
Blog Post
Concentration Risk: What to Do When You Cannot Diversify
August 17, 2026
European supervisors published their first sector-wide incident report in June 2026, covering more than three thousand major ICT incidents across financial services during 2025. Twenty-nine percent originated with a third party. One third had cross-border impact.
The same exercise produced something more uncomfortable. Regulators built a map of which providers the sector collectively depends on, and they built it from the registers financial entities submitted themselves. Nineteen providers were designated as critical, and the list confirmed that a large share of the sector runs on a handful of the same names. Concentration stopped being a theoretical portfolio property at that point and became a supervised one.
Concentration Has Several Types and Only One Is Obvious
Vendor programs look for the same provider appearing twice, which is the easiest form to spot and rarely the one that causes the outage.
Same Provider
Several suppliers running on one hosting platform, or several business processes depending on one software vendor. Visible in a register once someone thinks to sort by provider rather than by contract, and the version most programs have already addressed.
Same Region or Availability Zone
Two providers on different platforms can occupy the same physical region, and a multi-cloud posture that places both primary and failover in the same geography has bought less resilience than the architecture diagram suggests. Supervisors are reportedly probing availability zone strategy and whether failover has been tested rather than designed.
Same Component
Shared software beneath unrelated vendors is invisible in a vendor register entirely. A widely used library, an operating system, a certificate authority or a DNS provider can appear in the dependency chain of a dozen suppliers who have no commercial relationship with each other. Aggregation through shared software is the documented case, and nothing in a questionnaire surfaces it.
Same Sub-Processor
Your vendor's vendor is your dependency. The presence of colocation and telecommunications providers among the designated critical providers illustrates the point, since those sit beneath cloud platforms rather than beside them. Fourth-party risk is where concentration hides most reliably, because the register was never designed to record it.
Diversification Frequently Does Not Work
The standard advice is to identify concentration and diversify. Analysis of the critical provider designations makes the problem with that explicit, noting that fourth-party dependencies invalidate simplistic diversification strategies.

Two independent suppliers sharing a colocation facility, an internet exchange or a telecom carrier are correlated regardless of contractual separation. Adding a second provider in that situation increases cost and integration surface while leaving the correlated failure mode intact. Diversification only reduces exposure where the alternatives are independent all the way down, and establishing that requires visibility most organizations do not have.
Substitutability Is Now a Formal Test
Among the criteria supervisors apply when designating a provider as critical is whether financial entities could realistically migrate elsewhere within an operationally relevant timeframe. The criterion reframes the question usefully. Concentration matters most where substitution is slow, so a provider you could replace in weeks presents a different exposure from one you could not replace within a year even with unlimited budget.
Measuring Concentration Rather Than Noticing It
A register sorted by provider identifies where concentration exists. It does not say how much exposure it carries, and the answer requires modeling the provider failing rather than assessing the vendors individually.

Model the Dependency Failing, Not the Contract
The scenario worth modeling is a specific shared provider becoming unavailable, applied simultaneously to every dependent process. Assessing each vendor separately and adding the results produces a smaller number, because independent assessment assumes independent failure. The whole point of concentration is that the assumption is wrong.
The Systemic Share Is the Number to Report
Splitting modeled loss into events that originate inside the organization and events arriving through shared infrastructure produces a proportion a board can act on. Where the systemic share approaches or exceeds half the portfolio, most of the exposure is not addressable by internal controls at all, which changes what the security budget can be expected to achieve. Reporting that alongside quantified board figures is more informative than a vendor count.
Correlation Moves the Tail, Not the Average
Concentration barely affects expected annual loss and substantially affects the extreme figure, because a shared dependency failing hits everything at once rather than occasionally. Programs reasoning about vendors through averages therefore see almost none of it, which is the single most common reason concentration goes unmeasured in organizations that already run quantification.
What Supervisors Now Do With Your Register
The register stopped being a filing obligation and became an input to sector-level analysis. Regulators aggregated submissions across the market, identified which providers carried systemic significance, and designated nineteen of them, with designation falling on the provider rather than on the financial entity.
Each designated provider now has a lead overseer with powers to request information and conduct inspections. Recommendations rather than fines are the direct instrument, with enforcement flowing back through national authorities and the entities themselves. For a financial entity the practical consequence is that reliance on a designated provider for a critical function is a supervisory topic rather than a commercial choice, and the wider obligations arriving with it assume the register is current.
The Contract Backlog Is a Live Exposure
A central bank review found that around one in eight critical outsourcing contracts at significant institutions were noncompliant with existing requirements by the institutions' own reporting, and that a majority of those had not been audited in the previous three years. Entities entering active supervision carry that position into an examination, and remediating contract terms is slower than remediating a control.
Boards Now Need a Concentration Tolerance
Supervisory expectations include the management body setting an explicit appetite and tolerance for concentration on designated providers. The expectation is a threshold rather than a statement, expressed as a share of critical functions or of modeled exposure attributable to one provider, and it needs the same properties as any other appetite threshold that can be breached.
