Supply Chain Fallout: Managing Legal Risk, Ransomware, and Compliance in Ed Tech
Supply Chain Fallout: Managing Legal Risk, Ransomware, and Compliance in Ed Tech
Friday, October 02, 2026 | 8:00AM–8:45AM MT
Session Type:
Featured Session
Delivery Format:
Featured Session
Recent high-profile breaches across platforms like Canvas and PeopleSoft highlight a stark reality: institutional data risk frequently stems from downstream vendors. When breaches disrupt campus operations, university counsel and IT leaders must navigate complex contractual, regulatory, and incident-response challenges. This session breaks down key legal takeaways from recent ransomware incidents:
Procurement & Contracts: Structuring indemnification, SLAs, and risk clauses for third- and fourth-party vendors.
Compliance & Privacy: Managing FERPA obligations (including faculty-student communications) alongside international laws like GDPR and PIPL.
Ransom Payments & Disclosure: Evaluating institutional notification duties and insurance liabilities when vendors pay extortion demands.
Incident Response: Practical strategies for general counsel and IT leadership to coordinate swift, cross-departmental breach response.