Free is Not Really Free
HigherEdRisk Editorial
<p>Institutions are becoming increasingly reliant on third-party vendors. The risk is escalating. Combine this with cyber risk, and you have an even more heightened risk exposure. </p><p>The cyber attack on Instructure underscores the importance of this risk. I am not going to rehash what the news has already reported, but let's think about this: Instructure, which owns Canvas, is one of the nation's most popular learning management systems, used by 41% of higher education institutions across North America. The hackers claimed the attack affected nearly 9,000 schools worldwide and would compromise the personally identifiable information of 275 million people, including students, teachers, and staff. The risk is clear: third-party risk is real and will impact even the most sophisticated vendors and well-prepared schools. The 2024 Crowdstrike outage taught us that!</p><h3>"Freemium" is a Risk</h3><p>As I researched the breach, I found articles stating that the hackers used "Free-For-Teacher" (FFT) accounts to access the system. Freemium features on enterprise platforms tend to be underexamined risks. Most vendor security questionnaires focus on the core product. A free tier sitting on shared infrastructure, with lighter identity verification and its own support system, is rarely assessed separately, even though it may share backend access. The assumption that open access and light verification constitute an acceptable trade-off for convenience is a very big risk! </p><p>Therefore, the key risk management failure in this breach is related to insufficient tenant isolation. The FFT environment was designed for individual, unverified, low-stakes users, but it had pathways into data belonging to paying institutional customers. This is a classic architecture risk: a low-security front door connected to a high-value back room. </p><h3>A Pattern Emerges</h3><p>And here is the part that I did not recall. The hackers "ShinyHunters" apparently hit Instructure in 2025, hit Infini