Legal Cyber Academy

Navigating Data Breaches: Vendor Risks

Cyber Incidents· PremiumLevel: Intermediate

Overview of Navigating Data Breaches: Vendor Risks

Third-party vendors are among the most common entry points for data breaches, yet many organizations lack the contractual and operational frameworks needed to manage that exposure effectively. This course examines how service providers, cloud platforms, and other external partners can create legal and regulatory liability for the businesses that engage them. Participants will work through practical approaches to vendor risk assessment, contract review, and policy development that align with current regulatory expectations. The course also addresses the evolving litigation and enforcement landscape, helping legal advisors and their clients understand what is at stake when a vendor-side breach occurs.

What you’ll learn in Navigating Data Breaches: Vendor Risks

  • Identify the primary ways third-party vendors introduce data breach risk to an organization's operations
  • Evaluate vendor contracts for key provisions related to data security, breach notification, and liability allocation
  • Apply a practical framework for assessing and prioritizing vendor risk across different categories of service providers
  • Explain the regulatory obligations that arise when a data breach originates from a third-party vendor
  • Develop internal policies and due diligence processes that support ongoing vendor risk management
  • Recognize the current litigation trends and enforcement actions shaping third-party data breach accountability

Audience and prerequisites

Who should take this courseNavigating Data Breaches: Vendor Risks

Legal advisors, executives, and CISOs and security teams who are responsible for managing vendor relationships, negotiating contracts, or advising organizations on data breach liability and regulatory compliance.

Prerequisites for Navigating Data Breaches: Vendor Risks

No technical background required — the course is designed for legal professionals and business leaders with general familiarity with data privacy and contracting concepts.

Curriculum

  1. 1. The Lawyers Guide to Navigating Data Breaches: Vendor Risks Part 1 of 2

    In part one (1) of this course, our expert panelists begin by explaining what data breaches are and how they happen. Our speakers then give an overview of the data breach risks that third-party vendors pose. Together, our speakers discuss the policies that businesses should establish across management policies and procedures. Our panelists conclude by assessing the current legal landscape and recent litigations regarding third-party vendor data breaches. Topics covered in this webinar: Data Breaches 101 Data Breach Risks from Third-Party Vendors Policies to Reduce Vendor Cyber Risks Regulatory Landscape and Recent Litigation

    Video coming soon
  2. 2. The Lawyers Guide to Navigating Data Breaches: Vendor Risks Part 2 of 2

    In part two (2) of this webinar, our expert panelists begin by discussing the questions organizations should ask third-party vendors when informed of a data breach. Next, our speakers break down the steps to understanding and evaluating contracts during breaches, as well as reviewing breach notification clauses and author preventative contractual provisions. Finally, they provide some of the key elements to prevent vendor risks, sharing their expert opinions to highlight the value of incorporating cybersecurity practices into corporate governance and culture, as well as taking rigorous preventative measures. Topics covered in this webinar: Questions to Ask When Informed of Vendor Data Breach Steps to Understanding and Evaluating Contracts During Breaches Ways to Reduce (Vendor) Cyb

    Video coming soon