This Month in Renewals: A Vendor Outage Still Unresolved Weeks Later
Not how long the downtime lasted, but how long the scope of it stayed genuinely unknown.
This Month in Renewals, August 2026, Edition 3. A financial services technology vendor serving credit unions spent weeks working toward what its own CEO described as basic recovery, not full recovery, from an incident serious enough to force a shutdown of parts of its network. As of mid-August, forensic investigators still had not determined whether member data was compromised.
What actually happened
The vendor, which processes billing, claims and annuity services for credit union clients, targeted the first half of August just to restore basic billing and claims servicing, weeks after the initial incident. Recovery was handled in isolated phases rather than a full system restart, with core payment processing tested individually with a handful of client credit unions before wider rollout. The more complex life insurance servicing platform remained unresolved even at that stage.
Recovery in phases, scope still open
Downtime duration
Hours or days until service returns, which is the number an uptime SLA covers.
Duration of uncertainty
A vendor can be recovering and still be an open question on your own risk register.
Source: Industry reporting on the vendor's public recovery updates and CEO statements, as of mid-August 2026.
Why the open-ended timeline is the real story
Most outage coverage focuses on downtime duration, the hours or days until service returns. This incident illustrates a different and often underweighted risk: an outage where the actual scope, whether customer data was exposed at all, remains genuinely unknown for weeks after systems start coming back online. A vendor can be recovering and still be an open question mark on your own risk register.
The renewal and vendor-risk lesson
This is the scenario a vendor risk review is supposed to catch before it happens, not the technical security review alone but the practical question of what your exposure looks like if a critical vendor goes dark for weeks with an uncertain data outcome. Few standard renewal processes ask a vendor directly what their documented incident response and communication timeline actually looks like. Most simply assume one exists.
What to actually ask a critical vendor now
- Whether they have a documented, time-bound commitment for initial incident communication, not just an uptime SLA
- Whether contract language addresses your own obligations and exposure during an extended, ambiguous recovery period
- What their phased recovery order would be, and where your services would sit in it
- Who your named contact is during an incident, and how often they commit to updating you
Source: Industry reporting on the vendor's public recovery updates and CEO statements, as of mid-August 2026.