Resources

Vendor Concentration Risk & SPOF: Mapping Critical Dependencies

How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.

TL;DR

A vendor SPOF is a third party whose failure alone halts a critical activity, with no fallback. You do not find it by assessing vendors one by one: you have to cross the activities × vendors matrix, look for third parties spanning several critical activities, and document second-tier dependencies. DORA makes this analysis mandatory for the financial sector.

What is a vendor SPOF?

Most vendor risk management approaches assess each third party individually: its security maturity, its certifications, its questionnaire answers. This approach, while necessary, misses a risk of a different nature: concentration. An organization can have ten vendors individually judged solid, and discover that all of them, behind the scenes, depend on the same cloud host, the same payment subcontractor, or the same geographic region exposed to the same climate or geopolitical risk.

A vendor single point of failure (SPOF) occurs precisely when a critical business activity — or several — relies on a single third party, with no fallback identified, tested, or even considered. When that third party goes down, the activity goes down with it, immediately, with no room to maneuver.

This type of risk is structurally invisible until it has been explicitly mapped. It doesn't show up in a standard vendor register — it only appears once you cross-reference vendors with the business activities they support, and look for patterns of repetition and excessive dependency.

Why does concentration stay a blind spot?

The vendor register and the business process map live in different tools. Procurement knows the list of vendor contracts. The business knows its critical processes. Rarely are the two connected in a single reference that can answer: "if this vendor goes down, which activities stop, and are there others in the same situation?"

Second-tier dependency escapes the analysis. A direct vendor may look diversified from your point of view, while itself depending on a subcontractor shared with several of your other vendors. This "fourth-party" dependency stays entirely invisible without an active multi-tier mapping effort — a topic significant enough to deserve its own treatment.

The incident is often the first revealer. In many post-mortems, discovering excessive risk concentration happens after the fact — the moment an incident at a vendor reveals that three supposedly independent activities stopped simultaneously, or that the planned continuity fallback relied on a backup vendor that itself depended on the same compromised third party.

No global resilience view blocks prioritization. Without a consolidated concentration indicator, it's impossible for a CISO or risk manager to objectively decide where to invest first: diversification, continuity planning, or negotiating stronger contractual SLAs.

How do you map the structure, not just the vendors?

Managing vendor concentration risk relies on principles now formalized by the most demanding frameworks — notably DORA for the financial sector, which explicitly requires a concentration matrix and a register of critical ICT third-party providers (CTPP).

1. Model business activities as first-class entities. Before mapping vendors, you need to map what matters: critical business processes, their owner, their criticality level, and their planned continuity approach. Without this foundation, vendor mapping stays disconnected from reality.

2. Explicitly link every vendor to every activity it supports. This activities × vendors matrix is the core of concentration analysis. It alone can answer the central question: which vendors appear across the largest number of critical activities?

3. Identify activities with no fallback. An activity that relies on a single vendor, with no alternative identified or tested, is a SPOF by definition — regardless of that vendor's security quality.

4. Analyze structure beyond the first tier. A mature mapping effort tries to document, at least for the most critical vendors, their own significant dependencies (subcontractors, hosts), to reveal second-tier concentration.

5. Overlay risk level onto the map. Once the structure is known, you also need to visualize where identified risks sit (vulnerabilities, compliance gaps, past incidents) to distinguish a "robust" SPOF from a "fragile" one — the latter calling for immediate action.

6. Calculate a global resilience indicator and track it over time. A consolidated indicator (number of SPOFs, average concentration level, trend) lets you measure progress on a diversification or hardening plan, and present it to the leadership team.

Types of vendor concentration and the signal that reveals them
Type of concentrationExampleHow to detect itPossible treatment
Single vendor on one activityOnly one payroll providerActivities × vendors matrixQualified fallback vendor
Vendor across many activitiesOne publisher across five processesActivity count per third partyContractual continuity plan
Technology concentrationDistinct vendors, same hostSubcontractor disclosureMulti-region requirement
Geographic concentrationProviders in one regionDeclared data locationGeographic diversification
Skills concentrationOnly one integrator knows the toolKnowledge dependency reviewDocumentation, reversibility

How does CISAPP reveal concentration risk?

CISAPP was built to make this structural analysis accessible without requiring a dedicated data team.

A native model linking activities and vendors. Business activities (scopes) are a first-class entity in CISAPP, with criticality, business owner, and documented continuity plan. Every vendor is linked to the activities it supports through a native dependency matrix — the structure exists from data entry, it doesn't need to be reconstructed afterward.

A dependency map dedicated to concentration. The mapping and exposure module (/exposition/dependency-map, /exposition/concentration) offers a dedicated "concentration" view: activities with no fallback, subjects shared across multiple critical activities, and an automatically calculated global resilience indicator. The question "which vendors touch the most critical activities?" gets a direct, filterable answer, exportable to PDF for a leadership committee.

An overlaid risk matrix. The risk matrix view lets you visualize risk levels by subject and activity, instantly revealing SPOFs that also carry a high risk level — priorities emerge naturally instead of being guessed at.

A risk register that turns findings into an action plan. Once excessive concentration is identified, it can be formalized as a standalone risk in the register (EBIOS RM-inspired wizard), with treatment measures, an owner, and a deadline — vendor diversification, negotiating a contractual continuity plan, or qualifying a backup vendor.

An organization usually discovers its vendor concentration risk at the worst possible moment — during the incident. CISAPP makes it visible beforehand, by natively linking vendors, activities, and risks in one register, turning a blind spot into a managed priority.

FAQ

A Single Point of Failure vendor is a third party whose unavailability or compromise would, on its own, halt one or more critical business activities, with no immediate fallback in place.

Sources

  1. Regulation (EU) 2022/2554 (DORA) — concentration risk and register of information — EUR-Lex, 2022-12-14

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account