Perspectives

Mapped but Not Governed: Third-Party Dependency and the Board's Resilience Obligation

Regulators in the EU, the UK, and the US have converged on a single test for critical technology dependencies, and the test is substitutability rather than inventory.

Governance August 4, 2026
The Brief
Recommendations & Citations

THE BRIEF

A single faulty software update disabled an estimated 8.5 million Windows devices on 19 July 2024, and one airline cancelled approximately 7,000 flights over five days, a disruption it now values in litigation at more than USD 500 million [1][2].

In the period since, the EU has brought 19 critical ICT providers under direct supervision through DORA, the United Kingdom has brought its critical third parties regime into force, and NIS2 has carried management accountability for cybersecurity into national law across the Union. Each regime tests the same property: whether a firm could substitute a critical provider before breaching its tolerance for disruption [3][4][5][6][8].

Fiduciary doctrine reached the dependency from another direction. The Boeing derivative litigation treated safety as a mission-critical board responsibility and settled for USD 237.5 million, and approximately 74% of Russell 3000 companies now codify board-level oversight of cybersecurity [14][15].

Most organisations can name their critical providers. Far fewer have set tolerances for losing one, tested an exit under stress, or asked the board to own the concentration that remains.

I. ONE FAULTY UPDATE, 8.5 MILLION MACHINES: HOW CONCENTRATION SETS THE SCALE OF FAILURE

On 19 July 2024, a defective content update distributed by a single security vendor disabled an estimated 8.5 million Windows devices, a figure Microsoft placed at less than 1% of all Windows machines while observing that the broad economic and societal impacts reflected the use of CrowdStrike by enterprises that run many critical services [1]. Delta Air Lines cancelled approximately 7,000 flights over five days of disruption and later claimed more than USD 500 million in out-of-pocket losses in a complaint filed against CrowdStrike in the Superior Court of Fulton County, Georgia, on 25 October 2024 [2].

The instructive feature of the episode is the propagation rather than the defect. The update was routine, centrally distributed, and embedded beneath operations that had no tested way of running without it, so the severity of the outcome was set by the architecture of the dependency rather than by the technical seriousness of the error. An organisation's exposure to this class of failure is decided long before any incident, in choices about which providers sit beneath which operations and in whether anyone has established what the organisation can do when one of them stops.

Litigation now prices those choices. A single interrupted dependency produced a pleaded loss exceeding half a billion US dollars from one customer over five days [2]. A board that has treated vendor selection as a closed procurement outcome can read, in the Delta complaint, what the same selection looks like when it is restated as an operational loss.

II. THREE REGIMES, ONE TEST: REGULATION HAS MADE THE DEPENDENCY A GOVERNANCE OBJECT

Regulators reached the same conclusion before the outage occurred and have spent the period since building enforcement architecture around it. The EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied to financial entities since 17 January 2025 and frames the ultimate responsibility of the management body for managing ICT risk as an overarching principle of the regime [3]. On 18 November 2025 the European Supervisory Authorities designated the first critical ICT third-party providers for direct oversight, assessed on criteria that include a provider's systemic importance, its role in supporting critical or important functions for financial entities, and the level of substitutability of its services [4]. The first list comprises 19 providers, with cloud hyperscalers, major data vendors, and core ICT integrators featuring prominently [5].

The United Kingdom built a parallel structure. Acting under powers created by the Financial Services and Markets Act 2023, the Bank of England, the PRA, and the FCA published final rules for critical third parties in November 2024, in force from 1 January 2025 and applying to providers once HM Treasury designates them, with six Fundamental Rules and eight operational risk and resilience requirements directed principally at systemic third party services [6]. On the firm side of the same regime, in-scope financial firms had until 31 March 2025 to demonstrate that they could keep their important business services within defined impact tolerances, supported by mapping and scenario testing [7].

The pattern extends beyond financial services. The NIS2 Directive, whose transposition deadline passed on 17 October 2024, introduces accountability of top management for non-compliance with cybersecurity risk-management measures across essential sectors, an approach the European Commission describes as bringing cybersecurity to the attention of the boardroom [8][9]. In the United States, rules adopted by the SEC in July 2023 require public companies to disclose material cybersecurity incidents on Form 8-K, generally within four business days of determining materiality, and to describe board oversight of cybersecurity risk in annual reports under Regulation S-K Item 106 [10].

Read together, these regimes mark a reclassification. Third-party dependency is no longer treated as an operational hygiene matter delegated to procurement and vendor management; it is regulated as a governance object, with accountability assigned by name to management bodies and boards.

III. SUBSTITUTABILITY IS THE TEST MOST PROGRAMMES DO NOT RUN

The Financial Stability Board's December 2023 toolkit for financial institutions and financial authorities directed attention to the same point at the system level, providing tools for identifying, monitoring, and managing systemic third-party dependencies and the risks they pose to financial stability [11]. What separates a dependency register from dependency governance is the question the register cannot answer: whether the organisation could migrate to an alternative provider before breaching its own tolerance for disruption. The DORA designation criteria make that question explicit by ranking providers partly on the substitutability of their services [4].

