Congress demands answers from Instructure after the Canvas breach

The House Committee on Homeland Security has asked Instructure to account for the large-scale attack on the Canvas learning platform. In its letter, lawmakers ask how the attackers gained access, which security controls failed, and whether weaknesses were known beforehand. The attack, linked to the ShinyHunters group, hit schools and universities during exam season and reportedly exposed names, email addresses, student IDs and private communications. The company has been asked to provide documentation by the end of May.

What this means for your organisation

What is instructive here is not only the breach but the aftermath. A compromised vendor now has to answer for its control choices to regulators, customers and ultimately its own board. Norwegian organisations are in the same position when a cloud service they use is hit: responsibility for personal data stays with you as controller, whoever runs the platform. The question you should be able to answer the same day is what data the vendor actually holds.

Berigo recommends

  • Build an overview of which SaaS services process personal data on your behalf, and which categories they hold.
  • Put notification deadlines and a named contact point for breaches into your data processing agreements, not just a generic reference to GDPR.
  • Rehearse the scenario where the vendor is breached and you must notify your own users without technical visibility of your own.
  • Take supplier risk to the board as its own agenda item, with named services rather than an aggregate score.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch