IAPP Privacy. Security. Risk. + AI Governance Global 2026
SEATTLE
6-9 October
Whose Breach is it Anyway? Untangling Third-Party Incident Chaos
Wednesday, 7 Oct.
13:30 - 17:00 EDT
Intermediate level
Third-party vendor incidents are everywhere: from the 2023 MOVEit supply-chain catastrophe that rippled through thousands of organizations to the 2025 Salesloft/Drift OAuth compromise that exposed hundreds of Salesforce environments and downstream customers. Yet organizations still struggle with who discloses, who pays, and who owns the narrative. Whose Breach Is It Anyway? turns breach response into an interactive experience with games like Risk Roulette, Media Statement Mad Libs, Clause or Chaos, and the live countdown Is It Material? Attendees will laugh, compete, and walk away with practical, cross-functional strategies for legal, comms, and operational readiness in the age of cascading third-party breaches.
What you will learn:
- How legal liability, regulatory duty, and public perception diverge during third-party incidents.
- How specific contract language can make or break incident timelines and obligations.
- Practical frameworks for coordinated comms, legal, and ops response when vendor breaches hit.
Additional registration fee required.
Moderator and speakers

Frances Faircloth
Partner, Data, Privacy and Cybersecurity
Ropes & Gray

Kelly Miller
Managing Director, Cybersecurity and Data Privacy Communications
FTI Consulting