Lessons from the Canvas cyberattack


CISOs must reconsider how vendor risk is evaluated. Historically, many third-party risk programs focused heavily on compliance artifacts such as SOC reports, ISO certifications, penetration testing summaries and questionnaire-based responses. While these remain useful, the Canvas incident demonstrates that such controls alone do not guarantee operational security and resilience. Organizations must begin evaluating vendors not only on preventive security controls, but also on their incident response maturity, crisis communications capabilities, architectural resilience, data segmentation strategies, recovery timelines and executive transparency.

As I researched Instructure for this article, I found an impressive website, the Instructure Trust Center. The site displays eleven compliance “badges” – SOC 2 Type 2, SOC 3, PCI, ISO 27001, GDPR, etc. The site also provides access to 74 compliance-supporting documents and 57 FAQ items. To illustrate an earlier point about organizations focusing on primary product offerings rather than risks associated with secondary products and services, I accessed and reviewed Instructure’s ISO 27001 certificate, which is current and expires October 15, 2027.

The certificate states that “The scope of this ISO/IEC 27001:2022 certificate includes Instructure’s products, teams and ISMS managed at its HQ location in Salt Lake City, UT, USA. The in-scope people, processes, technology and locations are defined within the Instructure Scope of the Information Security Management System (ISMS), dated August 1, 2025, and the Statement of Applicability, dated April 16, 2025. The scope of the ISMS implemented by Instructure includes the following elements:

Leave a Reply

Your email address will not be published. Required fields are marked *