what your directors should understand about the path forward,” Schultz said in a message to credit union CEOs.

Data Investigation Remains Ongoing

The new guide comes as TruStage continues investigating the potential data impact from the cyberattack, an issue the company acknowledged remains a significant concern for credit union executives and directors.

Schultz said credit unions face the challenge of preparing for different possible outcomes while TruStage’s assessment remains underway.

“We recognize that uncertainty creates difficult questions for credit unions, their Boards and their members,” Schultz said. “Our responsibility is to pursue accurate conclusions, communicate verified information and prepare responsibly for the paths that may follow.”

TruStage said it will share its final plan once that work is completed.

The guide includes an overview of how TruStage is managing its recovery, independent security and financial perspectives, the status of the data investigation and clarifications addressing frequently asked questions as of Sept. 1.

It also provides cybersecurity considerations for credit union directors and information on where credit unions can find the latest updates.

Boards Asking What CUs Can Learn

TruStage said another question emerging from credit union boards is what their own institutions should learn from an attack significant enough to disrupt the company, which it has said is the result of an employee downloading a malicious file.

“If an attack of this magnitude could affect TruStage, what can our credit union learn from the experience?” Schultz said some directors are asking.

TruStage said it expects eventually to share lessons learned from the attack and recovery that could help credit unions strengthen their own resilience. The company said it remains too deeply involved in its investigation and recovery to provide that broader assessment now.

In the meantime, the board guide includes recommendations from TruStage’s cybersecurity response partners addressing resiliency, testing and governance that credit union directors can consider in overseeing their own institutions.

Some Services Still Limited

TruStage said it continues to make progress restoring operations and has prioritized functions affecting credit union members, employees and institutions.

The company acknowledged, however, that some services remain limited or continue to rely on interim processes.

“We also recognize that some experiences remain limited or dependent on interim processes,” Schultz said. “Our commitment is to continue reducing that burden while giving you information that is useful, current and straightforward.”

TruStage said the board guide is intended to complement, rather than replace, the more detailed operational updates it has been providing to credit unions through its partner communications and online outage dashboard.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.