Higher Ed Told to View Third-Party Cyber Risks as Their Own

At the EDUCAUSE conference, a legal consultant said colleges should treat technology supply-chain threats as part of their own institutional security, privacy and legal concerns. Attacks this year on Instructure's Canvas and Oracle PeopleSoft showed how a vendor flaw can disrupt campus operations, including delayed final exams. Institutions also face overlapping state and federal breach-reporting duties, which can complicate reliance on vendor assurances.
At EDUCAUSE in Denver, legal consultant Emma Bahner said campus cybersecurity, procurement and legal units often fail to coordinate, even though vendor breaches can create institutional exposure. The Canvas incident involved unauthorized access on April 29 through Free-for-Teacher accounts, followed by a second exploited flaw on May 7 that forced Instructure to take the platform offline.
The outage disrupted campuses, with some finals delayed or rescheduled. Instructure said it later reached an agreement with the intruder and received electronic assurance that taken information had been eliminated, and planned to provide affected institutions more detail. UC San Diego privacy chief Pegah Parsi added that exposed messages may carry distinct risks depending on their contents.
This story may affect students, faculty, and administrators whose campuses rely on outside software. A vendor breach could delay exams, expose personal records, or complicate legal reporting, potentially eroding trust in digital learning tools. Institutions may need clearer contracts and closer coordination among legal, privacy, IT, and procurement staff. The impact could extend to families and applicants if sensitive messages or identifiers surface.