Manage cookies
This site uses cookies to collect information about your browsing activities in order to provide you with more relevant content and promotional materials, and help us understand your interests and enhance the site. Visit our cookie policy to learn more.
Manage cookies
Cookie Settings
Cookies necessary for the correct operation of the site are always enabled.
Other cookies are configurable.
Essential cookies
Always On. These cookies are essential so that you can use the website and use its functions. They cannot be turned off. They're set in response to requests made by you, such as setting your privacy preferences, logging in or filling in forms.
Analytics cookies
Disabled
These cookies collect information to help us understand how our Websites are being used or how effective our marketing campaigns are, or to help us customise our Websites for you. See a list of the analytics cookies we use here.
Advertising cookies
Disabled
These cookies provide advertising companies with information about your online activity to help them deliver more relevant online advertising to you or to limit how many times you see an ad. This information may be shared with other advertising companies. See a list of the advertising cookies we use here.
Supply Chain Security and Third Party Risk Consulting | Resilience Guard
Supply chain and third party security

Your resilience is hostage to suppliers you have never audited.

The defining disruptions of recent years began in a vendor's data centre, not inside the victim's perimeter: one shared platform, many organisations, simultaneous impact. We map, assure, contract and exercise the extended enterprise so a supplier's failure stops being your crisis.

The service

What is supply chain security?

Supply chain security is the discipline of managing the risk an organisation inherits from its suppliers, service providers and the platforms it shares with others: mapping the extended enterprise and its concentration points, assuring critical providers against recognised standards, embedding resilience obligations into contracts, and exercising joint behaviour under disruption, aligned to ISO 28000 and the supply chain duties of NIS2 and DORA.

Digital concentration has quietly rewritten the risk landscape. Shared platforms, dominant software vendors and outsourced operations deliver enormous efficiency, but they concentrate operational risk into single points of failure whose compromise is felt simultaneously across every organisation that depends on them. Efficiency and fragility are purchased with the same coin, and the seam between you and your provider, who decides, who communicates, who recovers first, is typically governed by a contract that says a great deal about performance on a normal day and almost nothing about behaviour in a crisis.

Regulation has caught up. NIS2 Article 21 names supply chain security among its mandatory measures, DORA devotes an entire pillar to ICT third party risk with direct oversight of critical providers, and sector regimes from aviation's Part-IS to the Swiss ISG expect the dependency to be governed, not assumed. Our practice makes that governable: the same discipline that anchors the provider extension of our DAEDALUS framework, applied to any sector.

Anchors
ISO 28000, ISO 27001
Regimes
NIS2 Art. 21, DORA pillar 4
Focus
Concentration and seams
Proven by
Joint exercises
ONE SUPPLIER, MANY VICTIMS: THE BLAST RADIUSSharedsupplierYour organisationSimultaneous, identical impactPeer organisationSimultaneous, identical impactPeer organisationSimultaneous, identical impactConcentration: one platform, many dependantsEfficiency and fragility are purchased with the same coin: shared platforms concentrate risk into single points of failure.
The blast radius: a single shared supplier failing simultaneously across every organisation that depends on it, the defining disruption pattern of recent years.
What we deliver

From vendor list to governed dependency

Extended enterprise mapping. The suppliers, platforms, utilities and fourth parties your critical operations actually stand on, including the cross boundary single points of failure a conventional register misses, tiered by criticality and concentration.
Concentration risk analysis. Where a single provider, platform or region carries an unacceptable share of your operation, assessed through the 7A exposure and confidence lens, with engineered redundancy or rehearsed fallback where the concentration cannot be unwound.
Provider assurance. Critical suppliers assessed against the recognised standard for their function, security posture, recovery capability, segmentation that bounds the blast radius, with the evidence feeding your own risk picture rather than filed in procurement.
Contractual resilience. Resilience obligations written into the relationship: incident notification duties aligned to your regulatory clocks, recovery commitments, audit and exercise rights, exit and substitution strategies for the day the provider itself is the casualty.
Exercising the seam. Joint scenarios in which you and your critical providers respond together, because the boundary between organisations is where disruptions win and the only place a plan for it can be tested. Delivered through our exercise programmes.
Questions

Frequently asked questions

What is the difference between supply chain security and vendor management?+

Vendor management governs the commercial relationship: performance, service levels and spend. Supply chain security governs the inherited risk: what happens to your operation when the provider fails, is compromised or is held to ransom. The first is procurement; the second is resilience, and the recent disruption record shows which one was missing.

What does NIS2 require for supply chains?+

Article 21 names supply chain security, including the security related aspects of relationships with direct suppliers and service providers, among the mandatory risk management measures. Entities are expected to assess provider vulnerabilities and overall quality, and supervisors increasingly ask for the evidence.

How does DORA treat third party risk?+

As one of its five pillars: a register of ICT third party arrangements, mandatory contractual provisions, concentration risk assessment, monitoring and exit strategies, with critical ICT providers subject to direct European oversight. Our third party workstream builds exactly that evidence base.

What is concentration risk?+

The share of your operation carried by a single provider, platform or location. It is what turned one vendor's ransomware incident into simultaneous manual operations at four major airports: many organisations, one dependency, one failure. Concentration is measured, then either engineered down or wrapped in a rehearsed fallback.

Can suppliers be brought into our exercises?+

They must be. A continuity plan whose critical steps are performed by a provider who has never rehearsed them with you is an assumption. We design joint scenarios with your critical providers, from tabletop to functional, so the seam is tested with the people who own the other side of it.

Explore further

Related services

Cyber and security

Cyber Resilience

Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.

Explore the service ›
Cyber and security

Information Security

Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.

Explore the service ›
Regulation and crisis

DORA Compliance

The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.

Explore the service ›
Regulation and crisis

NIS2 Compliance

From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.

Explore the service ›
Risk and governance

Risk Management

From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.

Explore the service ›
Sector framework

DAEDALUS Airport Resilience Framework

The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.

Explore the service ›
Continuity and resilience

Business Continuity Management

BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.

Explore the service ›
Continuity and resilience

Business Continuity Exercises

Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.

Explore the service ›
Regulation and crisis

Crisis Management

Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.

Explore the service ›
Continuity and resilience

Organisational Resilience

The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.

Explore the service ›
Risk and governance

7A Risk Management Framework

Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.

Explore the service ›
Risk and governance

AI Governance and Resilience

Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.

Explore the service ›
Next step

Find your concentration points before an adversary does.

Ask us for an extended enterprise mapping; the single points of failure outside your perimeter will be more revealing than anything inside it.

Book a consultation
All consultations are treated with strict confidentiality.