Schools · Governance & compliance

Supplier risk management at the ISNSW Security Symposium

Using the Canvas data breach to explore practical, collaborative approaches to supplier risk management in education.

Damien Cantelo

Damien Cantelo

August 4, 2026

ISNSW Security Symposium event announcement

We used the Canvas data breach as a case study to explore what it means for schools and to discuss practical approaches to supplier risk management in education.

Third-party risk is becoming increasingly difficult to manage. Many schools rely on more than 100 suppliers, but few have the resources to conduct detailed assurance reviews of every one of them.

The answer cannot simply be more questionnaires and more administration.

We need risk-based approaches that help:

  • Identify the suppliers that support critical services or handle sensitive data
  • Focus assurance efforts on the areas of greatest exposure
  • Set clearer minimum security expectations
  • Monitor material risks throughout the supplier relationship
  • Share knowledge and assurance activities across the sector

There is a real opportunity to tackle these challenges collectively, reducing duplicated effort while improving the quality of supplier oversight.

Thanks to Marcus Claxton for organising a great event and showcasing Member Advantage partners like Apollo Secure.

Make Cyber Compliance Simple

See how Apollo Secure can help you manage cyber risk, compliance and customer trust without enterprise complexity.

Book a Demo