CeFPro Connect

Event Q&A
Strengthening Third-Party Resilience in an Increasingly Cloud-Dependent Environment
The Q&A highlights that organisations should treat cloud providers and cloud-hosted services, including AI, as critical dependencies in the same way as single- or sole-source suppliers. The central message is that traditional third-party risk management remains relevant, but its scope must expand to capture hidden fourth-party dependencies, cloud concentration, operational resilience, and the practical consequences of cloud outages.
Oct 08, 2026
Mark Carroll
Mark Carroll, Founder - Graduate ERM Program, Boston University
Tags: Vendor and Third Party Risk
Strengthening Third-Party Resilience in an Increasingly Cloud-Dependent Environment
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
  • Improving visibility of hidden dependencies: Identify sole-source suppliers, subcontractors, and cloud dependencies through assessments and mapping exercises.
  • Assessing resilience through evidence: Go beyond certifications by reviewing testing, incident, recovery, and performance data.
  • Managing cloud concentration risk: Strengthen operational resilience and access to critical data during outages.
  • Expanding risk frameworks for AI: Treat cloud-hosted AI and related services as dependencies subject to existing controls.
  • Focusing on practical resilience: Prioritise defence-in-depth, dependency management, contingency planning, and operational resilience over adding more cloud providers.
Log in to continue or register for free
WHAT'S INCLUDED:
Unlimited access to peer-contribution articles and insights
Global research and market intelligence reports
Discover Connect Magazine, a monthly publication
Panel discussion and presentation recordings
Sign in to view comments
ad
Related insights —