The question is becoming harder to answer, not easier. The Bank of England's April 2025 assessment of artificial intelligence in the financial system warned that reliance on a small number of providers for a given service could generate systemic risks where rapid migration to alternatives is not feasible, and identified model costs, complexity, and vertical integration of the AI stack as factors that could increase concentration in the generative AI market over time, to the point where a widespread outage of one or several key models could leave many firms unable to deliver vital services [12]. A new and concentrated AI-supply layer is being assembled on top of cloud, data, and integration layers that the first European designation list already shows to be concentrated [5].

Supervisory expectations on the firm-side answer predate all of this. The PRA's supervisory statement on outsourcing and third party risk management, first published in March 2021, set expectations for business continuity and exit plans, including exits executed under stress [13]. The practical gap is that most exit plans exist as documents rather than as rehearsed capabilities, and the UK's March 2025 operational resilience deadline converted the document into an evidenced fact: a firm must be able to show, through mapping and testing, that its important business services stay within tolerance when the dependency fails [7].

IV. THE OVERSIGHT DUTY HAS ALREADY REACHED THE DEPENDENCY

Fiduciary doctrine arrived at the dependency from a different direction. Under Caremark, Delaware law requires boards to implement a reasonable information and reporting system for the corporation's central risks and to monitor what it reports [14]. In the Boeing derivative litigation, the Delaware Court of Chancery treated aircraft safety as a mission-critical board oversight responsibility, and the claims settled for USD 237.5 million, one of the largest derivative settlements in history [14].

The translation to technology dependency is direct. Where a single provider's failure can halt core operations for days, that dependency is mission-critical on any operational reading, and the oversight obligation attaches to it in the same way it attached to safety at an aircraft manufacturer. The disclosure architecture now makes the state of that oversight publicly legible: approximately 74% of Russell 3000 companies have codified board or committee oversight of cybersecurity following the SEC's 2023 rules [15], and Item 106 requires companies to describe how their boards exercise that oversight [10].

Codified oversight and exercised oversight are different assets. A committee charter that names third-party risk, sitting above an exit plan that has never been tested, describes accountability without exercising it. The discipline involved is the one that already applies to governing the systems an organisation deploys: an inventory of what is in use, a named owner for each item, and evidence that the stated controls operate in practice. Dependency governance extends that discipline one layer down, to the providers those systems stand on.

V. WHAT GOVERNED DEPENDENCY REQUIRES

Four elements separate governed dependency from mapped dependency. The first is an inventory ranked by substitutability rather than by spend, because the provider that costs the least may be the one the organisation can least afford to lose. The second is a set of disruption tolerances defined and owned at board level, in the manner the UK regime requires for important business services [7]. The third is exit and continuity capability tested against those tolerances, in line with supervisory expectations that contemplate stressed as well as orderly exits [13]. The fourth is explicit ownership of what remains: where a dependency is genuinely unsubstitutable, the governance output is a recorded board-level decision to accept a named concentration, with compensating controls and a defined trigger for review.

The fourth element is the least practised, because it requires the organisation to say plainly that a tolerance cannot currently be met. Regulators have already accepted that answer as legitimate; the designation criteria and concentration analyses cited above exist precisely because some services cannot be rapidly substituted [4][12]. What supervision and, increasingly, litigation will not accept is the undocumented version, in which the concentration exists, no one has costed it, and the board learns the tolerance was unmet from the incident itself.

Three developments are foreseeable on this trajectory. The published designation lists will function as de facto concentration maps of the technology economy, sharpening scrutiny of every customer of the 19 named providers [5]. Supervisory questioning will move from the existence of dependency registers to the evidence of tested exits, following the path the UK's impact-tolerance regime has already cut [7]. And within two to three years, an operational failure at a major third party is likely to generate oversight claims of the Boeing type against customer-side boards, with plaintiffs reading a company's own Item 106 disclosures back to it as the statement of the oversight it promised [10][14].

VI. CONCLUSION

Concentration is economically rational, which is why the next CrowdStrike-shaped event is a matter of timing rather than possibility. The regulatory work of 2024 and 2025 did not attempt to prohibit concentration; it assigned the resulting exposure to management bodies and boards by name, in the EU, the United Kingdom, and the United States, and it selected substitutability as the measure of whether a dependency is governed. Organisations that absorb the next event well will be those that treated each critical dependency as a governed object: ranked by substitutability, bounded by tested tolerances, and owned, where it cannot be substituted, as an explicit board-level decision. Mapping records what an organisation depends on, and governance decides what happens when the dependency stops.

RECOMMENDATIONS

Within 30 days

Produce a board-level inventory of critical technology dependencies ranked by substitutability and mapped to the operations each provider supports, and identify the dependencies whose failure would breach the organisation's tolerance for disruption before any alternative could absorb the service.

Within 90 days

Define impact tolerances for the services those dependencies support, secure board ownership of the tolerances, and run a first stressed-exit exercise against the highest-ranked dependency, recording where the documented plan and the rehearsed capability diverge.