What to Do When Diversification Is Unavailable
Sometimes there are three credible providers for a service and all three are already systemically significant. Four responses remain, and none of them is switching.
- Degraded Mode Operation: Define what the business does without the provider for a day, a week and a month, and test it rather than document it.
- Partial Migration: Moving specific workloads to an alternative reduces the concentration figure without a full exit.
- Staged Exit Plans: Tested rather than written, with the constraint usually being data extraction in usable form rather than technical migration.
Risk transfer completes the set for the residual, though coverage for a widespread outage affecting many insureds simultaneously is precisely where policy wording and aggregate limits matter most. Correlated events are the ones insurers price most carefully, so the coverage details deserve reading before relying on them for this exposure.
Concentration Inside Your Own Stack
The vendor framing understates the problem, because the same logic applies to internal dependencies nobody classifies as third party. One identity provider authenticating every application. One continuous integration pipeline deploying everything. One network path carrying all egress.
Each is a single point through which unrelated processes fail together, and none appears in a vendor register. Mapping internal shared dependencies alongside external ones produces a more honest picture, and it frequently reveals that the largest correlated exposure sits inside the organization rather than outside it. Concentration risk is a property of the dependency graph rather than of the supplier list.
A Dependency Graph, Not a Vendor List
Concentration is invisible to vendor-by-vendor assessment because it lives in the relationships between dependencies rather than inside any one of them. It barely moves the average and substantially moves the tail, so programs reasoning through expected loss will not find it. Measuring it requires modeling a shared provider failing across everything that depends on it, reporting the systemic share, and accepting that diversification is frequently unavailable so the answer is degraded operation and tested exit rather than a second contract. Kovrr's third-party risk modeling aggregates vendor exposure with correlation applied, so the concentration figure is produced rather than inferred.
To see how much of your modeled exposure arrives through shared dependencies rather than your own environment, book a demo with our cyber risk experts.
Concentration Risk FAQs
Speak to an ExpertWhat is ICT concentration risk?
It is the exposure created when many processes, suppliers or institutions depend on the same underlying provider or component, so a single failure affects all of them simultaneously. Four types matter and only the first is easy to spot. Same provider, where several suppliers run on one platform. Same region or availability zone, where nominally separate providers occupy the same geography. Same component, where a shared library, operating system, certificate authority or DNS provider sits beneath unrelated vendors. Same sub-processor, where your vendor's vendor is the real dependency and no register records it.
Why does diversification often fail to reduce concentration?
Because independence has to hold all the way down the dependency chain, and it frequently does not. Two suppliers on different cloud platforms can share a colocation facility, an internet exchange or a telecommunications carrier, which correlates them regardless of contractual separation. Analysis of the European critical provider designations notes explicitly that fourth-party dependencies invalidate simplistic diversification strategies, and the presence of colocation and telecom providers among those designated illustrates why. Adding a second provider in that situation raises cost and integration surface while leaving the correlated failure intact.
How do you measure concentration risk rather than just identify it?
Model the specific shared provider becoming unavailable and apply that scenario simultaneously to every dependent process, rather than assessing each vendor separately and adding the results. Independent assessment assumes independent failure, and that is the assumption concentration violates. Splitting modeled loss into events originating inside the organization and events arriving through shared infrastructure produces a systemic share, and where that approaches half the portfolio most exposure is not addressable by internal controls. Concentration barely affects expected annual loss and substantially affects the extreme figure.
What did regulators do with the third-party registers?
European supervisors aggregated register submissions across the financial market, used them to identify which providers carried systemic significance, and designated nineteen as critical, including major cloud and data providers. Designation falls on the provider rather than on the financial entity, and each designated provider now has a lead overseer with powers to request information and conduct inspections. Recommendations rather than fines are the direct instrument, with enforcement flowing back through national authorities. Reliance on a designated provider for a critical function has therefore become a supervisory topic rather than a purely commercial choice.
What can you do if diversification is not available?
Four responses remain when the credible alternatives are all systemically significant. Degraded mode operation, meaning a defined and tested account of what the business does without the provider for a day, a week and a month. Partial migration, since moving specific workloads elsewhere reduces the concentration figure without a full exit. Staged exit plans, tested rather than written, where the constraint is usually extracting data in usable form. Risk transfer for the residual, with the caveat that widespread outages affecting many insureds at once are exactly where wording and aggregate limits matter.
Does concentration risk only involve vendors?
No, and the vendor framing understates it. One identity provider authenticating every application, one continuous integration pipeline deploying everything, or one network path carrying all egress each create a single point through which unrelated processes fail together, and none appears in a third-party register. Mapping internal shared dependencies alongside external ones frequently reveals that the largest correlated exposure sits inside the organization. Concentration is a property of the dependency graph rather than of the supplier list, which is why assessing the vendor portfolio is necessary and not sufficient.




