CIO Brief: Third-Party Ransomware and Your Disclosure Obligations
Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.
The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers had to notify their own donors and students. Years later, regulators penalized Blackbaud for misleading disclosures.
Why a vendor's ransomware is your incident
When a vendor holding your data is breached, your obligations don't disappear. You may need to notify the people affected, answer regulators and handle the reputational fallout — often with incomplete information from the vendor.
The business impact
- Notification costs and staff time.
- Reputational damage with customers, donors or patients.
- Regulatory exposure, especially in healthcare, education and finance.
- Uncertainty, when the vendor's account of events changes.
Questions to ask your team
- Which vendors hold our most sensitive data?
- What do our contracts require them to tell us, and how quickly?
- Do we have a plan to notify affected people if a vendor is breached?
- Could we reduce the data we share with them?
What good looks like
A ranked list of high-risk vendors, strong contract terms, minimal data shared, and a ready-to-use vendor breach response plan.
The decision
Ask legal and IT to run a short exercise: "Our largest data vendor announces a ransomware attack today." The gaps it reveals are usually inexpensive to fix in advance.
- Blackbaud Ransomware (July 2020): When Your SaaS Provider Pays the Ransom Incident Teardowns
- How to Assess SaaS Vendors' Security Before You Sign How-To & Hardening
- Monitoring Third-Party SaaS Risk Signals and Breach Notifications Detection & Response