Protecting revenue when the operating system breaks
How companies can design for revenue and value continuity when shocks disrupt customers, channels, technology or supply.
Read articleHow many critical suppliers depend on the same thing?
Vendor count is not diversification. Two suppliers may depend on the same cloud region, software library, subcontractor, manufacturing plant, port, energy network or specialist workforce. Contractual separation can therefore conceal a single operational exposure.
Map the service, not just the legal entity. For every critical outcome, trace prime suppliers, material subcontractors, hosting locations, control planes, data routes, logistics nodes and ultimate ownership. Record which dependencies are substitutable, the time and data needed to switch, and whether capacity would still be available during an industry-wide event.
European financial regulation offers a useful operating signal. DORA became applicable in January 2025 and requires in-scope firms to maintain registers of ICT third-party arrangements; its EU oversight framework explicitly addresses systemic and concentration risk arising from reliance on a limited number of critical providers. The mapping principle extends well beyond finance.
Test correlated scenarios: one cloud identity failure, common cyber compromise, regional power loss, export restriction, transport closure or upstream insolvency. Ask suppliers for evidence rather than assurance, include audit and notification rights, and monitor changes in subcontracting. A nominal exit clause has little value if migration takes longer than the business can tolerate.
Prioritise exposures by consequence, substitutability and switching time. Reduce them through architectural portability, inventory, dual tooling, alternate routes or explicit acceptance backed by larger buffers. The objective is not eliminating concentration; it is seeing where independent-looking choices collapse onto the same point of failure.
Related macro
Articles
How companies can design for revenue and value continuity when shocks disrupt customers, channels, technology or supply.
Read articleWhy enterprises need to shift from static recovery plans to adaptive systems that connect operations, suppliers, people and critical dependencies.
Read articleFocus
Technology resilience depends on understanding whether supposedly independent recovery mechanisms share infrastructure, services or failure modes.
Systemic exposure matters when one event affects multiple dependencies, markets or operating capabilities simultaneously.
Strategic challenges
A shock may begin in energy, geopolitics or infrastructure but become material through suppliers, customers, financing or workforce behaviour.
Stakeholders may form conclusions while information remains incomplete, creating pressure before the organisation has established a coherent view of events.
POV
Readiness comes from exercising decisions, dependencies and recovery actions, not from approving a document and storing it.
Resilience is revealed by what remains possible when assumptions fail, cash tightens and several adverse conditions occur together.
Strategic impact
Clear rhythms for assessing information, making decisions and reviewing consequences can prevent both paralysis and uncontrolled reaction.
Revenue depends on interconnected marketing, channels, contracting, fulfilment and service capabilities that can fail at different points.
What we observe
We frequently see documented procedures built around assumptions about availability, dependencies and recovery times that exercises have never validated.
We frequently see exercises confirm that a plan exists without testing whether teams can coordinate decisions and execute recovery under disruption.