The SHA-1 deprecation wasn't a secret: it was decided back in October, 2014. In February 2016, one provider basically said "oops, we screwed up, how can we get a SHA-1 certificate?", whereupon the answer was a one-off exception that would be notated as "yes, Symantec violated the rules, but everyone agreed to let this exception go through." This exception was converted into a more formal exceptions approval in June.
Tyro's certificate would have expired on June 9, 2016 if I'm reading the timeline right. There is nothing that would have prevented them from doing what WorldPay did and approach the CAB themselves, or become vigorously involved in the ongoing discussion (the proposal document for the process was made June 3, 2016).
On the other hand, as the IT mantra goes, failure to plan on your part does not constitute an emergency to plan on my part. The evidence is that Tyro updated its certs at the last minute, found that they couldn't get the SHA-1 they needed, and basically shopped around until they found someone who gave it to them (while lying about it!), instead of, say, making sure to request a certificate in late December to maximum the transition time available.
The great sin is not so much that they issued the SHA-1 certificate, but that they agreed not to do it, and when someone needed one, rather than bring it up with the CAB Forum, they issued one and lied about their compliance. The REALLY great sin is that they appear to have built an entire system to do the backdating, rather than applying one-offs.
Browsers can forgive CAs when they fess up to their mistakes. It's when they lie about them that they get really pissed off.