“Our provider is down” explains the cause. It does not transfer the consequence.
If a cloud platform, identity provider, telecom operator, payment processor or specialist software supplier fails, your customers still experience your unavailable service.
Outsourcing a service does not outsource accountability for continuity. Boards that treat a vendor status page as the response have confused a cause with a plan.
When a Third Party Becomes Your Emergency
A third-party failure becomes a business emergency when it threatens a critical outcome and demands immediate coordination. For example:
- A customer-facing service cannot operate.
- Employees cannot authenticate.
- Transactions cannot be processed or reconciled.
- Sensitive data may have been compromised.
- Recovery time is uncertain.
- Contractual escalation is not producing decisions.
Critical still describes the business outcome, not the vendor’s brand. Identity going dark is often critical because everything else sits on it. A non-customer-facing reporting tool going dark is usually urgent at most: delay has a cost; normal governance can still work. Do not let the supplier’s drama upgrade the classification for you.
The board should expect more than a screenshot of someone else’s incident banner. It should expect named executive ownership, business workarounds, independent impact assessment, regulatory analysis, customer-communication criteria and clear decision times.
Readiness Starts Before the Call
Emergency readiness for suppliers is mostly unglamorous work done in the calm:
- Dependency mapping that reaches the hidden pumps, not only the contracted logo
- Tested exit or substitution options, including the honest answer “there is no substitute in the recovery window”
- Recoverable data that does not live only in the failed environment
- Escalation contacts that work at 02:13, not only in account-management hours
- Realistic concentration-risk scenarios: one cloud, one identity provider, one payments rail
For DORA-regulated entities, major ICT incidents must be escalated to senior management and the management body, with the impact, response and additional controls explained. The regulation does not care that the ICT sits in another company’s data centre. Your authorisation conditions and your customers still do.
If the only thing you can do without a named supplier is wait, you have already written the first hour of the crisis. Write the second hour now, while you can still choose it.
Board question: Which supplier failure would place us in crisis within one hour—and what can we do without that supplier?
Relevant Sources
- Regulation (EU) 2022/2554 (DORA), Article 17 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Regulation (EU) 2022/2554 (DORA), Article 3 — EUR-Lex — https://eur-lex.europa.eu/eli/reg/2022/2554/oj
- Cybersecurity Incident — NIST CSRC Glossary — https://csrc.nist.gov/glossary/term/cybersecurity_incident
I work with boards on concentration risk and supplier emergencies: ownership, workarounds, and what you can still do when the status page is the only thing still up. Contact me.
