
Governance & Vendor Risk
Why School Boards Need a Vendor Risk Register, Not Just an IT Team
The modern school does not run on one platform. It runs on a web of vendors, agencies, apps, integrations, and cloud providers. If leadership cannot see that web, leadership cannot govern the risk.
Schools often talk about cyber risk as if it sits inside the technology department. In reality, many of the biggest exposures sit outside the school's direct control: website developers, edtech platforms, payment providers, communications tools, identity integrations, cloud hosts, and analytics vendors. The recent Vercel incident and the recent Victorian schools incident both underline the same point from different angles: the school may feel the impact even when the failure starts elsewhere.
That is why every school board should insist on a vendor risk register. This does not need to be a huge enterprise document. At minimum, it should show which vendors are critical, what school data they handle, where services are hosted, what authentication model they rely on, which integrations they use, and who inside the school owns the relationship. Without that map, schools struggle to answer even basic questions during an incident.
The education privacy community has been saying this for years. The U.S. Department of Education's student privacy resources include guidance aimed at education technology vendors and stress that third-party providers handling student information need appropriate controls and accountability. The governance implication for schools is obvious: if a vendor touches student information or school identities, it belongs in an active oversight process, not just in procurement paperwork.
A board-level vendor register also improves incident response. When a breach hits the news, leadership can quickly ask the right questions: do we use this provider directly, do any of our vendors use it, what data could be affected, which secrets or integrations are in scope, and who is coordinating our response? Without a register, those questions are often answered too late and through fragmented email chains.
The right register does not make cyber risk disappear. It makes it visible and governable. For schools that now depend on a growing ecosystem of apps and vendors, that visibility is no longer optional.
