↑ Critical
Concentration Risk
1
Salesforce · 4 of 5 vendors
3 High
Active Signals
84
Dependencies mapped
✓ Verified
Audit-Grade Findings
6
Confirmed by 2+ sources
0 sent
Vendor Cooperation
None
100% public signals
Monitored Vendors
Click to filter dependency view
Vendor A
18 deps
● Critical
Vendor B
22 deps
● High
Vendor C
12 deps
● High
Vendor D
8 deps
● Confirmed
Vendor E
14 deps
● Confirmed
◈
Concentration Risk Findings
Sorted by severity · 9 findings
| Dependency | Vendors | Sources | Severity | Regulatory |
|---|---|---|---|---|
|
Shared CRM Platform
CRM · Enterprise
|
A
B
C
D
4 of 5
|
Critical | DORA Art.28 | |
|
Email Infrastructure
Productivity · Cloud
|
A
B
C
D
E
5 of 5
|
Audit Grade | DORA · OCC | |
|
Cloud Provider
Infrastructure · IaaS
|
A
B
D
3 of 5
|
High | NIST GV.SC-07 | |
|
Project Management
Collaboration · SaaS
|
A
C
2 of 5
|
Audit Grade | OCC 2023-17 | |
|
CDN / Security
Network · Edge
|
A
B
2 of 5
|
Confirmed | DORA Art.28 |
◎ Blast Radius
Shared CRM Platform failure impact
CRM
Critical
Vendor A
Payments
⚠ At risk
Vendor B
Messaging
⚠ At risk
Vendor C
Design
⚠ At risk
Vendor D
Comms
⚠ At risk
Vendor E
Security
✓ No exposure
⊕ Signal Sources
Active collection · May 2026
DNS Fingerprinting
MX · CNAME · TXT Records
21
Cert Transparency
crt.sh · Google CT
34
Job Postings
LinkedIn · Indeed · Glassdoor
29
◻ Regulatory Compliance Mapping
DORA · NIST · OCC — findings mapped
| Framework | Article / Control | Findings mapped | Status |
|---|---|---|---|
| DORA | Article 28 · ICT Concentration | 6 findings | Satisfied |
| NIST SP 800-161r1 | GV.SC-07 · C-SCRM | 6 findings | Satisfied |
| OCC 2023-17 | Third-Party Risk · 4th Party | 4 findings | Satisfied |
▦ Cloud Monoculture Exposure
Provider concentration across ecosystem
| Provider | Vendors | Exposure | Risk |
|---|---|---|---|
| Cloud Provider A | 3 of 5 | 60% | High |
| Cloud Provider B | 2 of 5 | 40% | Medium |
| Cloud Provider C | 1 of 5 | 20% | Low |