Oct 01 2026
Security

Roundtable: How K–12 Districts Are Managing Third-Party Risk

K–12 districts are tightening contracts, standardizing data privacy agreements and building response plans to protect student data from vendor-related security failures.

Schools increasingly depend on third-party tools to support everything from classroom learning to back-office operations. But there’s a price to pay. A majority of all publicly disclosed K–12 data breaches have traced back to vendors and third-party partners, not direct attacks on districts. Districts often bear the consequences of their vendors’ security shortcomings.

With 48% of education breaches now involving a third party, schools are taking a hard look at how they manage that risk. With that in mind, EdTech convened a roundtable of district leaders to talk about their strategies. Participants included:

Click the banner below to learn how organizations are adjusting their cybersecurity strategies.

 

EDTECH: How are you managing vendor contracts to mitigate risk?

BERGER: Here in Arlington, we have add-ons to our contracts. Some of the more recent events that have happened around third-party risk are causing all of us to look at those more closely, to really better define contact and consider the level of detail within that contact.

When the third party has the breach, if they’re just reaching out and saying, “Hey, something has happened, we’ll get back to you,” we want a little more context. Maybe, “Here’s what you need to be aware of or what you need to do.” What actions do we need to take on our end to make sure that we are protecting our data? You sometimes sit in this waiting game, and we have to be a little more proactive from our side of the house. So, we’re putting language in there around that.

BRANDT: We have a thorough process to evaluate programs before we sign any contract, which involves our local and district data governance committees. If a staff member wants to use a third-party tool, they must take it through that governance process.

We use resources such as 1EdTech, a consortium that helps vet products, and we are also members of Access 4 Learning (A4L), which originated the National Student Data Privacy Agreement. Our committee reviews both resources to assess the vetting quality. We don’t proceed unless a vendor agrees to sign our data privacy agreement. All of that is part of the process.

READ MORE: Protect student data through smarter vendor risk management.

LEVENS: You need to develop a cadence for how you will review your existing application suite annually. Double-check who you’re using annually, and before you just sign that renewal, do a deep dive into their privacy policy to re-examine what could have changed between this signing of the contract and what you signed a year ago or maybe five years ago.

Also, most vendor contracts require the vendor to notify the district when its permissions, terms or privacy policies change. That is important, but notification alone may not be enough. Many school districts do not have the staff or resources to continuously monitor frequent updates.

Districts should consider including contractual language that requires material changes to be reviewed and approved before they take effect. That gives the district an opportunity to evaluate the change, understand the potential risk and determine whether it is still comfortable continuing the relationship.

LOMBARDO: In the past, it was sometimes hard to know who you were dealing with, especially when you have individual teachers who’ve signed up for products. So, that first tier is getting an accurate inventory of what vendors you’re talking about. That’s the first stage for us, along with making sure that everyone involved in the procurement process knows how to deal with a vendor.

We have a software catalog that we maintain, and anyone can request an application be added to it. Once that request has been made, it kicks off the whole process of us evaluating terms of service and looking at student data privacy agreements.

Andy Lombardo

 

EDTECH: How are you handling data privacy agreements?

BERGER: We do have a standard data privacy agreement that’s out there. But it’s not only third-party: It’s also the third parties of the third parties. With how AI works nowadays, the third-party provider might have an AI engine that’s also working within theirs that’s off-sourcing our data.

We’re really asking a lot more defined questions around that data privacy aspect of it, who all the holders or processors of our data are and what level of control that third party has over it. We’ve really tried to get a sense of how much we’re providing — how much do we really need to send to you? — and really pare that back.

BRANDT: We require vendors to sign the data privacy agreement we have with A4L. Because our attorneys have already vetted this agreement, it streamlines the process significantly. If a vendor signs it, we are ready to proceed. This documentation also allows other school districts in the state to piggyback off our agreement.

Collaborating on a standard agreement saves everyone time, keeps our standards high and ensures we can trust the process.

WEBINAR: Map third-party SaaS risk across education institutions.

LEVENS: The challenge with any vendor that has access to district data is determining how you can be confident that the vendor is meeting its privacy and security responsibilities. One tool we leverage as appropriate is the Michigan Student Data Privacy Consortium Agreement. 

Michigan’s participation in the Student Data Privacy Consortium gives districts access to a standardized data privacy addendum that has already undergone legal review and reflects expectations established for the K–12 environment. Districts can present that addendum to vendors as part of the contracting process rather than developing privacy language from the ground up for every agreement.

We also leverage CoSN’s vendor assessment toolkit. That has all of the different questions that you would want to ask as a customer of any ed tech platform, or any platform that’s going to have access to your data.

