The European Union’s Digital Operational Resilience Act has applied since 17 January 2025, so financial entities in scope have now lived with it for close to a year. It reaches beyond those entities to the technology providers they depend on, including providers established outside the European Union.
The requirement that has produced the most work is also the least glamorous. Firms must maintain a register of information covering their contractual arrangements for information and communication technology services, which sounds like an administrative exercise and turns out to be a mapping exercise most organizations had never completed.
A supplier list is not a dependency map
Procurement records answer the question of who the organization pays. Operational resilience depends on a different question, which is what stops working if a given provider stops working, and the two lists overlap far less than people expect.
The gap shows up most clearly in concentration. Four contracts with four vendors can rest on one underlying platform, and nothing in the contracts discloses it, because each vendor is describing its own service rather than its own dependencies. An organization can hold a well-managed supplier portfolio and a single undocumented point of failure at the same time.
This is the value of the register even to organizations the regulation does not cover. It forces the enquiry that nobody schedules, and the answer is frequently uncomfortable enough to justify the effort on its own.
The worked example
On 19 July 2024 a routine update from a single security vendor took more than eight million Windows machines out of service. Airlines stopped flying, hospitals reverted to paper, and payment systems failed, in organizations that had no contractual relationship with each other and no obvious commonality.
Nothing about that incident was an attack, which is the part worth holding onto. The disruption came from a supplier doing what it did every week, and it demonstrated that the resilience question and the security question are not the same question.

Procurement records answer who the organization pays. Resilience depends on what stops working if a given provider does, and the two lists overlap less than most boards expect.
Exit plans that have never been tested
Most organizations hold documented exit arrangements for their material providers, and most of those documents were written to satisfy a checklist rather than to be used. They describe an orderly transition over a period of months, which is a reasonable description of a commercial separation and an unhelpful one for a provider that has become unavailable this morning.
A useful exit plan answers narrower questions. Where does the data physically sit, in what format, and who has tested restoring it somewhere else? What is the minimum viable version of the service, and how long does standing it up actually take when measured rather than estimated?
Those measurements are the substance of business continuity work. An organization that has performed them holds a number it can give a board, and an organization that has not holds a document.
Where to start if the register does not apply to you
- List the services that stop the business if they stop, working from the operations outward rather than from the contract file.
- For each, identify the provider, then identify what that provider itself depends on, which is the step that surfaces concentration.
- Establish the recovery time by testing it once, since an estimate and a measurement differ by more than most people assume.
- Record who decides to invoke an alternative, because that decision is usually the slowest part of the response.

The July 2024 outage was not an attack. A routine update from one supplier took more than eight million machines out of service, in organizations with no relationship to one another.
Operational technology is the harder half
Where an organization runs physical processes, the dependency question extends into equipment that was installed to last decades and was never designed to be patched. The systems are less visible than the corporate estate, they are frequently maintained by the vendor rather than by internal staff, and the consequences of an interruption are physical rather than administrative.
A security and safety assessment covering those environments asks different questions from a corporate technology review, and the two are often commissioned by different people who do not compare their findings.
Our Book of the Month shelf has Countdown to Zero Day, which remains the clearest published account of what it means when code reaches machinery, and it is worth reading by anyone responsible for a plant rather than an office.
The question for a board
Name the third party whose failure would stop the organization trading tomorrow morning. Where two directors would name different providers, the mapping has not been done, and the register requirement exists precisely because that was the common position.
The second question is how long recovery would take, expressed as a tested number rather than a target. That figure determines what an incident costs, and it is the one most likely to be wrong in the direction that matters.
Falcone International
Bring us a question like this one
We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.
