# What is Concentration Risk?

> Concentration risk is the exposure created when critical operations depend on too few providers, platforms, or suppliers — so a single failure or compromise cascades across the organization.

- Canonical URL: https://yellowcube.eu/glossary/concentration-risk/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Depending on one cloud region, one identity provider, one payments processor, or a dominant software vendor means their outage, breach, price change, or exit becomes the organization’s. Financial-sector rules such as DORA now make ICT concentration risk an explicit regulatory concern, including dependencies shared across an entire industry.

### Key points

- **Dependency mapping:** Inventory critical providers and their own dependencies — concentration hides in sub-suppliers and shared platforms not chosen directly.
- **Cost-benefit balance:** Multi-vendor, portability, and exit plans cost money and complexity; apply them where failure tolerance is genuinely low.
- **Important limitation:** Diversification reduces correlated failure, not necessarily risk. Two weak providers can be worse than one strong one, and some concentrations — like a dominant identity platform — may be unavoidable; then the control becomes resilience to its failure, not escape from it.

### Related terms

[Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/>) · [Third-party risk management (TPRM)](<https://yellowcube.eu/glossary/third-party-risk-management/>) · [Digital Operational Resilience Act (DORA)](<https://yellowcube.eu/glossary/digital-operational-resilience-act/>) · [Business continuity](<https://yellowcube.eu/glossary/business-continuity/>) · [Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/>)

### Sources

[EUR-Lex, Digital Operational Resilience Act (EU) 2022/2554](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) · [NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

