We used the Canvas data breach as a case study to explore what it means for schools and to discuss practical approaches to supplier risk management in education.
Third-party risk is becoming increasingly difficult to manage. Many schools rely on more than 100 suppliers, but few have the resources to conduct detailed assurance reviews of every one of them.
The answer cannot simply be more questionnaires and more administration.
We need risk-based approaches that help:
- Identify the suppliers that support critical services or handle sensitive data
- Focus assurance efforts on the areas of greatest exposure
- Set clearer minimum security expectations
- Monitor material risks throughout the supplier relationship
- Share knowledge and assurance activities across the sector
There is a real opportunity to tackle these challenges collectively, reducing duplicated effort while improving the quality of supplier oversight.
Thanks to Marcus Claxton for organising a great event and showcasing Member Advantage partners like Apollo Secure.

