Ultimately, it highlights the trade-off in risks that often occurs when procuring technology services and the need for robust, proactive risk management. In the case of the Online SCR incident, it was the platform’s own software supplier Intradev that was hit by the cyber-attack. Maturely accepting and managing vendor risk means:Involving Data Protection Officers (DPOs) from the outsetSchools should always assess data risks and conduct vendor due diligence before entering into contracts. Your DPO should be involved from the very beginning of any tech procurement exercise to help to bring a focus on data protection risks. The Online SCR incident should be a wake-up call for the entire education sector.