Depending on one cloud region, one identity provider, one payments processor, or a dominant software vendor means their outage, breach, price change, or exit becomes the organization’s. Financial-sector rules such as DORA now make ICT concentration risk an explicit regulatory concern, including dependencies shared across an entire industry.
Key points
Dependency mappingInventory critical providers and their own dependencies — concentration hides in sub-suppliers and shared platforms not chosen directly.
Cost-benefit balanceMulti-vendor, portability, and exit plans cost money and complexity; apply them where failure tolerance is genuinely low.
Important limitationDiversification reduces correlated failure, not necessarily risk. Two weak providers can be worse than one strong one, and some concentrations — like a dominant identity platform — may be unavoidable; then the control becomes resilience to its failure, not escape from it.