Blog Post

Concentration Risk: What to Do When You Cannot Diversify

August 17, 2026

Table of Contents

European supervisors published their first sector-wide incident report in June 2026, covering more than three thousand major ICT incidents across financial services during 2025. Twenty-nine percent originated with a third party. One third had cross-border impact.

The same exercise produced something more uncomfortable. Regulators built a map of which providers the sector collectively depends on, and they built it from the registers financial entities submitted themselves. Nineteen providers were designated as critical, and the list confirmed that a large share of the sector runs on a handful of the same names. Concentration stopped being a theoretical portfolio property at that point and became a supervised one.

Concentration Has Several Types and Only One Is Obvious

Vendor programs look for the same provider appearing twice, which is the easiest form to spot and rarely the one that causes the outage.

Same Provider

Several suppliers running on one hosting platform, or several business processes depending on one software vendor. Visible in a register once someone thinks to sort by provider rather than by contract, and the version most programs have already addressed.

Same Region or Availability Zone

Two providers on different platforms can occupy the same physical region, and a multi-cloud posture that places both primary and failover in the same geography has bought less resilience than the architecture diagram suggests. Supervisors are reportedly probing availability zone strategy and whether failover has been tested rather than designed.

Same Component

Shared software beneath unrelated vendors is invisible in a vendor register entirely. A widely used library, an operating system, a certificate authority or a DNS provider can appear in the dependency chain of a dozen suppliers who have no commercial relationship with each other. Aggregation through shared software is the documented case, and nothing in a questionnaire surfaces it.

Same Sub-Processor

Your vendor's vendor is your dependency. The presence of colocation and telecommunications providers among the designated critical providers illustrates the point, since those sit beneath cloud platforms rather than beside them. Fourth-party risk is where concentration hides most reliably, because the register was never designed to record it.

Diversification Frequently Does Not Work

The standard advice is to identify concentration and diversify. Analysis of the critical provider designations makes the problem with that explicit, noting that fourth-party dependencies invalidate simplistic diversification strategies.

Distribution of modeled annual loss split between systemic events affecting shared dependencies and idiosyncratic events affecting the organization alone
Separating systemic loss from idiosyncratic loss shows how much of a portfolio depends on events that arrive through somebody else's infrastructure.

Two independent suppliers sharing a colocation facility, an internet exchange or a telecom carrier are correlated regardless of contractual separation. Adding a second provider in that situation increases cost and integration surface while leaving the correlated failure mode intact. Diversification only reduces exposure where the alternatives are independent all the way down, and establishing that requires visibility most organizations do not have.

Substitutability Is Now a Formal Test

Among the criteria supervisors apply when designating a provider as critical is whether financial entities could realistically migrate elsewhere within an operationally relevant timeframe. The criterion reframes the question usefully. Concentration matters most where substitution is slow, so a provider you could replace in weeks presents a different exposure from one you could not replace within a year even with unlimited budget.

Measuring Concentration Rather Than Noticing It

A register sorted by provider identifies where concentration exists. It does not say how much exposure it carries, and the answer requires modeling the provider failing rather than assessing the vendors individually.

Aggregate exposure across a portfolio of entities showing average annual loss, extreme loss and the correlation applied between them
Aggregating across entities with a correlation factor produces a tail figure that summing individual exposures cannot reach.

Model the Dependency Failing, Not the Contract

The scenario worth modeling is a specific shared provider becoming unavailable, applied simultaneously to every dependent process. Assessing each vendor separately and adding the results produces a smaller number, because independent assessment assumes independent failure. The whole point of concentration is that the assumption is wrong.

The Systemic Share Is the Number to Report

Splitting modeled loss into events that originate inside the organization and events arriving through shared infrastructure produces a proportion a board can act on. Where the systemic share approaches or exceeds half the portfolio, most of the exposure is not addressable by internal controls at all, which changes what the security budget can be expected to achieve. Reporting that alongside quantified board figures is more informative than a vendor count.

Correlation Moves the Tail, Not the Average

Concentration barely affects expected annual loss and substantially affects the extreme figure, because a shared dependency failing hits everything at once rather than occasionally. Programs reasoning about vendors through averages therefore see almost none of it, which is the single most common reason concentration goes unmeasured in organizations that already run quantification.

What Supervisors Now Do With Your Register

The register stopped being a filing obligation and became an input to sector-level analysis. Regulators aggregated submissions across the market, identified which providers carried systemic significance, and designated nineteen of them, with designation falling on the provider rather than on the financial entity.

Each designated provider now has a lead overseer with powers to request information and conduct inspections. Recommendations rather than fines are the direct instrument, with enforcement flowing back through national authorities and the entities themselves. For a financial entity the practical consequence is that reliance on a designated provider for a critical function is a supervisory topic rather than a commercial choice, and the wider obligations arriving with it assume the register is current.

The Contract Backlog Is a Live Exposure

A central bank review found that around one in eight critical outsourcing contracts at significant institutions were noncompliant with existing requirements by the institutions' own reporting, and that a majority of those had not been audited in the previous three years. Entities entering active supervision carry that position into an examination, and remediating contract terms is slower than remediating a control.

Boards Now Need a Concentration Tolerance

Supervisory expectations include the management body setting an explicit appetite and tolerance for concentration on designated providers. The expectation is a threshold rather than a statement, expressed as a share of critical functions or of modeled exposure attributable to one provider, and it needs the same properties as any other appetite threshold that can be breached.

What to Do When Diversification Is Unavailable

Sometimes there are three credible providers for a service and all three are already systemically significant. Four responses remain, and none of them is switching.

  • Degraded Mode Operation: Define what the business does without the provider for a day, a week and a month, and test it rather than document it.
  • Partial Migration: Moving specific workloads to an alternative reduces the concentration figure without a full exit.
  • Staged Exit Plans: Tested rather than written, with the constraint usually being data extraction in usable form rather than technical migration.

Risk transfer completes the set for the residual, though coverage for a widespread outage affecting many insureds simultaneously is precisely where policy wording and aggregate limits matter most. Correlated events are the ones insurers price most carefully, so the coverage details deserve reading before relying on them for this exposure.

Concentration Inside Your Own Stack

The vendor framing understates the problem, because the same logic applies to internal dependencies nobody classifies as third party. One identity provider authenticating every application. One continuous integration pipeline deploying everything. One network path carrying all egress.

Each is a single point through which unrelated processes fail together, and none appears in a vendor register. Mapping internal shared dependencies alongside external ones produces a more honest picture, and it frequently reveals that the largest correlated exposure sits inside the organization rather than outside it. Concentration risk is a property of the dependency graph rather than of the supplier list.

A Dependency Graph, Not a Vendor List

Concentration is invisible to vendor-by-vendor assessment because it lives in the relationships between dependencies rather than inside any one of them. It barely moves the average and substantially moves the tail, so programs reasoning through expected loss will not find it. Measuring it requires modeling a shared provider failing across everything that depends on it, reporting the systemic share, and accepting that diversification is frequently unavailable so the answer is degraded operation and tested exit rather than a second contract. Kovrr's third-party risk modeling aggregates vendor exposure with correlation applied, so the concentration figure is produced rather than inferred.

To see how much of your modeled exposure arrives through shared dependencies rather than your own environment, book a demo with our cyber risk experts.

Tomer Shoolman

Product Manager

Concentration Risk FAQs

Speak to an Expert

What is ICT concentration risk?

Why does diversification often fail to reduce concentration?

How do you measure concentration risk rather than just identify it?

What did regulators do with the third-party registers?

What can you do if diversification is not available?

Does concentration risk only involve vendors?