LOMBARDO: You can request data privacy agreements from vendors, but it involves a whole legal negotiation process. As a small district, I don’t have a lawyer on retainer who can negotiate data privacy agreements for me.

Thankfully, we can rely on the Student Data Privacy Consortium. We also belong to an education cooperative, the TEC Student Data Privacy Alliance. Our state educational association has contracted with them for discounted services, where they do the heavy lifting when it comes to negotiating data privacy agreements with vendors. Through SDPC, we can submit a request for a data privacy agreement with a vendor and tag TEC on it. Then, TEC’s lawyers will do the negotiation on the data privacy agreement for us. That’s been a huge help.

Data Point

 

EDTECH: How do you pick up the pieces when a third-party-based breach occurs?

BERGER: As a district, we have incident response plans built around cyber incidents. But sometimes, those are written for if it happens here, within our area of control. We’ve been re-evaluating our incident response plans for when it is a third-party breach. What steps and actions can we take, knowing that we might not have full knowledge of what is happening? What can we do to secure our district, our students’ data and assets overall? 

That means really being sure that we have clearly defined how all of these programs are connected to us. Say a third party had a breach: It’s making sure that we can terminate our connections to them. Because interoperability in ed tech is great, but sometimes when we go to unwind it, it can get very cumbersome.

BRANDT: The first step is to stay calm, gather all of the information and assess the extent of the breach. Identify exactly what was compromised. Was it sensitive data, like Social Security numbers? If so, you will proceed a lot differently than if the breach involved information that was not as critical.

First, you need to inform the superintendent of the investigation. Then, develop a plan for how to communicate with stakeholders — teachers, parents, students and the community.

We’ve seen companies that have dealt with breaches be very transparent about what happened, what they could share and their plan. Open communication with our partners helps everybody navigate these situations successfully.

LEVENS: With a third party, you want to consider a few things. What agreements do you have in place with them regarding what they will do when a bad thing happens? Your incident response plan might literally pose this question: What do we have in place with this vendor around identity theft and credit monitoring if a breach occurs?

Have an inventory list where you would really put the nuts-and-bolts details: For this application, we have these agreements in place. Then, the incident response plan would say to check that list.

LOMBARDO: We’re also a member of K12 SIX, an information-sharing consortium. They have a third-party risk management framework that they provide for districts free of charge, to use to help evaluate contracts. And if there is a breach, K12 SIX does a great job of aggregating information quickly and disseminating it to members.

Once we gather the information, a lot of it evolves over time as you find out the depth and breadth of what happened. Some of that can come from the vendor, and some of it will be your own investigative work.

If there is an incident, we want our stakeholders to learn about it from us first and not from the news. So, we like to err on the side of communicating quickly, even if it’s not complete information — just something to let them know that there has been an incident, we’re aware, we’re working with a vendor and they’ll get updates later.

Suzan Brandt

 

EDTECH: What advice would you offer to other K–12 schools looking to manage third-party risk?

BERGER: When these third-party breaches happen, a lot of us are in the same situation. When a recent breach occurred, all of us area CTOs were on the phone together strategizing: “Here’s what I’m doing. What are you doing? What is your forward messaging that you’re putting out to your community?” We often run into one district saying one thing while another is not saying anything, and another is saying something else. We try to get together on our messaging.

BRANDT: Companies are bought and sold constantly, and new functionalities are added to programs every day. We need a way to monitor and watch those changes so we can hold companies accountable. We need to be notified so we can evaluate what we want to do moving forward with that company.

And consistency is vital. You need to develop a process, stick to the process and apply the process to every vendor.

LEVENS: Classify your vendors by risk, so that you know and understand the prioritization of the data that they have access to. They might not house it, but if there’s a breach, they might have access to sensitive data. So, have a list of what they have, categorized by sensitivity.

You also need to have a plan for vendor failure. What is your district’s plan to be able to move forward if a significant vendor fails? How will you continue? Have a continuing-operations plan, so you know how to keep the school functioning on a day-to-day basis if any of these critical systems fail entirely.

LOMBARDO: One of the things that K12 SIX recommends is evaluating your vendors based on both the sensitivity of the data that they house and the operational sensitivity, or how impactful that vendor is.

When you’re doing that contract evaluation and determining where your different vendors are in terms of risk, that can change your response plan — the depth and breadth of how much you have to investigate, how much you have to communicate. Having a good idea of how critical a vendor is on the front end will inform what kind of steps you need to take and how much you need to communicate.

Michael Glenwood Gibbs/Theispot
Close

New Research from CDW Explores AI and Cybersecurity

Learn how AI is helping IT teams manage risk and improve resilience.