Edtechnolog
FeaturesLong read

Third-Party Risk Management for EdTech Vendors

Schools hand vendors kids' data but can't escape blame when breaches happen.

Senior Writer · · 11 min read
Cover illustration for “Third-Party Risk Management for EdTech Vendors”
Features · August 18, 2026 · 11 min read · 2,464 words

EdTech vendors have a strange job. Schools hand them the most sensitive data you can imagine (kids' names, grades, disability records, sometimes fingerprints or face scans), and a lot of these vendors are smaller and thinner on staff than the districts cutting them checks. That mismatch is the whole story of vendor risk in education right now. A school can hand off the data work, but it can't hand off the blame when things go wrong, so the scrutiny on vendors keeps climbing.

Here's the part that trips people up: there are vendors with signed contracts, and then there's a shadow tier with access to school systems but nothing on paper. A district might juggle 200-plus EdTech providers at once, and if you're one of them, any weak link anywhere in that chain becomes your problem too, even when you did everything right on your end.

How bad the breach environment actually is in education right now

The numbers are rough. Education ranked third in breach frequency across all industries in 2024, per IBM's Cost of a Data Breach Report, with an average cost of $3.65 million per breach, and that's not a typo, nor a fluke year.

More than half of U.S. school districts, 52%, had a cybersecurity incident in 2025, up 36% from the year before, according to Clever's K-12 identity platform. Higher ed isn't doing much better; Quorum Cyber tracked a 63% jump in cyberattack activity at colleges and universities from 2024 into 2025.

Web apps are the main way attackers get in, accounting for 71% of education breaches per the Verizon DBIR. Since most EdTech products are, at bottom, web apps, that stat points right at you. Ransomware volume climbed 23% in the first half of 2025 compared to the year before, with at least 130 known cases and ransom demands averaging north of $550,000.

Add it up and the picture is plain: attackers target this sector on purpose, they know it's underfunded relative to how valuable its data is, and they keep showing back up.

What recent landmark breaches reveal about where EdTech vendor security actually fails

Skip the theory and look at what actually happened.

PowerSchool, December 2024: an attacker got in with stolen credentials from a technical support subcontractor. That account had access to the customer support portal but no multi-factor authentication, and the breach sat there undetected for nine days before anyone noticed. Sixty-two million students and 9.5 million educators had their data exposed. PowerSchool sits in roughly 75% of the K-12 market, more than 18,000 schools across North America, with operations in over 90 countries. When a vendor is woven that deep into the system, one bad login turns into a sector-wide event overnight, and some districts even got hit with their own extortion demands afterward. The root failure was a missing MFA toggle on one subcontractor's account, and that was the whole thing.

Instructure, the company behind Canvas, had its own reckoning in spring 2026. A group calling itself ShinyHunters claimed it pulled 3.65 terabytes of data covering 275 million users across nearly 9,000 schools, and some in the industry called it the largest attack on education ever recorded. Instructure confirmed it reached some kind of agreement with the attackers, which raises its own separate question: how does a company handle the aftermath once the breach itself is old news?

There's also the Oracle E-Business Suite and PeopleSoft mess spanning 2025 into 2026. A zero-day vulnerability got exploited across more than 100 organizations, and 68% of those hit were in higher ed. UpGuard's 2026 analysis found 28% of the 100 most-used higher ed vendors have been breached since 2024. That's the supply chain cascade in motion: one flaw in a widely used enterprise system, and dozens of schools are cleaning up the same mess at the same time.

Illuminate Education is the fourth case, and the FTC went after it in December 2025. The agency said the company never put in place reasonable security measures to protect data belonging to more than 10 million students, and Illuminate reportedly waited almost two years to tell some districts, ones covering 380,000 students, that their data had been exposed. The FTC's remedy forced Illuminate to build a real security program and delete data it no longer needed. That enforcement outcome should worry vendors more than the breach itself did.

Notice the thread running through all four? None of this was clever hacking. Missing MFA, unmonitored subcontractor access, a notification delay measured in years, a security program regulators had to force into existence: these are operational failures, plain ones, the kind a decent audit catches if anyone actually looks.

