IAPP Privacy. Security. Risk. + AI Governance Global 2026
SEATTLE
6-9 October
It is Not Your System but It is Still Your Incident: Supply Chain Cyber Exercise
Friday, 9 Oct.
11:15 - 12:15 EDT
Intermediate level
Modern incidents rarely stay inside your four walls. From compromised SaaS integrations to network infrastructure attacks, today’s most disruptive breaches often originate in the supply chain, forcing companies to respond inside environments they do not control and alongside teams they have never exercised with. This interactive tabletop exercise, led by senior leaders blending technical and legal incident response experience, walks participants through a realistic supply chain attack ripped straight from the headlines. Attendees will navigate the legal, technical, reputational and operational challenges that arise when data, access and control sit with a vendor, not your enterprise.
What you will learn:
- Actionable approaches to strengthening supply chain security posture and updating incident response playbooks to reflect today’s interconnected risk landscape.
- Coordination strategies across legal, security, procurement and business teams.
- Solutions for common breakdowns in ownership and decision making.
- Regulator expectations and evolving customer expectations for mitigating risk in supply chain incidents.
Moderator and speakers

Christopher Hale
CIPP/E, CIPP/US, CIPM, FIP
Senior Director and Associate General Counsel
Cisco

Phil Kealy
Head of US West Incident Response, Mandiant Consulting

Katherine McDaniel
CIPP/US
Director, Cyber Legal
T-Mobile

Joseph Santiesteban
Partner
Orrick, Herrington & Sutcliffe