Open in interactive viewer → charts, metric popovers & call review

Craneware Resets to Its $185M ARR Floor — With a Cyber Breach and a 340B Squeeze On Top

Flat FY26 revenue, a fresh threat-actor incident, and a full cost-base review force the health-IT name to rebase FY27 back to recurring revenue.
CRW.L · Earnings Call · 2026-09-22

The reset nobody wanted

Craneware arrived at its FY26 call in full damage-control mode. The headline numbers were not catastrophic — revenue was broadly unchanged at $206 million, adjusted EBITDA landed at $67.1 million for a 33% margin, adjusted EPS was $1.68, ARR held steady at $185 million, and operating cash conversion came in at 98% — but the trajectory had clearly broken. The Board still proposed maintaining the 32p total dividend, and year-end cash of $54.8 million against $43.5 million of bank debt left a modest net-positive position. CEO Keith Neilson did not sugarcoat it: “we are obviously deeply disappointed by the fiscal '26 results” — Keith Neilson, Chief Executive Officer · 2026-09-22, before adding the plea that has become the call's refrain — “not to throw the baby out with the bathwater” — Keith Neilson, Chief Executive Officer · 2026-09-22. What makes this quarter a genuine inflection is the guidance decision. Rather than model growth off a stalled top line, management rebased fiscal 2027 revenue to roughly the level of its recurring revenue base, abandoning any near-term transactional upside until the uncertainty clears. CFO Craig Preston framed it as prudence over hope:

As we enter fiscal '27 and in light of the post year-end cyber incident that Keith has talked you through, we have adopted a prudent planning basis we've reset our revenue expectations to approximately the level of our current ARR, and that's to provide certainty to all our stakeholders... at this point.

Craig Preston, Chief Financial Officer · 2026-09-22
Against that lower base, the company launched a comprehensive review of its entire cost base — a review Neilson conceded would keep the group at mid-to-high-20s margins through FY27 rather than the 30%-plus it historically enjoyed.The 340B fault line The root cause of the miss is structural, not self-inflicted. Craneware's transactional economics lean heavily on the U.S. 340B program — now, per Neilson, a roughly $100 billion program in its 34th year. The problem is drug manufacturers unilaterally restricting hospitals' ability to use contract pharmacies and honor 340B pricing. Craig's illustration was the shelter program: “we saw high levels of customer engagement. But due to the restrictions that were being placed on them, they were unable to take advantage of these opportunities” — Craig Preston, Chief Financial Officer · 2026-09-22. The result was a visible late-year slowdown in Transactional revenue, which also stalled platform revenue from being reclassified as recurring — a double hit to both ARR and growth. The policy backdrop is genuinely fluid: proposed rebate model pilots starting January 1, plus three competing bills — the SUSTAIN, SECURE, and ACCESS 340B Acts — with differing treatments of contract pharmacy protections and rebates. Craneware's answer is product: the new OneLink Medication, built to push 340B workflows, auditability and transparency onto the Trisus platform regardless of which model wins, alongside its continuing revenue integrity enhancements. Notably, 340B is a world Craneware occupies essentially alone — no 340B theme surfaces anywhere in the broader market's curated keyword set, confirming this is a company-unique exposure rather than a sector wave.

An unwelcome July surprise

The second, fresher shock arrived after the balance-sheet date. In early July, Craneware disclosed that external threat actors had accessed its systems — a cybersecurity incident in which files were exfiltrated and threatened with dark-web publication, some containing staff and customer patient details. “some threat actors had access to our system and had exfiltrated some files from our system with the threat that we would publish the details of those files onto the dark web” — Keith Neilson, Chief Executive Officer · 2026-09-22. The company says the actors were verified out of the environment within hours and that operations continued, but it has now entered a formal remediation phase. On cost, Neilson was blunt: “We just don't know. It's too hard to quantify that at this stage” — Keith Neilson, Chief Executive Officer · 2026-09-22. On customers, he reported no lost or delayed renewals. This is where contrast is instructive. Cybersecurity shows up globally only in scattered, low-conviction clusters — Commvault's Cyber Resilience platform is one of the few, and it is not a market-wide advancer. Breaches are idiosyncratic events, not a theme the tape is collectively pricing, so Craneware's incident reads as a single-name overhang, not a risk factor the whole sector is discounting.

Why it matters

The bull case now rests on resilience rather than growth. ARR is genuinely diversified — no single customer exceeds 8% of it, the top ten are under 30%, and those relationships average over 21 years. Neilson also confirmed there is no takeover interest on the table (“Any potential bid, nothing we're aware of” — Keith Neilson, Chief Executive Officer · 2026-09-22), and Preston guided that the model still assumes roughly 100% net revenue retention. In other words, Craneware is not shrinking — it is deliberately standing still while it waits for 340B rule-making and cyber clarity to resolve. For a sub-$400 million-cap name with no visible price tape, that is a credible but thin story: a profitable, cash-generative annuity business choosing a lower, surer base over an uncertain one, betting the swing back toward providers arrives by FY28.