EDUCAUSE ’26: Colleges Need to Treat Vendor Risk as Institutional Risk | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


DENVER — Cyber attacks on Instructure’s Canvas learning management system and Oracle PeopleSoft applications earlier this year offered colleges and universities a lesson: to treat their technology supply chains as part of their own security, privacy and legal risk.

At the EDUCAUSE annual conference last week, Senior Associate Emma Bahner of XL Law and Consulting, a legal group serving higher-ed institutions, said even though attacks on third-party tools can bring legal risks to those institutions, their cybersecurity, procurement and legal teams do not always talk to each other.

The Canvas attack demonstrated how quickly a problem in a third-party service can become an operational problem for universities. According to Instructure’s FAQ page about the incident, an attacker first gained unauthorized access on April 29 through a vulnerability involving the platform’s Free-for-Teacher accounts. On May 7, the attacker exploited a second Canvas vulnerability, prompting Instructure to take the platform temporarily offline. The company’s website said the second incident did not result in additional data exfiltration.


The disruption nevertheless reached directly into campus operations. Universities reported delayed or rescheduled final exams after Canvas was taken offline in May.

Instructure’s website said the company ultimately reached an agreement with the unauthorized user and received digital confirmation that the stolen data had been destroyed. The website said Instructure also intended to provide affected institutions with more detailed information about the data involved.

However, that assurance may cause problems with overlapping state and federal reporting requirements in some cases. For example, the Department of Education’s website says schools must immediately report breaches of student records and information, including the date, number of affected records, how the breach occurred, a security contact, remediation status and next steps.

To meet these requirements, assurance from a vendor, much less a cyber criminal, that stolen information has been deleted may not be enough, Bahner said.

“These are bad actors,” she said. “These aren’t honest people to start with.”

Outside of these requirements, Pegah Parsi, chief privacy officer at the University of California San Diego, said institutions need to think beyond the most obvious forms of sensitive information that third-party vendors have access to when considering their security posture. The Canvas incident, for example, involved data such as names, student IDs and email addresses, but potentially exposed messages could create different risks depending on their contents.

Some institution leaders at the EDUCAUSE session said they were still waiting to hear from Instructure about which messages were exposed in the breach and what information they might have contained.

“You have to really think about people that are on the back end of this,” Parsi said. “They are the thing that we’re trying to protect.”

That means institutions should establish those relationships before an incident occurs, Parsi said. The first step is to identify who owns institutional data and who has the authority to make decisions about it, especially in the event of a breach. Data stewards, IT and cybersecurity teams should determine what systems and information were affected, while privacy and legal teams assess which laws and contractual obligations apply. Procurement teams can then work with those groups to review the vendor’s contract, including requirements for breach notification.

Institutions should also make sure those contracts require vendors to notify the institution when they suspect an incident, rather than waiting until they have confirmed that an incident meets the legal definition of “breach,” Parsi said. That way, institutions are not at risk of non-compliance with reporting requirements that include timely notification.

“If you call it a breach, a lot of places will interpret that to mean, ‘We get to do our whole investigation, we get to do a bunch of stuff, and then three months later, once we’ve confirmed that it is in fact a breach, only then will we tell you,’” she said.

The work should not end when the vendor closes the incident, Parsi said. She recommended that that same group of leaders in IT, legal counsel and procurement conduct an independent post-incident review, examining what information the vendor had, whether the institution retained more data than it needed and where communication broke down.

Tabletop exercises can help institutions identify those weaknesses before a real breach occurs and expose which institutional practices might worsen the impact. For example, Bahner said she knows of some institutions that had never purged data stored in Canvas since they licensed it, in part because teachers wanted consistent access to past course materials. Those institutions saw many more people impacted by the breach than those with data-retention schedules.

Parsi said institutions should run these exercises even for free software that does not play as big of a role in institutional operations as Canvas or PeopleSoft.

“Free of charge does not mean free of risk,” she said.



——————————————————-


Click Here For The Original Source.