IAPP Privacy. Security. Risk. + AI Governance Global 2026

SEATTLE

6-9 October

Back to conference agenda

Whose Breach is it Anyway? Untangling Third-Party Incident Chaos

Wednesday, 7 Oct.

13:30 - 17:00 EDT

Intermediate level

WORKSHOPPRIVACYDATA SECURITYINCIDENT MANAGEMENTLAW AND REGULATIONSTRATEGY AND GOVERNANCEU.S. STATE REGULATIONPROFESSIONAL SERVICESTECHNOLOGYHEALTH CARE

Third-party vendor incidents are everywhere: from the 2023 MOVEit supply-chain catastrophe that rippled through thousands of organizations to the 2025 Salesloft/Drift OAuth compromise that exposed hundreds of Salesforce environments and downstream customers. Yet organizations still struggle with who discloses, who pays, and who owns the narrative. Whose Breach Is It Anyway? turns breach response into an interactive experience with games like Risk Roulette, Media Statement Mad Libs, Clause or Chaos, and the live countdown Is It Material? Attendees will laugh, compete, and walk away with practical, cross-functional strategies for legal, comms, and operational readiness in the age of cascading third-party breaches.

What you will learn:

  • How legal liability, regulatory duty, and public perception diverge during third-party incidents.
  • How specific contract language can make or break incident timelines and obligations.
  • Practical frameworks for coordinated comms, legal, and ops response when vendor breaches hit.

Additional registration fee required.

Moderator and speakers

headshot of Frances Faircloth

Frances Faircloth

Partner, Data, Privacy and Cybersecurity

Ropes & Gray

generic profile silhouette

Kelly Miller

Managing Director, Cybersecurity and Data Privacy Communications

FTI Consulting