Cybersecurity continues to be top of mind in new ways that we might not have considered during “normal” times. One area that needed our attention then and now is vendor management. Especially with the mad dash over the summer to get many districts ready for at least some remote learning, there are a lot of new third-party vendors on the scene.

Pre-COVID, third-party vendors for schools and districts meant everything from transportation systems and student information platforms to applications like PowerSchool, Quizlet, and Google Classroom. Post-COVID, the term references all of that–plus things like COVID tracking and tracing programs.

Related content: 3 ways to improve online learning security

Regardless of whether we are talking pre- or post-pandemic, third-party vendor risk is a serious thing. Ponemon Institute found that in the United States, 61 percent of data breaches were caused by third parties and vendors.

Are you wondering if you should get rid of third-party vendors? There’s no need to take such a dramatic step, but you should plan to get more focused on knowing what third-party vendors bring to the table when working with your school or district.

Let the vetting begin

Vetting third-party vendors is like asking a teenager if they cleaned their room. As long as you don’t look under the bed or in the closet, everything looks good. The problem is, when you’re running a school, you have to really dig into those dark places no one wants to look.

About the Author:

Ryan Cloutier, CISSP, is the principal security consultant at SecurityStudio, which works to fix information security industry problems through simplification. A passionate cybersecurity thought leader Ryan is an advisor on the Consortium for School Networking (CoSN) Cyber Security Advisory Panel and can be reached at rcloutier@securitystudio.com.


Add your opinion to the discussion.