Supply chain
Making fourth parties and concentration risks visible
Many seemingly independent providers depend on the same cloud, identity, network or software services.
8 minute read · Content as of 21.07.2026
Subcontractors create new nodes in the risk chain
Transparency should focus on the parts of the supply chain that affect the specific service, relevant data or recovery objectives. A bare list of all subcontractors without role and region helps little.
Concentration is a portfolio risk
The critical dependency often only becomes visible when relationships are viewed together. Several SaaS providers may use the same hyperscaler, DNS service or identity provider.
- record critical fourth parties per service
- aggregate shared platforms and regions
- test outage and exit scenarios across the portfolio
- have top management accept deliberate risk concentration
Sources used
- Directive (EU) 2022/2555 – NIS2 · EU · 2022
- ISO/IEC 27036-3:2023 – Supply chain security · ISO · 2023
- BSI Standard 200-4 Business Continuity Management · BSI · 2023
- Vendor, due diligence and exit patterns · KaitoSec