Three Questions TruStage Should Be Able to Answer Right Now
Posted August 4, 2026 · Cybersecurity / Third-Party Risk
Jeff L. Bassill, CU Risk Advisors
Public updates regarding the recent cybersecurity incident remain focused on limited preliminary findings. As of its most recent public updates, TruStage has confirmed that account balances, including 401(k) and other retirement accounts, were not affected. However, specific details regarding whether member or credit union data was accessed have not yet been disclosed. Three weeks in, this reflects the reality of complex forensic investigations, which naturally require time to complete thoroughly.
Yet, there is an important distinction between what an active forensic investigation can confirm and what a standard vendor risk management framework should enable a partner to clarify. The questions below do not ask TruStage to reveal premature investigative findings. Instead, they focus on foundational operational practices that should exist independent of any active incident. Establishing clarity on these points is essential for credit unions evaluating their own risk profile.
What are your data retention policies?
This is a policy question, not an investigative one. Every credit union with a current or former TruStage program should be able to receive clear documentation on how long member and credit union data is retained, both during an active contract and after a relationship concludes. A documented retention schedule exists independently of an active incident investigation.
Do you maintain an inventory of what credit union data was in your systems?
Before any vendor can confirm whether an institution's data was impacted, it must maintain a comprehensive data inventory. This is a matter of data governance rather than forensics. A mature data governance program maintains structured records of which categories of data reside within specific systems and client relationships. Having this inventory documented is a foundational pillar of effective vendor risk oversight.
Do you use third-party processors or subcontractors, and were any in scope?
Third-party risk rarely stops at the primary contract. If a vendor relies on sub-processors, technology partners, or subcontractors to manage member or credit union data, financial institutions have a regulatory interest in knowing those operational dependencies exist and whether they fall within the scope of the incident. This is a standard disclosure regarding the supply chain, rather than a request for technical root-cause analysis.
What to do while you wait:
Submitting formal, documented inquiries puts your risk assessment on record. Communicate in writing, maintain accurate copies, and review contractually specified retention or destruction terms. Absent institution-specific confirmation, documented policies and confirmed operational outcomes must be treated as distinct factors in your risk assessment.
Document every step of your oversight process: your formal written inquiries, submission dates, responses received, and internal risk decisions made in the interim. This aligns with standard incident response recordkeeping and protects your institution's compliance posture regardless of future disclosures.
As forensic investigations progress over the coming weeks, credit unions that proactively document these questions, maintain clear records, and monitor developments will be in the best position to protect their institutions and members.
*The views expressed in this post are my own and do not represent the official position of Kings Federal Credit Union. This post reflects publicly available information as of the date above and is not legal advice. Institutions should consult counsel regarding their own contractual rights and notification obligations.

