- › Vendor assessment is done one supplier at a time, which means nobody is looking at what the whole set has in common.
- › Forty suppliers frequently resolve to a handful of shared providers for mail, storage, authentication, and payments.
- › Your diligence measured each vendor's practices and told you nothing about whether their failures are correlated.
- › Map what your top suppliers depend on before you add another questionnaire, because the concentration is the finding.
- › Write the subprocessor disclosure and change notice into the contract at renewal, since that is the only point where you have any say.
A vendor risk program looks like this in most organizations. There is a list of suppliers, a questionnaire, a schedule, and somebody whose job includes chasing people for answers. Every vendor gets assessed on its own. Each assessment produces a score, the scores go into a register, and the register gets reviewed once a quarter by people who are reading forty rows and thinking about forty separate things.
That process is genuinely useful and it has one blind spot built into its shape. Assessing forty vendors individually cannot tell you anything about what the forty have in common, because the question is never asked at that level. You end up with a very good picture of each tree and no picture of the forest. When somebody finally does look at the forest, it is usually about four companies wide.
What Actually Sits Under Your Supplier List
Pick your top twenty vendors and ask a narrower question than the questionnaire asks. Not how they manage access or whether they encrypt at rest. Ask who sends their transactional email, where they store their data, who handles their authentication, and who processes their payments.
The answers collapse fast. Transactional email is a market of maybe five real providers, object storage is effectively three, identity is a handful, and payments is narrower still. Your forty suppliers are running on a set of shared providers small enough to write on one hand, and none of those providers appears anywhere in your vendor register, because you have no contract with them and never selected them.
We covered a version of this recently without naming it as such. A hardware wallet company’s customers got phished because the company’s email provider was breached, and a separate incident at a fulfillment vendor exposed customer records the company had been told were deleted. In both cases the organization doing the apologizing had done nothing wrong at its own layer. The failure happened one step further down, at a provider its customers had never heard of and it had not chosen for them.
That is fourth-party risk, and it does not behave the way the third-party kind does. The tools we built for one do very little for the other.
Why This Is Different From Ordinary Vendor Risk
Third-party risk is mostly about whether a given supplier is competent and careful, and it responds to the tools we already have. Diligence, contracts, audits, and the occasional difficult conversation. Our supply chain guidance covers that work and it holds up.
Concentration is a different property altogether, and it has nothing to do with any individual supplier being weak. It is a question about whether their failures arrive together.
Forty vendors each with a small independent chance of an outage is a manageable risk, and it is the risk your register is implicitly modeling. Forty vendors where eleven of them run on the same storage provider is a different distribution entirely, because those eleven fail on the same morning. Your business continuity plan, which assumes you lose one supplier at a time and route around them, was written against the first distribution.
There is a second consequence that shows up earlier and more often than an outage. A breach at a shared provider becomes a notification obligation at several of your vendors simultaneously, and you will hear about it from four of them in the same week, with four different timelines and four different levels of candor. We wrote about what happens when the breach is your vendor’s and the clock is yours, and the concentrated version of that is the same problem multiplied by however many suppliers share the provider.
Why Nobody Catches It
I want to be fair to the people running these programs, because the miss is structural and not careless. Three things about how the work is organized push against ever finding it.
The questionnaire asks each vendor about itself. That is the correct scope for what a questionnaire can verify, and asking a supplier to enumerate its own dependencies produces either a refusal or a list of forty subprocessors that arrives as an unsearchable PDF attachment. The person receiving it has thirty-nine more assessments in the queue and no time to cross-reference.
The register is organized by vendor, which is the right shape for managing relationships and the wrong shape for spotting patterns. Nothing about a row-per-supplier view surfaces the fact that rows 4, 11, 19, and 26 all terminate in the same place.
The incentive also points away from looking. A concentration finding does not resolve into an action anybody can take this quarter. You cannot make a vendor change its email provider, and the honest recommendation coming out of the analysis is usually to accept the exposure with your eyes open. That is a real outcome and it is a hard one to put in front of a committee that wants a remediation date.
So the work does not happen, and then it is not anybody’s fault in particular, which is how most of the interesting risks in an organization end up unowned.
The Version That Fits in a Week
You do not need a platform for this, and the platforms that sell it will produce a prettier version of an answer you can reach by hand in an afternoon. The work is four questions and one table.
Ask four questions of your top twenty
Email delivery, data storage, authentication, and payments are the whole survey. Send them as four questions in the body of an email rather than as an attachment, because the response rate on four questions is dramatically better than on a document.
Most vendors will answer. The ones that will not tell you something too, and their refusal belongs in the register next to whatever score you gave them.
Build one table, sorted the other way
Put providers down the left and your vendors across the top. The concentration becomes visible the moment the table exists, and it usually takes one afternoon. What you are looking for is any provider that appears under more than three or four suppliers, and particularly one that appears under suppliers you consider unrelated.
Sorting by provider instead of by vendor is the entire technique. Everything else follows from having the data in that orientation.
Rewrite the continuity plan against the real clusters
Take your two or three biggest clusters and walk through losing each one whole. Not one vendor, the cluster. What still works, who you call, what you tell customers, and how long you can run in that state.
This is where the exercise pays for itself, because the answer is frequently that several things you had listed as independent workarounds are in the same cluster as the thing they were supposed to work around.
Put it in the contract at renewal
Renewal is the only moment when anybody on the vendor’s side has a reason to say yes, and the ask is modest enough to survive a negotiation. Disclosure of material subprocessors, notice before they change, and notification when one of them has an incident that touches your data. Our due diligence playbook makes the same argument in an acquisition context, and the principle transfers: the contract is where a question becomes an obligation.
Ask for it every time. Some vendors will agree, more will agree than you expect, and the ones who refuse have told you something about how they think about their own supply chain.
What to Do With an Answer You Cannot Fix
Some concentration is unavoidable and pretending otherwise wastes everybody’s time. There are three real cloud providers. If eleven of your suppliers run on one of them, that is a fact about the market and not a failure of your program.
The point of finding it is to stop being surprised by it, to know which morning is going to be bad, and to have told the people who need to know beforehand instead of during. Fixing it is one possible outcome and frequently not the available one. An accepted risk that somebody senior has actually seen and signed is a different situation from an unexamined one, even when the exposure is identical.
The organizations that handle this well are the ones where somebody can answer the question in an hour. Their dependency map is no less concentrated than anybody else’s.
If you want help mapping what your supplier base actually runs on, contact Grab The Axe. You can also take our free Human Attack Surface Score to see where the people-shaped gaps sit.
Marie Welch is Director of Behavioral Security Operations at Grab The Axe.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →