Continuing Education Information Sheet
Don't Gamble on Vendors: Strategies for Third-Party Cyber Risk Mitigation
- Provider
- Legal Cyber Academy · Lexeprint Inc.
13413 Granger Ave, Orlando, FL 32827
info@lawandforensics.com · https://www.lexeprint.com - Delivery method
- On-demand, self-study (online, recorded)
- Instructional time
- 59m
- Assessment
- Graded multiple-choice exam · pass mark 70%
- Administered online, unproctored, with identity verified only to the level of a confirmed email address. Each sitting draws 10questions at random from the course’s pool, is timed, and is fixed for that sitting; correct answers are never disclosed. The pass mark is provider-set and is not supported by published reliability statistics or a standard-setting panel.
Equivalent credit hours
0.9 on a 60-minute basis (most CLE / general CE) · 1.1 on a 50-minute basis (NASBA CPE). Rounded down to the nearest tenth of an hour; your board may round differently.
Learning objectives
- Explain why vendors create a unique cybersecurity threat
- Implement policies and practices to reduce vendor risk
- Conduct regular vendor risk assessments
- Apply lessons from the evolving regulatory landscape and case law
Audience & prerequisites
Intended audience: Attorneys and risk professionals advising clients on third-party vendor cyber risk.
Level: intermediate
Prerequisites: None
Faculty
Daniel B. Garrie, Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard
Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare
Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.
Roland Cloutier, Former Global Chief Security Officer, TikTok; former CSO, ADP
Roland Cloutier is a security executive with more than 30 years in cybersecurity, risk management, and law enforcement. He served as Global Chief Security Officer at TikTok, leading security for the platform's global user base until 2022, and spent a decade as Corporate Vice President and Global Chief Security Officer at ADP, where he ran cyber, information protection, risk, workforce protection, crisis management, and investigative security operations worldwide. He was previously Chief Security Officer at EMC, and earlier served with the United States Air Force, the Department of Defense, and the Department of Veterans Affairs. At Legal Cyber Academy he teaches on third-party and vendor cyber risk mitigation.
Judith Selby, Partner, TittmannWeix
TittmannWeix
Judith A. Selby is a partner at TittmannWeix, where her practice covers cyber, privacy and technology; first- and third-party cyber insurance coverage; regulatory claims insurance coverage litigation; and policy wording. She draws on more than 30 years in insurance coverage. She was named Zywave Cyber Risk Attorney of the Year in 2023 and a National Law Review Insurance Law Trailblazer in 2021, and served on the Zywave Cyber Risks Advisory Board in 2024. She holds a J.D. from Brooklyn Law School and is admitted in New York and Washington, D.C. At Legal Cyber Academy, Judith Selby teaches on cyber insurance and third-party cyber risk mitigation.
Timed agenda
| # | Topic | Minutes |
|---|---|---|
| 1 | Why Vendors Create a Unique Cybersecurity Threat | 59 |
| 2 | Key Policies and Practices That Can Help Reduce Vendor Risk | — |
| 3 | The Evolving Regulatory Landscape and Case Study | — |
| Total instructional time | 59 |
Self-submission by credit type
Legal Cyber Academy is not an accredited provider; the notes below explain how a learner may self-submitthis activity where their board permits. The pathways shown reflect this course’s subject matter. Always confirm your board’s current rules.
CLE (attorneys)up to 0.9 hr (60-min basis)
Many U.S. jurisdictions let an attorney apply for CLE credit for a non-accredited program (often called individual attorney or self-application). Use this certificate plus the course Information Sheet as your supporting documentation. Your state bar or CLE board decides whether credit is granted, how much, and any self-study cap.
CE / CPD (privacy, insurance, IT)up to 0.9 hr (60-min basis)
Where your professional body recognizes self-reported or self-directed learning (CPD) — for example many privacy (CIPP/CIPM) and security certifications — record this activity using the certificate and Information Sheet. Confirm your program's self-reporting rules and any documentation it requires.
Legal Cyber Academy is not an accredited continuing-education provider, and its courses are not pre-approved for CLE, CE, CME, or CPE credit. Each course provides a graded assessment, a verifiable Certificate of Completion, and a Continuing Education Information Sheet documenting instructional time, learning objectives, faculty, and a timed agenda — the records most licensing bodies require when a learner applies for self-submitted or self-study credit. Whether credit is granted, and how much, is determined solely by your licensing board. Confirm your board's rules before claiming credit. Verify certificates at https://www.legalcyberacademy.com/certificate/ <code>.