Supply Chain Resilience: Managing Third-Party and Supplier Risk
How to build supply chain resilience: mapping and tiering suppliers, assessing their resilience, and planning for vendor disruption.
The last few years taught every operations leader the same lesson: a business is only as resilient as the suppliers it depends on. A single vendor failure, a chip shortage, or a compromised software update can stop an otherwise healthy organization cold. Supply chain resilience is the discipline of seeing those dependencies clearly and planning for their failure. Here is how to approach it.
Why the supply chain is a continuity problem
Continuity planning often stops at the organization’s own walls. That is where it fails, because a critical activity you have carefully protected can still halt when an outside supplier goes down. A business impact analysis that maps dependencies will almost always surface suppliers as a point of fragility, which is why supplier continuity belongs in the same conversation as your own recovery planning, not in a separate procurement silo.
Map and tier your suppliers
You cannot protect what you have not mapped. Build a single inventory of your suppliers, then tier them by how much damage their failure would cause, not by how much you spend with them. A small vendor that provides a single irreplaceable component can outrank a large one you could switch tomorrow. This tiering tells you where to concentrate due diligence and where a lighter touch is fine.
Assess resilience before you sign
For your critical suppliers, resilience should be a selection criterion, not an afterthought. Ask what their own continuity and recovery capabilities look like, whether they depend on the same infrastructure you do, and who their critical subcontractors are. The federal guidance on this, NIST’s Cybersecurity Supply Chain Risk Management program (SP 800-161), makes the point that risk visibility has to extend through the tiers, not stop at your direct vendor.
Build resilience into the relationship
- Diversify where it counts. A single source for a critical input is a single point of failure. Qualify a second source before you need it.
- Contract for continuity. Put recovery expectations, notification duties, and audit rights into the agreement.
- Monitor continuously. Supplier risk is not static. Reassess as their circumstances and yours change.
- Include suppliers in exercises. A tabletop exercise that assumes a key vendor is offline tests a failure you are genuinely likely to face.
Cyber and physical risk are converging
Modern supply chains carry both operational and digital risk, often at the same time. A vendor is a physical dependency and, increasingly, a path into your systems, which is why a cybersecurity incident response plan and supply chain resilience now reinforce each other. Treating them together, inside a broader continuity plan, is what separates organizations that absorb a supplier shock from those that are taken down by one.
More on this discipline is in our Operations & Project Delivery section, and the wider picture is in our guide to workplace emergency preparedness.
Frequently asked questions
What is supply chain resilience?
It is an organization’s ability to keep operating when a supplier or supply route fails, through visibility into dependencies, diversification, and planning for supplier disruption.
How do you prioritize which suppliers to focus on?
Tier them by the impact of their failure, not by spend. A low-cost supplier of an irreplaceable input can be more critical than a large, easily replaced one.
What is NIST SP 800-161?
It is NIST’s guidance on cybersecurity supply chain risk management (C-SCRM), which helps organizations identify, assess, and mitigate risks introduced by suppliers across the tiers of a supply chain.
General guidance, not legal or compliance advice. See CISA and ISO 22301 for authoritative detail.