Glossary
What Is Supply-Chain Risk?
Supply-chain risk in cybersecurity is exposure inherited from the third parties an organisation depends on — hosting providers, DNS operators, registrars, and the networks beneath them. A compromise or outage anywhere in that chain becomes your incident, which is why NIS2 Art. 21 makes supply-chain security a board-level duty.
The dependency you didn't choose
Your security posture is only as strong as the providers you rest on. The CDN in front of your site, the DNS operator that answers for you, the registrar that holds your domain, the ASN that routes your traffic — each is a third party whose failure or compromise is inherited by you, often without a contract that says so.
Mapping the chain
You cannot manage a dependency you cannot see. Mapping the chain means tracing an organisation outward — domain to hosting to routing to the physical layer — and naming every provider in the path. The graph makes those dependencies explicit edges, so the chain is a traversal rather than a guess.
What NIS2 expects
NIS2 Article 21 names supply-chain security as a required risk-management measure for essential and important entities, with accountability at board level. Evidencing it means showing you know, and monitor, the third-party infrastructure your services depend on.
Where this shows up
See it in a live investigation: Map an org’s infrastructure concentration risk.
Go hands-on with the compliance recipes.
Workflows that use this
Runnable workflows where this concept does the work.