Skip to content
Black Atlas — Powered by KRYOS V6

Domain 6 · Supply-Chain and Third-Party Security

Vendor Concentration and Supply-Chain Exposure


Build simplified external dependency twins and surface latent shared dependencies between suppliers that appear independent.

Classification

DERIVED

Maturity

DERIVED_VALIDATION_REQUIRED

Authorization

Level 0 to Level 1

Decision it answers

What happens to us if this vendor is compromised, and who else fails with them?

Inputs it needs

  • Vendor register with granted access and criticality
  • Software dependency manifests and SBOMs
  • Connector and integration inventory
  • Contractual and provenance records

Methods applied

  • Dependency twin construction per critical vendor
  • Hidden concentration discovery across nominally separate suppliers
  • Access, criticality, concentration and replaceability weighting
  • Compromise simulation against the enterprise twin

Outputs produced

  • Vendor exposure profiles
  • Hidden concentration findings
  • Compromise scenarios with reachable assets
  • Replaceability and containment options

Must remain human-owned

Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.