A Resiliate analysis shows that Danish ministries have a median of 23 visible, direct technology vendors. Go just one link further down the supply chain, and the number grows to 305. That changes the picture of where control over critical digital infrastructure actually sits.
Most organisations know who they've signed contracts with. They know who supplies their systems, cloud solutions and other critical technologies. And they've typically assessed those vendors' security, financial standing and ability to deliver.
But that's only the top layer.
Behind the companies an organisation has chosen sit a far larger chain of sub-vendors - cloud platforms, software, data centres, identity services, network services and other technologies the organisation may never have chosen itself, but which its critical functions depend on all the same.
That's the gap Resiliate set out to measure.
The analysis shows that the Danish ministries studied have a median of 23 visible, direct technology vendors. Once their vendors' own dependencies are counted just one link further down, that number rises to 305.
"Most companies have a reasonably good handle on who they buy from. But that's not the same as knowing who they depend on. The critical dependencies can sit several links further down the chain, at companies they never chose and never had a contract with." — Lars Neupart, CEO, Resiliate
What Sits Beneath the Contract
The difference matters because an organisation's own vendor choices don't necessarily reveal where its real technological dependencies lie.
A Danish or European vendor, for instance, may build its product on technology from companies outside Europe - and that vendor may in turn depend on other platforms and infrastructure.
Resiliate's analysis also shows that the share of EU-owned vendors drops sharply once vendors further down the chain are included. That doesn't automatically mean a non-European vendor is a problem. But it does mean that decisions about digital sovereignty and vendor risk can't be made on the name of the company on the contract alone.
"You can have made a deliberate choice about your direct vendors and still end up with entirely different dependencies further down the chain. If you can't see them, you can't assess the risk they pose either." — Lars Neupart
Two Solutions Can Share the Same Point of Failure
Supply chains carry another kind of risk too.
An organisation may have chosen several different vendors to build in redundancy and reduce its exposure. On paper, the solutions look independent. But further down the chain, they can depend on the same cloud platform, the same software component, the same identity service, or the same piece of digital infrastructure. Two different solutions can end up sharing the exact same point of failure.
"Two different vendors aren't necessarily two independent solutions. If they both build on the same service further down the chain, you still have one shared point of failure. Those are the kinds of concentrations you need to know about if redundancy is going to be real." — Lars Neupart
Resilience Can't Be Assessed in Isolation
This challenges how organisations traditionally assess their own resilience.
An organisation can have its own security, its incident response and its direct vendors well in hand, and still be exposed to events at companies it has no relationship with at all.
The more digital infrastructure is interconnected, the harder it becomes to assess resilience within an organisation's own boundaries alone.
So the decisive question isn't only whether an organisation's own systems can withstand an incident. It's also what the organisation is connected to - and what those systems are connected to in turn.
Another Question Boards Need to Ask
That doesn't mean board members need full visibility into every single company several links down every technology supply chain. But they do need to know the dependencies that could affect the organisation's ability to function.
"Leadership doesn't need to know the names of 305 vendors. But it should know where the critical dependencies and shared points of failure sit. Otherwise, you risk believing you've built resilience into your operations without actually having done so." — Lars Neupart