The Vendor's Breach, Your Students: Third-Party Student Data Exposure
The breach didn't happen on your network. It happened at a vendor most of your campus has never heard of — and it exposed decades of your students' data, including records nobody remembered sharing. The vendor will investigate on its own timeline. Your students, parents, press, and regulators expect answers on yours.
This scenario runs university leadership through the defining data crisis of the outsourced era: accountability without control. Data mapping under pressure, a campus community learning about the breach from social media, notification letters nobody wants their name on, and a town hall where the honest answers are the uncomfortable ones.
Approachable for teams new to incident exercises, and pointed enough to reshape how your institution governs every vendor that touches student data.
1 hr 30 minBeginner
EducationFERPANIST CSF
What this scenario tests
- Whether your institution can answer for a breach it didn't cause and doesn't control
- How quickly your team can establish what data a vendor actually held
- How your leaders communicate honestly when the vendor's facts keep changing
- What your campus learns about every other vendor holding student data
Who it's for
Executive / C-Suite · IT & Security Team · Legal & Compliance · Communications / PR