Within 6 months

Embed dependency governance in committee charters, reconcile external descriptions of board oversight with the evidence that the oversight operates, and, for entities in scope of DORA or the UK regime, map internal obligations to the designation-based oversight now in force.

Benchmarks that should change the recommendation

HM Treasury's first designation orders, findings from the ESAs' oversight of the designated providers, and any judicial treatment of oversight claims arising from a third-party technology failure would each sharpen or redirect the guidance above.

CAVEATS

Litigation figures are pleaded allegations. The USD 500 million loss figure and the flight-cancellation count derive from Delta's complaint; they are Delta's allegations, and they had not been adjudicated at the time of writing [2].

The 8.5 million device count is Microsoft's estimate, published on 20 July 2024, and was framed by Microsoft as an estimate rather than a census [1].

The count of 19 designated providers reflects the ESAs' first designation list of 18 November 2025 as reported in the cited analysis; the list and the surrounding oversight arrangements will evolve [4][5].

The 74% figure is a Glass Lewis analysis of Russell 3000 disclosure practice following the SEC's 2023 rules, published in March 2025; index composition and disclosure-coding methodology affect comparability across studies [15].

UK critical third parties obligations bind a provider only once an HM Treasury designation order takes effect, and no designations had been made when the final rules were published in November 2024; readers should verify the current designation state [6].

The analysis reflects the regulatory position as at August 2026. The characterisation of the Caremark line and the Boeing settlement follows the cited American Bar Association account [14].

REFERENCES

[1] Microsoft, "Helping our customers through the CrowdStrike outage," The Official Microsoft Blog, 20 July 2024. https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/

[2] Delta Air Lines, Inc. v. CrowdStrike, Inc., Complaint, Superior Court of Fulton County, State of Georgia, 25 October 2024. https://cdn.arstechnica.net/wp-content/uploads/2024/10/Delta-v-CrowdStrike-Complaint-10-25-24.pdf

[3] European Parliament and Council, "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)," EUR-Lex, 27 December 2022. https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng

[4] European Supervisory Authorities (EBA, EIOPA, ESMA), "European Supervisory Authorities designate critical ICT third-party providers under the Digital Operational Resilience Act," EIOPA, 18 November 2025. https://www.eiopa.europa.eu/european-supervisory-authorities-designate-critical-ict-third-party-providers-under-digital-2025-11-18_en

[5] PwC Legal, "ESAs publish first list of critical ICT third-party providers under DORA," November 2025. https://legal.pwc.de/en/news/articles/esas-publish-first-list-of-critical-ict-third-party-providers-under-dora

[6] Bank of England, Prudential Regulation Authority, and Financial Conduct Authority, "PS16/24 - Operational resilience: Critical third parties to the UK financial sector," Bank of England, 12 November 2024. https://www.bankofengland.co.uk/prudential-regulation/publication/2024/november/operational-resilience-critical-third-parties-to-the-uk-financial-sector-policy-statement

[7] Financial Conduct Authority, "Operational resilience," FCA, accessed August 2026. https://www.fca.org.uk/firms/operational-resilience

[8] European Commission, "NIS2 Directive: new rules on cybersecurity of network and information systems," Shaping Europe's Digital Future, accessed August 2026. https://digital-strategy.ec.europa.eu/en/policies/nis2-directive

[9] European Parliament and Council, "Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive)," EUR-Lex, 27 December 2022. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng

[10] U.S. Securities and Exchange Commission, "SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies," Press Release 2023-139, 26 July 2023. https://www.sec.gov/newsroom/press-releases/2023-139

[11] Financial Stability Board, "Final Report on Enhancing Third-Party Risk Management and Oversight: A Toolkit for Financial Institutions and Financial Authorities," FSB, 4 December 2023. https://www.fsb.org/2023/12/final-report-on-enhancing-third-party-risk-management-and-oversight-a-toolkit-for-financial-institutions-and-financial-authorities/

[12] Bank of England, "Financial Stability in Focus: Artificial intelligence in the financial system," April 2025. https://www.bankofengland.co.uk/-/media/boe/files/financial-stability-in-focus/2025/financial-stability-in-focus-artificial-intelligence-in-the-financial-system.pdf

[13] Prudential Regulation Authority, "SS2/21 - Outsourcing and third party risk management," Bank of England, 29 March 2021. https://www.bankofengland.co.uk/prudential-regulation/publication/2021/march/outsourcing-and-third-party-risk-management-ss

[14] American Bar Association, "Boards' Duty of Oversight: From Caremark to the Continuing Travails of Boeing," Business Law Today, May 2024. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-may/boards-duty-oversight-caremark-continuing-travails-boeing/

[15] Glass, Lewis & Co. (Aaron Wendt and Joah Clements), "Board Oversight of Cybersecurity Incidents," Harvard Law School Forum on Corporate Governance, 6 March 2025. https://corpgov.law.harvard.edu/2025/03/06/board-oversight-of-cybersecurity-incidents/