Domain 6 · Supply-Chain and Third-Party Security
Vendor Concentration and Supply-Chain Exposure
Build simplified external dependency twins and surface latent shared dependencies between suppliers that appear independent.
Decision it answers
What happens to us if this vendor is compromised, and who else fails with them?
Inputs it needs
- Vendor register with granted access and criticality
- Software dependency manifests and SBOMs
- Connector and integration inventory
- Contractual and provenance records
Methods applied
- Dependency twin construction per critical vendor
- Hidden concentration discovery across nominally separate suppliers
- Access, criticality, concentration and replaceability weighting
- Compromise simulation against the enterprise twin
Outputs produced
- Vendor exposure profiles
- Hidden concentration findings
- Compromise scenarios with reachable assets
- Replaceability and containment options
Must remain human-owned
Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.
