Concentration Risk (ICT)
ICT concentration risk is the exposure created when many organizations depend on the same technology or cloud providers, so a single provider-side failure, outage, or compromise cascades across a large portion of the sector simultaneously.
Why Concentration Risk Matters
Modern enterprise IT is heavily concentrated in a small number of providers. A handful of hyperscale cloud providers underlie most enterprise workloads. A small set of authentication providers handles identity for a large share of the market. A limited number of SaaS platforms operate widely across sectors. When one of these providers fails, the failure does not affect one organization. It affects a large fraction of the ecosystem simultaneously.
See what keeps a CISO up at night: managing cyber supply chain risk.
Regulatory Attention to Concentration Risk
Financial regulators, particularly in the EU, have made ICT concentration risk a specific focus. DORA requires financial entities to identify and manage concentration risk explicitly, and empowers regulators to designate specific ICT providers as critical, subjecting them to direct supervisory oversight.
The regulatory concern is systemic: an incident at a critical provider could affect financial stability, not just individual firm operations.
Managing Concentration Risk
Effective management includes explicit mapping of provider dependencies through the Register of Information or equivalent, contingency planning for provider-side incidents, and modeling of concentration-driven loss scenarios in CRQ. Diversification is often more expensive than the risk it addresses, so the analysis has to be quantified rather than assumed.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


