Continuing Education Information Sheet
Vendor Vulnerability: Navigating Data Breaches (Part 2 of 2)
- Provider
- Legal Cyber Academy · Lexeprint Inc.
13413 Granger Ave, Orlando, FL 32827
info@lawandforensics.com · https://www.lexeprint.com - Delivery method
- On-demand, self-study (online, recorded)
- Instructional time
- 1h 4m
- Assessment
- Graded multiple-choice exam · pass mark 70%
- Administered online, unproctored, with identity verified only to the level of a confirmed email address. Each sitting draws 10questions at random from the course’s pool, is timed, and is fixed for that sitting; correct answers are never disclosed. The pass mark is provider-set and is not supported by published reliability statistics or a standard-setting panel.
Equivalent credit hours
1.0 on a 60-minute basis (most CLE / general CE) · 1.2 on a 50-minute basis (NASBA CPE). Rounded down to the nearest tenth of an hour; your board may round differently.
Learning objectives
- Know what to ask third-party vendors when informed of a data breach
- Evaluate contracts and breach-notification clauses during a breach
- Draft preventative contractual provisions to reduce vendor risk
- Incorporate cybersecurity into corporate governance to reduce vendor cyber risk
Audience & prerequisites
Intended audience: Attorneys advising boards and managing law firms on third-party risk and liability.
Level: intermediate
Prerequisites: Part 1 of this two-part series recommended.
Faculty
Daniel B. Garrie, Founder, Law & Forensics; Neutral at JAMS; Faculty at Harvard
Law & Forensics LLC · JAMS · Harvard · Rutgers Law School · Journal of Law & Cyber Warfare
Daniel B. Garrie is the founder and executive managing partner of Law & Forensics LLC, a boutique cybersecurity and forensic engineering firm he co-founded in 2008. He serves as a neutral, arbitrator, and forensic special master at JAMS, focusing on cybersecurity, cryptocurrency, and complex technology disputes, and holds faculty appointments at Harvard and Rutgers Law School. A patented software inventor and prolific author, he is editor-in-chief of the Journal of Law & Cyber Warfare and a widely cited authority on computer forensics, eDiscovery, and cyber litigation.
Stacy Harrison, Partner, Orrick, Herrington & Sutcliffe LLP
Orrick, Herrington & Sutcliffe LLP
Stacy W. Harrison is a partner in the Los Angeles office of Orrick, Herrington & Sutcliffe, practising in complex litigation and dispute resolution and class action defense. She represents consumer product companies, financial institutions and energy companies in class actions and multidistrict litigation involving products liability and unfair competition, including Proposition 65 claims, and has served as lead trial counsel in asbestos-mesothelioma litigation. She co-authored the “Digital Forensic Investigations and E-Discovery” chapter of Orrick's Plugged In: Guidebook to Software and the Law, and was an Alternative Dispute Resolution Neutral for the Los Angeles County Superior Court from 2006 to 2010. She holds a J.D. from UCLA School of Law. At Legal Cyber Academy, Stacy Harrison teaches on vendor-related data breaches and the right of publicity in a technology-driven world.
Shawn Tuma, Partner and Cyber, Data, AI & Emerging Technology Practice Group Leader, Spencer Fane LLP
Shawn Tuma is a partner at Spencer Fane LLP, where he leads the firm's Cyber, Data, Artificial Intelligence and Emerging Technology practice group and serves as managing partner of the Plano, Texas office. He has practised in this area of law since 1999 and advises companies on artificial intelligence strategy and governance, cyber risk management, incident response coordination, the structuring and negotiation of AI-related contracts, and litigation involving cybersecurity and AI disputes. He is a past chair of the State Bar of Texas Computer and Technology Section and serves on the board of directors of the Cyber Future Foundation. He holds a J.D., magna cum laude, from Regent University School of Law, and is a Certified Information Privacy Professional (CIPP/US) and Certified Artificial Intelligence Governance Professional (AIGP). At Legal Cyber Academy he teaches on vendor-related data breaches.
Joseph Santiesteban, Partner, Orrick, Herrington & Sutcliffe LLP
Joseph Santiesteban is a partner in the Seattle office of Orrick, Herrington & Sutcliffe LLP, where he co-leads the firm's global Cyber, Privacy & Data Innovation group. He guides companies through the full lifecycle of a cybersecurity incident, including incident assessment, forensic investigation management, legal risk analysis, breach notification obligations, regulatory inquiries and related litigation. He holds a J.D. from the University of California, Berkeley School of Law, where he was editor-in-chief of the Berkeley Business Law Journal, and is admitted in Washington, Massachusetts and California. He was named to the 2024 Lawdragon 500 X Next Generation Rising Stars list. At Legal Cyber Academy, Joseph Santiesteban teaches on vendor-related data breaches and attorneys' ethical obligations after a data breach.
Brian Levine, Former EY-Parthenon Managing Director, Cybersecurity and Data Privacy, Ernst & Young LLP
Ernst & Young
Brian Levine is a cybersecurity and data privacy lawyer who served as EY-Parthenon Managing Director, Cybersecurity and Data Privacy at Ernst & Young LLP, leading a cybersecurity and data privacy team focused on the strategic application of security in the context of capital transactions, including mergers, acquisitions, divestitures and restructurings. He joined EY from the U.S. Department of Justice, where he served as the National Coordinator for more than 300 federal prosecutors focused on investigating and prosecuting computer crime and intellectual property crime, and served as a federal prosecutor and senior counsel with the DOJ's Computer Crime and Intellectual Property Section. Earlier he served as an Assistant Attorney General for the Internet & Technology Bureau of the New York Attorney General's Office. He earned his BA from the University of Pennsylvania and his JD from New York University School of Law. At Legal Cyber Academy, Brian Levine teaches on vendor and data breach risk, financial-sector cybersecurity, and cyber litigation trends.
Timed agenda
| # | Topic | Minutes |
|---|---|---|
| 1 | Questions to Ask When Informed of Vendor Data Breach | 64 |
| 2 | Steps to Understanding and Evaluating Contracts During Breaches | — |
| 3 | Ways to Reduce (Vendor) Cyber Risks | — |
| Total instructional time | 64 |
Self-submission by credit type
Legal Cyber Academy is not an accredited provider; the notes below explain how a learner may self-submitthis activity where their board permits. The pathways shown reflect this course’s subject matter. Always confirm your board’s current rules.
CLE (attorneys)up to 1.0 hr (60-min basis)
Many U.S. jurisdictions let an attorney apply for CLE credit for a non-accredited program (often called individual attorney or self-application). Use this certificate plus the course Information Sheet as your supporting documentation. Your state bar or CLE board decides whether credit is granted, how much, and any self-study cap.
CE / CPD (privacy, insurance, IT)up to 1.0 hr (60-min basis)
Where your professional body recognizes self-reported or self-directed learning (CPD) — for example many privacy (CIPP/CIPM) and security certifications — record this activity using the certificate and Information Sheet. Confirm your program's self-reporting rules and any documentation it requires.
Legal Cyber Academy is not an accredited continuing-education provider, and its courses are not pre-approved for CLE, CE, CME, or CPE credit. Each course provides a graded assessment, a verifiable Certificate of Completion, and a Continuing Education Information Sheet documenting instructional time, learning objectives, faculty, and a timed agenda — the records most licensing bodies require when a learner applies for self-submitted or self-study credit. Whether credit is granted, and how much, is determined solely by your licensing board. Confirm your board's rules before claiming credit. Verify certificates at https://www.legalcyberacademy.com/certificate/ <code>.