In the News: Lauren Godfrey Examines Third-Party Vendor Cyber Risks in The Legal Intelligencer
Constangy Cyber Team partner Lauren Godfrey authored an article for The Legal Intelligencer examining the growing risks businesses face from third‑party vendor cyber incidents and outlining steps organizations should take to strengthen their vendor management programs.
Lauren highlighted that digital economy relies heavily on vendors for cloud services, IT infrastructure, software, data processing and security. While these partnerships provide efficiency and expertise, they also create significant exposure when a vendor suffers a cyberattack. Such incidents can cause business interruption, revenue loss, reputational harm, remediation costs and potential liability for compromised personal information.
Several major vendor‑related incidents from 2025 including ransomware affecting Ingram Micro, data breaches impacting Oracle Health and Oracle’s legacy cloud environment and unauthorized access to SonicWall firewall backups to demonstrate how third‑party compromises create widespread downstream disruption for client organizations.
“Dealing with the fallout from vendor cyberattacks can be time-consuming and costly,” suggested Lauren. “Taking proactive steps to bolster your vendor management program can yield significant rewards in business continuity, resiliency, reputation and customer satisfaction.”
To read the full article, click here.
Lauren D. Godfrey is a partner and member of Constangy's Cyber Team, who holds the CIPP/US and CIPP/E credentials and guides clients through data security incidents; helps them develop privacy, incident response and information security policies, as well as comprehensive governance and response plans; reviews contracts for privacy law compliance; assesses notification obligations; and assists with external communications.