By
Sean O’Brien - Vice President of NET+ Services, Internet2
Estimated reading time: 4 minutes
WHAT YOU SHOULD KNOW
Navigating a complex cybersecurity event is never easy, but one of the Internet2 NET+ program’s greatest strengths is bringing institutions together at scale. Through the program’s advisory groups, the 186 institutions participating in the NET+ Instructure Canvas program have a collective voice as Internet2 works closely with Instructure to move from immediate response to sustained action following the May 2026 security incident. That work includes tracking remediation, advancing contract protections, and strengthening long-term resilience.
When the Instructure security incident surfaced in May, subscribing institutions faced many of the same questions: What was exposed? What do we tell faculty and staff? How quickly will Instructure respond? And what needs to change to strengthen coordination and rebuild trust?
Redefining Program Governance: The EAG and SAG in Action
In direct response to community feedback calling for stronger, more strategic coordination, the NET+ Instructure Canvas program convened the NET+ Instructure Canvas Service Advisory Group (SAG) within days, working alongside Instructure to address immediate remediation and coordinate the response across subscribing institutions. That work quickly extended beyond technical remediation to include contract enhancements, business continuity planning, and broader questions about how higher education institutions could have a stronger voice in the program.
As part of that response, the program established the NET+ Instructure Executive Advisory Group (EAG), bringing CIOs and CISOs from subscribing institutions into direct, strategic conversations with Instructure executive leadership. The EAG provides executive-level oversight of program strategy, priorities, and escalation paths, while the SAG continues the hands-on work, meeting repeatedly throughout the quarter to track remediation, review NET+ contract enhancements, and coordinate business continuity efforts.
Together, the EAG and SAG give the NET+ Instructure Canvas community stronger channels to elevate institutional priorities, engage directly with Instructure leadership, and escalate critical concerns. One of the first areas of focus was identifying contract changes that would provide stronger protections for participating institutions.
Turning Community Priorities into Contract Updates
Those contract enhancements are now in negotiation. The combined scale of the NET+ Instructure Canvas program gives institutions a stronger collective voice, and the proposed amendment reflects lessons learned from the May incident. It focuses on three areas of contractual protection identified as particularly important by participating institutions:
- Clearer exit rights. Proposed termination provisions tied to objective remediation and performance standards.
- Stronger availability commitments. Service credits when monthly availability targets are not met.
- Specific breach notification. A clearer timeframe for notifications following discovery.
A contract amendment is in progress, with Advisory Group review targeted for later this year.
Security Remediation Progress: 21 of 47 Items Complete
Of the 47 security hardening items on the SAG remediation roadmap, 21 are complete as of the time of this blog’s publication. The full remediation tracker, including the 26 items still in progress, is available to subscribers upon request. We’re highlighting several of the completed items that may be of particular interest to security teams:
- Comprehensive penetration testing: Instructure completed three penetration tests in 2026, incorporating AI-assisted white-box and traditional testing methodologies.
- Granular forensic data delivery: Affected institutions received row-level forensic data, enabling local security teams to conduct their own risk assessments.
- Stronger support access controls: Additional multifactor authentication requirements and enhanced audit logging to strengthen controls around sensitive support access and actions.
- CrowdStrike integration: A custom connector to support enhanced endpoint security monitoring for institutions using CrowdStrike is now available.
Helping institutional Readiness: Business Continuity Playbooks
Building on lessons learned from the security incident, the SAG expanded its focus to Business Continuity Planning (BCP), examining how institutions can better prepare for and respond to disruptions involving critical technology providers. The group identified practices that can strengthen institutional continuity and incident response, from breach notification expectations to broader vendor risk planning. This work builds on the emergency SAG calls, subscriber communications, and cross-institutional coordination Internet2 organized in the immediate aftermath of the incident, reflecting a shift from urgent response toward longer-term resilience.
In parallel, Instructure developed business continuity playbooks designed to help institutions prepare for potential disruptions to their education technology ecosystem.
“Institutions don’t get a pause button during finals week,” said Melissa Loble, chief academic officer at Instructure, speaking to the impact outages can have during critical academic periods.
“A lesson learned from the incident is that we have an opportunity to help campus teams think through what happens if something goes down in their education technology ecosystem, well before it does,” Loble continued. “These playbooks give them a concrete place to start, and our Instructure account teams are ready to work through them with you.”
The playbooks are available to institutions through their Instructure customer success managers. The SAG will continue its business continuity work throughout the fall, using lessons from the incident to identify additional opportunities to strengthen institutional preparedness and resilience.
Upcoming: Technical Deep-Dive Webinar with Instructure’s Chief Architect
As the next step in this ongoing work, CISOs, security analysts, Canvas administrators, and central IT staff are invited to join Instructure’s chief architect, Zach Pendleton, on September 22 at 3:00 pm EDT for a transparent discussion and closer look at recently implemented administrative controls, new support access requirements, audit logging, and related technical integrations. The session will be followed by a live Q&A.
This virtual event is open to NET+ Instructure Canvas subscribers. If you are not on the distribution list and are interested in attending, you may email us at netplus@internet2.edu.
Stay Up to Date with NET+
The work following the Instructure security incident demonstrates the value of the NET+ model: institutions do not have to navigate complex vendor challenges alone. In the immediate aftermath, Internet2 focused on rapid information sharing and direct engagement with Instructure leadership.
In the months since, the work has been sustained: tracking commitments, advancing contractual protections, strengthening governance, and examining long-term resilience. Through NET+, participating institutions can bring their collective expertise, experience, and priorities forward with a stronger voice. The NET+ Instructure community will continue building on this work through sustained oversight, collaboration, and shared learning.
For questions about the security event, ongoing security remediation efforts, or NET+ Instructure program operations, please contact netplus@internet2.edu.
Contact NET+
About the Author(s)
Sean O’Brien leads Internet2’s strategy to help research and higher education institutions adopt and use cloud and emerging technologies effectively. He oversees the NET+ portfolio, including engagement with technology providers, service evaluations, communities of practice, and data and benchmarking capabilities. He is active across the research and higher education technology community and has held advisory and community leadership roles. He recently served as Expert-in-Residence at the University of Mary Washington’s Center for AI and the Liberal Arts.