Continuity · July 2026

Your vendor just told you to shut it down. Now what?

Every business has at least one vendor who could send that email. Very few have thought about what they would do next.

On July 10, 2026, Progress Software told customers running ShareFile Storage Zone Controllers to immediately shut down the Windows servers hosting them. Not patch them. Shut them down. The company cited a "credible external security threat" and simultaneously disabled access to affected ShareFile accounts while it investigated.

We plan for the vendor who gets breached. Far less for the vendor who does the right thing loudly and hands you an outage in the process.

There was no patch available. There was no timeline. Customers using ShareFile to store and share files, often the files their daily work depends on, were told to turn it off and wait.

Four days later, on July 14, Progress confirmed the cause: a previously undisclosed authenticated path traversal flaw affecting every 5.x and 6.x release of the Storage Zone Controller, which could let an attacker read, write and map files on customer servers. Patches shipped and access was restored. Progress said it found no evidence of unauthorized access to customer accounts or data, and no public reporting has confirmed anyone was actually compromised.

Nothing went wrong, and it was still disruptive

That last detail is the interesting part. By the available evidence, the system worked. A vendor found something serious, acted decisively rather than quietly, and got customers to safety before anybody was hurt.

And it was still four days of an important system being off, for every customer, with no warning.

We spend a lot of time planning for the vendor who gets breached. Far less for the vendor who does the right thing loudly and hands you an outage in the process. From where you sit, the two feel similar on the first morning.

The question to sit with

Which of your vendors could send you that email? Not which ones might get breached, which ones could credibly instruct you to stop using their product today, at no notice?

For most small organizations the list is short and uncomfortable: the file sharing platform, the practice or case management system, the accounting package, the remote access tool. Anything where the answer to "how would we work without this for four days?" is a long pause.

What a plan looks like

  • Know which systems have no workable substitute, and say so out loud before you need to
  • For each one, have a rough answer to how the work continues for a few days without it
  • Keep an independent copy of anything critical that lives only in a vendor platform
  • Make sure someone actually reads vendor security notices, rather than discovering it from a client
  • Know who decides to comply with a shutdown instruction, and how fast

Concentration is the real risk

None of this argues against cloud platforms, which are usually more secure than what a small business would run itself. It argues for knowing where you are concentrated. A single vendor holding the only copy of work your organization cannot pause is a risk whether or not that vendor ever has a bad week.

The practical answer is usually an independent backup and recovery position that does not depend on the platform being available, plus enough honesty about which systems are genuinely load-bearing. If you have never mapped that out, it is a short exercise with a very good return.

Get started

Questions about your own setup?

A free assessment turns general guidance into specific next steps for your organization. No pressure, no obligation.