PREMIUM CONTENT
This is premium content, available to Connect Plus users only
Unlock this content and more with Connect Plus membership.
Join a community of professionals and get:
Join a community of professionals and get:
15% discount
on all CeFPro events.
on all CeFPro events.
Post-event access:
unlock speaker decks and audience polls.
unlock speaker decks and audience polls.
Instant insights:
Full library access the moment you sign up.
Full library access the moment you sign up.
Digital Content

Log in to continue
Thank you for visiting CeFPro Connect and reading our latest industry updates. To continue reading more, please create your free account. You'll enjoy the following great benefits:
WHAT'S INCLUDED —
- Unlimited access to peer-contribution articles and insights
- Global research and market intelligence reports
- Discover Connect Magazine, a monthly publication
- Panel discussion and presentation recordings
Log in to continue or register for free
WHAT'S INCLUDED:
Access to peer-contribution articles and insights
Access to the latest global research and market intelligence reports
Access to the latest Connect Magazine, a monthly publication
Insight articles, panel discussions, webinars, podcasts and peer-led interviews
CONNECT+ MEMBERSHIP
Become a Connect+ member for unlimited access to our knowledge hub, receive 15% discount on all events, and access to audience insights and speaker presentations for up to three CeFPro events.
Log in or register for free in order to save this content
WHAT'S INCLUDED:
Unlimited access to peer-contribution articles and insights
Global research and market intelligence reports
Discover Connect Magazine, a monthly publication
Panel discussion and presentation recordings
Event Q&A
Strengthening Third-Party Resilience in an Increasingly Cloud-Dependent Environment
The Q&A highlights that organisations should treat cloud providers and cloud-hosted services, including AI, as critical dependencies in the same way as single- or sole-source suppliers. The central message is that traditional third-party risk management remains relevant, but its scope must expand to capture hidden fourth-party dependencies, cloud concentration, operational resilience, and the practical consequences of cloud outages.
Oct 08, 2026
.png)
Mark Carroll, Founder - Graduate ERM Program, Boston University
Tags:
Vendor and Third Party Risk
The views and opinions expressed in this content are those of the thought leader as an individual and are not attributed to CeFPro or any other organization
- Improving visibility of hidden dependencies: Identify sole-source suppliers, subcontractors, and cloud dependencies through assessments and mapping exercises.
- Assessing resilience through evidence: Go beyond certifications by reviewing testing, incident, recovery, and performance data.
- Managing cloud concentration risk: Strengthen operational resilience and access to critical data during outages.
- Expanding risk frameworks for AI: Treat cloud-hosted AI and related services as dependencies subject to existing controls.
- Focusing on practical resilience: Prioritise defence-in-depth, dependency management, contingency planning, and operational resilience over adding more cloud providers.
Log in to continue or register for free
WHAT'S INCLUDED:
Unlimited access to peer-contribution articles and insights
Global research and market intelligence reports
Discover Connect Magazine, a monthly publication
Panel discussion and presentation recordings
Sign in to view comments
Related insights —