The Vendor's Breach, Your Students: Third-Party Student Data Exposure

The breach didn't happen on your network. It happened at a vendor most of your campus has never heard of — and it exposed decades of your students' data, including records nobody remembered sharing. The vendor will investigate on its own timeline. Your students, parents, press, and regulators expect answers on yours.

This scenario runs university leadership through the defining data crisis of the outsourced era: accountability without control. Data mapping under pressure, a campus community learning about the breach from social media, notification letters nobody wants their name on, and a town hall where the honest answers are the uncomfortable ones.

Approachable for teams new to incident exercises, and pointed enough to reshape how your institution governs every vendor that touches student data.

1 hr 30 minBeginner

EducationFERPANIST CSF

What this scenario tests

  • Whether your institution can answer for a breach it didn't cause and doesn't control
  • How quickly your team can establish what data a vendor actually held
  • How your leaders communicate honestly when the vendor's facts keep changing
  • What your campus learns about every other vendor holding student data

Who it's for

Executive / C-Suite · IT & Security Team · Legal & Compliance · Communications / PR

Based on real events — read the source

READINESS STARTS BEFORE THE CRISIS.

Put your team to the test.

Build your first scenario and turn preparation into measurable progress.

Explore pricing →Request a demo →