Milan, July 29, 2026
Dear readers,
First of all, I’d like to wish a happy vacation to those who are about to leave, and a peaceful summer to those who will continue working in the coming weeks.
The summer months often coincide with a slowdown in business activity, but not necessarily in risks. Reduced staffing, supplier closures, more complex transportation, extreme weather events, and longer response times can make the dependencies on which an organization relies particularly apparent.
That is also why we chose to dedicate the July issue to supply chain resilience and third-party risk management.
While preparing this issue, one point became particularly clear: supply chain risk is no longer a specialized topic confined to procurement or logistics. It is one of the areas where nearly all major threats to business continuity converge.
A cyberattack can disrupt an essential service provider. A fire can render a production facility inoperable for months. A weather event can simultaneously paralyze infrastructure, transportation, and supply chains. A geopolitical decision can alter the availability or cost of materials and components in a matter of days.
Risk arises from the event, but its impact depends on the structure of the relationships through which that event spreads.
The data analyzed in the Outlook clearly illustrate the gap between awareness and actual capability. Only 3% of Allianz Risk Barometer participants who answered the specific question consider their supply chain to be very resilient. At the same time, the World Economic Forum notes that volatility should no longer be viewed as a temporary phase destined to fade away. It is a structural condition within which companies must learn to operate.
This change calls for a different approach.
It is not enough to simply know the list of suppliers, assign them a level of criticality, and periodically send them a questionnaire. It is necessary to understand which processes depend on each supply, how long it would take to replace it, and what additional dependencies exist beyond the direct supplier.
This is the topic addressed in the section “What Keeps You Awake at Night.” Two different suppliers may rely on the same manufacturer, the same data center, the same technology platform, or the same logistics hub. In this case, diversification exists in the contracts but not in actual operations.
Inthe Technical Corner, we’ve translated these principles into a concrete process. A Third-Party Risk Management program does not begin with due diligence and does not end with the signing of the contract. It includes identifying dependencies, classifying individual suppliers, conducting an evidence-based assessment, making risk decisions, drafting contracts, monitoring, and preparing for termination.
Legislation is also moving in the same direction.
The FAQs published by ACN on the supply chain security of NIS entities clarify the need to link risk assessment, contractual requirements, and periodic verification. DORA requires financial entities to provide a much more granular representation of their ICT dependencies through the Register of Information.
The regulatory message is clear: it is not enough to demonstrate that a process exists. It must be possible to reconstruct the decisions made, the information used, and the evidence gathered.
The Jaguar Land Rover case illustrates what happens when a disruption affects a key node in the supply chain. A cyber incident at the automaker did not merely halt its own production; it also reduced orders and cash flow for thousands of related businesses, many of which were financially dependent on this major customer.
This is an important reminder: supply chain risk does not flow in just one direction. We may depend on a supplier, but a supplier may depend just as critically on us. During the recovery, each party’s ability to resume operations depends on the other’s resilience.
This issue also highlights an aspect of third-party risk management that is sometimes underestimated: the prevention of industrial risks.
Cybersecurity, financial stability, and contractual provisions are essential elements, but supply continuity also depends on the physical protection of facilities and warehouses. The recent NFPA study on automated storage systems shows how increased efficiency and logistics density can create new concentrations of fire risk.
Finally, DRI International has introduced a specialized training and certification program in Supply Chain Resilience, featuring the new ASCRP and CSCRP credentials. This is a significant indicator of the discipline’s growing maturity and the increasing demand for professionals capable of integrating supply chain management, business continuity, risk management, and operational resilience.
The central theme of this edition can be summed up in one question:
Do we really understand the dependencies that underpin our organization?
It’s not just a matter of knowing who the suppliers are. We need to understand the facilities, technologies, infrastructure, subcontractors, and financial conditions that determine their ability to continue serving us.
Resilience does not consist in eliminating these dependencies—a goal that is almost always unrealistic. It consists in making them visible, understanding their consequences, and developing alternatives that are compatible with the timeframe within which the organization must continue to operate.
The full text of this edition can be downloaded from [Download not found]
Have a great vacation and enjoy the read.
See you soon,
Conrad Zana