The regulatory obligations EdTech vendors actually carry, and where they are commonly misread

FERPA gets misread constantly, even by vendors who think they've got it handled. Most vendors touch student data through the "school official" exception, and that requires an actual contract or formal policy designation, not a privacy policy sitting on a website somewhere. Plenty of consumer companies that expanded into schools never fixed this gap, since their privacy policy mentions education, but there's no contract holding it up.

Here's a myth worth killing: FERPA doesn't require schools to notify parents after a breach, only that the disclosure gets logged somewhere. Notification duties come from state law, not FERPA, and people mix the two up constantly, so vendors end up thinking they're covered when they've only handled half the job.

Federal attention has sharpened here too. In March 2025, the Department of Education required every state agency to certify FERPA compliance by April 30, 2025, an unprecedented move. Losing federal funding is the stated penalty for a FERPA violation, though it almost never actually happens; the reputational damage and canceled contracts show up long before any funding penalty would.

COPPA changed as well. The amended rule takes effect for compliance in April 2026, and it now requires covered operators to keep a written information-security program, run risk assessments at least yearly, and actually test their safeguards instead of just writing them down. Indefinite data retention is banned outright now, so if you're a vendor sitting on kids' data with no deletion schedule, that's a violation waiting to be found. The rule also now covers biometric identifiers by name: voiceprints, faceprints, gait patterns. If you build voice tutoring software, facial authentication, or remote proctoring tools, go read the new rule closely, because it almost certainly touches you now. Penalties run up to $53,088 per violation under the 2026 adjusted figure, and it's worth watching the COPPA 2.0 proposals, which would raise the covered age from under 13 to under 16. Even if COPPA doesn't touch you today, that could flip fast.

State law is its own patchwork. Twenty-one states have consumer data privacy laws on the books as of 2026, and a fair number single out children's or student data specifically. California's Privacy Protection Agency fined PlayOn Sports $1.1 million in March 2026, the first CPPA action aimed squarely at student privacy. PlayOn ran a digital ticketing platform used by roughly 1,400 California schools, and the violation was making students consent to tracking just to buy a ticket, then using that tracking data for ads. If you operate in multiple states, California is one hurdle among several, not the finish line.

How concentration and supply chain depth multiply a vendor's exposure

UpGuard mapped more than 105,000 vendor relationships across roughly 5,400 unique suppliers at 515 U.S. universities in its 2026 analysis. That's a huge web, and here's the twist: 31.9% of those vendors serve only one institution, yet plenty sit in sensitive spots like HR, finance, IT, and security. Single-use doesn't mean low-stakes.

Systemic vendors, the ones wired into hundreds or thousands of schools, get targeted precisely because of their reach. Breach one, and everyone downstream gets breached at the same moment, which is PowerSchool's whole story.

The subcontractor problem deserves its own callout. PowerSchool's breach didn't come from PowerSchool's own staff slipping up; it came from a technical support subcontractor, and your program is only as strong as what you actually demand from the vendors you hire, full stop. There's also a quieter risk buried in old data: several recent breaches hit former customers because their data was never wiped after the contract ended. Retention and offboarding are commitments you either keep or don't.

There's a shadow IT problem too, and it's your own version of the district's shadow vendor problem. If your internal team is quietly using unvetted storage tools, analytics platforms, or AI services, you've created access to institutional data the school can't see and can't audit. Institutions increasingly want proof that your whole supplier chain actually meets the standard you promised on paper, not just the parts they can see.

What a practical vendor-side TPRM program needs to cover

Start with an inventory. Map every sub-processor touching institutional data, split the ones under a formal agreement from the ones with informal or leftover access, and rank each one by data sensitivity and depth of access. A decent tiering system looks at what kind of data gets touched (student records, biometric data, financial info), how access got granted, and what that sub-processor's own audit history looks like.

Contracts need teeth. FERPA-compliant language has to flow down to anyone touching student data on your behalf; pointing to a privacy policy doesn't cut it. Spell out data use limits (no selling or reusing student data commercially, period), breach notification timelines, deletion requirements once the contract ends, and audit rights you can actually use, not just cite.

