FOURTH-PARTY DEPENDENCY MAPPING

Concentration risk hides one layer down, where many of your suppliers depend on the same fourth party, so a single distant failure can hit multiple services at once. That dependency is invisible today.

Actors

  • Third-Party Risk Manager
  • Head of Cyber Resilience
  • Procurement Lead

Systems / Vendors

  • TPRM
  • CMDB / service mapping
  • Contract register

Business Question

"How many of our suppliers secretly depend on the same fourth party, and what breaks if it fails?"

What SPoG Does

  • Maps hidden concentration risk via shared vendors.
  • Reveals fourth-party single points of failure.
  • Links the dependency to affected services.

Outcome Metrics

1

Fourth-party dependency map

−25%

Hidden concentration risk

6–10 wks

To first outcomes