The defining disruptions of recent years began in a vendor's data centre, not inside the victim's perimeter: one shared platform, many organisations, simultaneous impact. We map, assure, contract and exercise the extended enterprise so a supplier's failure stops being your crisis.
Supply chain security is the discipline of managing the risk an organisation inherits from its suppliers, service providers and the platforms it shares with others: mapping the extended enterprise and its concentration points, assuring critical providers against recognised standards, embedding resilience obligations into contracts, and exercising joint behaviour under disruption, aligned to ISO 28000 and the supply chain duties of NIS2 and DORA.
Digital concentration has quietly rewritten the risk landscape. Shared platforms, dominant software vendors and outsourced operations deliver enormous efficiency, but they concentrate operational risk into single points of failure whose compromise is felt simultaneously across every organisation that depends on them. Efficiency and fragility are purchased with the same coin, and the seam between you and your provider, who decides, who communicates, who recovers first, is typically governed by a contract that says a great deal about performance on a normal day and almost nothing about behaviour in a crisis.
Regulation has caught up. NIS2 Article 21 names supply chain security among its mandatory measures, DORA devotes an entire pillar to ICT third party risk with direct oversight of critical providers, and sector regimes from aviation's Part-IS to the Swiss ISG expect the dependency to be governed, not assumed. Our practice makes that governable: the same discipline that anchors the provider extension of our DAEDALUS framework, applied to any sector.
Vendor management governs the commercial relationship: performance, service levels and spend. Supply chain security governs the inherited risk: what happens to your operation when the provider fails, is compromised or is held to ransom. The first is procurement; the second is resilience, and the recent disruption record shows which one was missing.
Article 21 names supply chain security, including the security related aspects of relationships with direct suppliers and service providers, among the mandatory risk management measures. Entities are expected to assess provider vulnerabilities and overall quality, and supervisors increasingly ask for the evidence.
As one of its five pillars: a register of ICT third party arrangements, mandatory contractual provisions, concentration risk assessment, monitoring and exit strategies, with critical ICT providers subject to direct European oversight. Our third party workstream builds exactly that evidence base.
The share of your operation carried by a single provider, platform or location. It is what turned one vendor's ransomware incident into simultaneous manual operations at four major airports: many organisations, one dependency, one failure. Concentration is measured, then either engineered down or wrapped in a rehearsed fallback.
They must be. A continuity plan whose critical steps are performed by a provider who has never rehearsed them with you is an assumption. We design joint scenarios with your critical providers, from tabletop to functional, so the seam is tested with the people who own the other side of it.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Ask us for an extended enterprise mapping; the single points of failure outside your perimeter will be more revealing than anything inside it.
Book a consultation