Security baselines shouldn't be aspirational. MFA on every support account and real access controls for subcontractors are the floor, not a feature you add later, and PowerSchool proved that one the hard way.

Data minimization matters more now than it used to. COPPA's amended rule bans holding data forever, and FERPA enforcement increasingly looks at what vendors are sitting on that they don't need for education purposes anymore. Retention schedules have to run operationally, tracked and deleted on a real timeline, not just typed into a policy doc nobody reopens, and offboarding needs verified deletion, both from your sub-processors and from institutional clients who leave.

Incident response readiness isn't optional at this point. Illuminate's near two-year delay in telling districts covering 380,000 students is the benchmark regulators now measure against, and not the good kind of benchmark, so build a documented, tested notification timeline before you need it. State breach laws often move faster than FERPA's own recording requirement, so if you operate across states, build one playbook around the strictest deadline you're subject to, and use it everywhere.

One more thing: stop relying on an annual questionnaire as your only monitoring tool. The Oracle zero-day showed how fast one vulnerability cascades across dozens of schools at once, so you need some form of ongoing monitoring, automated signals off your public-facing systems, so you find out about a problem in days, not nine months later.

How to prepare for and survive the institutional security audit

Institutions can't outsource their compliance consequences, and that's exactly why their audits keep getting sharper. Contract requirements are, in practice, the enforcement arm that reaches vendors long before any regulator shows up.

What do procurement teams and security reviewers actually ask for? A written information-security program, now legally required under amended COPPA for covered vendors, plus a current sub-processor list with the contract controls tied to each name. Breach notification procedures with real timelines and a record of past incidents, plus retention schedules with proof of deletion for clients who've left. Access controls, especially MFA and privileged access rules for support staff, matter here too, and some form of outside attestation, SOC 2 or ISO 27001, where the specific certification matters less than the fact that someone outside your building actually checked your work.

There's a real gap between filling out a questionnaire and handing over evidence. Institutions that have lived through a breach cascade, and plenty have by now, want evidence, not reassurance. A vendor who can hand over a current sub-processor list, signed contractual flow-downs, and a documented incident response timeline is standing in a different room entirely from the vendor who just talks about these things on a sales call.

Higher ed adds a wrinkle: buying decisions often happen at the department level, outside central IT, so your documentation needs to make sense to a department buyer today and to a CISO reviewing the same file eighteen months later. Single-use vendors, that 31.9% slice UpGuard identified, usually carry the thinnest documentation. Closing that gap makes you stand out fast, not because you tried especially hard, but because most of your competitors never bothered.

Renewals are re-audits, whether anyone labels them that or not. Treat every renewal as a chance to hand over fresh documentation before the school has to ask. Waiting to be asked is a bad look, and an avoidable one.

## The evidence a vendor needs to build and maintain institutional trust over time

Checking compliance boxes gets you in the door, but it doesn't get you the renewal, and it definitely doesn't get you the referral. In a market where 28% of frequently used higher ed vendors have been breached since 2024, ongoing, provable security practice is what separates the vendors who stick around from the ones who show up in next year's breach report.

What actually builds trust over time? Telling schools about security changes, new sub-processors, or incidents before they have to ask, and sending fresh security documentation every year, or more often, without making institutions chase you for it. How you handle a small incident says more about your competence than any answer on a security questionnaire ever will, and data discipline matters too, meaning you don't treat student data as raw material for your own commercial use. PlayOn Sports learned that lesson the expensive way, courtesy of the CPPA.

Concentration risk cuts both ways here, and it's worth sitting with for a second. Yes, a vendor wired into hundreds of schools carries more systemic risk, but that same reach gives a vendor room to actually lead: publishing practices, sharing what it learned from an incident, engaging seriously with frameworks like NIST and the Department of Education's guidance for EdTech vendors. That kind of leadership is a real market advantage, mostly because everyone else in the room is still figuring out where their own sub-processors even live.

At $3.65 million per average breach, and regulators moving faster every quarter, building a real program instead of the bare minimum stops being a compliance decision. It becomes a business one, and the vendors who make it through this decade are the ones institutions stop auditing out of suspicion and start pointing to as the standard everyone else gets held against.

More in Features